> For the complete documentation index, see [llms.txt](https://oklencodes.gitbook.io/untitled/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://oklencodes.gitbook.io/untitled/ctfs/biteme-ctf/trying-to-gain-access-via-ssh.md).

# Trying to gain access via SSH

When that worked I was able to see a file browers and file viewer

![](https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FwSpltax9zj1ZkNfy8Npb%2FInside%20the%20dashboard.PNG?alt=media\&token=30380f47-5c8a-4539-977c-0184dc2fdf05)

![](https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2Fki9SrHEUQBv3yGkJRqL0%2FIn%20the%20dashboard%20found%20the%20first%20flag%20and%20ssh%20running.PNG?alt=media\&token=498d188c-a8bc-4c9c-bba6-bffc128c1987)

Within the file browser I typed  /home/jason/ - I then saw the user.txt flag and noticed that ssh was running

![](https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FwHe5Iz48OqBhVkgbrmMr%2Ftrying%20to%20access%20ssh%20keyts.PNG?alt=media\&token=4bbe88e5-e4b6-44e6-92e3-6454a86a5cbc)

While still in the file viewer i tried to type in /home/jason/.ssh/authorized\_keys – This was to see what keys i could access. I got a permission failure.

So next I tried /home/jason/.ssh/id\_rsa - conveniently I got access to the rsa private key.

![](https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2F5cimBR3s1aBtkZNyIaVR%2Ffound%20ssh%20isa%20private%20key.PNG?alt=media\&token=0cfc1703-bfac-4b99-a5c7-69b04c398553)

I then copied this into a sublime file named jason\_*id*\_rsa and i changed the permissions to only give myself readable access.&#x20;

With this information at hand I need a tool like John the ripper to help crack the password to the machine. John the Ripper (JtR) is a password cracking tool originally produced for UNIX-based systems. It was designed to test password strength, brute-force encrypted (hashed) passwords, and crack passwords via dictionary attacks.

![](https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FTO0UifwJy0vJRLh7BQmg%2Fusing%20John%20the%20ripper%20to%20get%20the%20password%20with%20the%20private%20key.PNG?alt=media\&token=26fae00f-968b-4fe3-9236-d3910a8b8924)

First I needed to find it with "locate ssh2john.py" then type in the address of where I found it to put it into usage and finally include the rsa file.

As you can see JtR successfully cracked the password, now with all that information I am able to successfully SSH into Jason's machine.&#x20;

![Successfully SSH'd ](https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FRhF4vQInN4zqKaFRgM2t%2FSuccessfully%20SSHing.PNG?alt=media\&token=053b6626-9472-498c-8d4d-52b62f7c3967)
