AVenger
Room Link: https://tryhackme.com/r/room/avenger
Scans
Initial scan
Kali
nmap -A $VICTIM

Longer scan
Kali

TCP/80 - HTTP
Find Pages
There were too many 404 and 403 in the scan so I changed to ffuf to ignore them.
Kali
Kali


The gift folder takes us to avenger.tryhackme

Add hostname to host file
Kali

Kali
Kali

Bruteforce admin page
Kali
Initial Shell

Kali
exploit.bat
I tried bypassing the file type restriction with the shell above, I could see the bat file running by seeing that it try to grab the shell.php file but I couldn't find a place to save the file where I could also see it on the website.
Kali

Nim reverse shell worked because they accept exe files
Kali
Kali
Kali

Kali #1


Kali #2

Privilege Esclation
Found some credentials.
Victim

From my computer I could access the mysql.
Kali
I was able to find a password but couldn't crack it
Kali(mysql)

I found a password
Victim

Kali

I can run a administrator shell from the GUI


Victim
Kali

Last updated