biteme

Room Link: https://tryhackme.com/room/biteme

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/80 - HTTP

Kali

Kali

Finding username

Kali

Recreating login

I merged configs.phps, functions.php and index.phps into a index.php file. Made some modifications so that it could run when hosted locally without the mfa part of the code so then I can try to bruteforce the credentials.

index.php

Kali

Bruteforce

Kali

Browser

Kali

Kali

LFI

Kali

TCP/22 - SSH

Kali

Lateral Movement

Victim

Victim

Kali

Victim

Get autocomplete

Privilege Escalation

Victim

Victim

Victim

Victim

Now we need to enter bad passwords until we've triggerd the ban action

Kali

Victim

Last updated