HTB | Synced | Write-Up

Summary:
This walkthrough provides help with solving the Synced machine challenge on Hack The Box, focusing on tasks related to rsync and its usage on the target machine. Key takeaways include understanding the default port for rsync (873), using anonymous authentication, and listing shares and files with the correct options.
Machine Name: Synced | Difficulty: Easy | OS: Linux
The aim of this walkthrough is to provide help with the Synced machine on the Hack The Box website. Please note that no flags are directly provided here. Moreover, be aware that this is only one of the many ways to solve the challenges.
It belongs to a series of tutorials that aim to help out complete beginners with finishing the Starting Point TIER 0 challenges.
Setup
There are a couple of ways to connect to the target machine. The one we will be using throughout this walkthrough is via the provided pwnbox.
Once our connection is taken care of, we spawn the target machine.
Additionally - even though not required - it is possible to set a local variable (only available in the current shell) containing our target host's IP address. Once set, we can easily access it by prepending a $ to our variable name.
┌─[htb-bluewalle@htb-pwdysfiide]─[~/Desktop]
└──╼ $rhost=<target-hosts-ip>
┌─[htb-bluewalle@htb-pwdysfiide]─[~/Desktop]
└──╼ $ echo $rhost
<target-hosts-ip>
┌─[htb-bluewalle@htb-pwdysfiide]─[~/Desktop]
└──╼ $
You could use the unset command to remove it after you no longer need it.
┌─[✗]─[htb-bluewalle@htb-pwdysfiide]─[~/Desktop]
└──╼ $unset rhost
┌─[htb-bluewalle@htb-pwdysfiide]─[~/Desktop]
└──╼ $
Task | 1
Question: What is the default port for rsync?
The answer I found on the internet was either the port used by the ssh connection, or tcp port 873.
873
Task | 2
Question: How many TCP ports are open on the remote host?
Scan all the tcp ports on the target machine with nmap. There appears only one open.
┌─[htb-bluewalle@htb-fjpem3fvtz]─[~/Desktop]
└──╼ $nmap -p- $rhost
Starting Nmap 7.93 ( https://nmap.org ) at 2023-05-04 21:53 BST
Nmap scan report for 10.129.228.37
Host is up (0.010s latency).
Not shown: 65534 closed tcp ports (conn-refused)
PORT STATE SERVICE
873/tcp open rsync
Nmap done: 1 IP address (1 host up) scanned in 246.65 seconds
┌─[htb-bluewalle@htb-fjpem3fvtz]─[~/Desktop]
└──╼ $
1
Task | 3
Question: What is the protocol version used by rsync on the remote machine?
Service/version detection can be done via the -sV option in nmap.
┌─[✗]─[htb-bluewalle@htb-fjpem3fvtz]─[~/Desktop]
└──╼ $nmap -sV -p 873 $rhost
Starting Nmap 7.93 ( https://nmap.org ) at 2023-05-04 22:01 BST
Nmap scan report for 10.129.228.37
Host is up (0.011s latency).
PORT STATE SERVICE VERSION
873/tcp open rsync (protocol version 31)
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 9.49 seconds
┌─[htb-bluewalle@htb-fjpem3fvtz]─[~/Desktop]
└──╼ $
31
Task | 4
Question: What is the most common command name on Linux to interact with rsync?
One way would be the usage of apropos to search all and any mention of the name rsync in the installed man pages and descriptions.
┌─[✗]