Anonymous
Room Link: https://tryhackme.com/room/anonymous
Initial Scan
Kali
nmap -A $VICTIM

Scan all ports
Kali

TCP/445 - SMB
Kali

There were just two dog pics, probably not interesting.
Kali
TCP/21 - FTP
Login using anonymous and no pass
Kali
Initial Shell
There were these 3 files

I modified clean.sh to have a reverse shell back to my kali

Kali #1
Kali #2
After a few minutes the script was ran and I had a shell.

Get autocomplete
Privilege Escalation
Followed this link on lxd privilege escalation
Link: https://www.hackingarticles.in/lxd-privilege-escalation/
Victim

Kali
Note: The command lxd init was to resolve a storage pool area issue, it may not always be needed.
Victim
Last updated