0day

Room Link: https://tryhackme.com/room/0day

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/80 - HTTP

Kali

This appeared to be a rabbit hole but I found a key and was able to bruteforce the password for it.

Kali

I found a cgi file. i tried checking if it was vulnerable to shellshock which wasn't working but it was vulnerable.

Kali

Initial Shell

Link: https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/cgi

Kali#1

Kali #2

Get autocomplete

Privilege Escalation

Victim

Kali

The exploit didn't work as it's complaining that it can't create dynamic library

Victim

To fix this we just had to export the binpath from the machine

Victim

Last updated