0day
Room Link: https://tryhackme.com/room/0day
Initial Scan
Kali
nmap -A $VICTIM
Scan all ports
Kali

TCP/80 - HTTP
Kali

This appeared to be a rabbit hole but I found a key and was able to bruteforce the password for it.

Kali

I found a cgi file. i tried checking if it was vulnerable to shellshock which wasn't working but it was vulnerable.
Kali

Initial Shell
Link: https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/cgi
Kali#1
Kali #2

Get autocomplete
Privilege Escalation
Victim

Kali

The exploit didn't work as it's complaining that it can't create dynamic library
Victim

To fix this we just had to export the binpath from the machine
Victim

Last updated