0day
Last updated
Last updated
Room Link: https://tryhackme.com/room/0day
Kali
Kali
Kali
This appeared to be a rabbit hole but I found a key and was able to bruteforce the password for it.
Kali
I found a cgi file. i tried checking if it was vulnerable to shellshock which wasn't working but it was vulnerable.
Kali
Link: https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/cgi
Kali#1
Kali #2
Get autocomplete
Victim
Kali
The exploit didn't work as it's complaining that it can't create dynamic library
Victim
To fix this we just had to export the binpath from the machine
Victim