Chocolate Factory
Room Link: https://tryhackme.com/room/chocolatefactory
Initial Scan
Kali
nmap -A $VICTIM




Scan all ports
No other ports found
Kali

TCP/21 - FTP
Kali

TCP/80 - HTTP
Kali


We can run commands here and we see the key_rev_key file

We go there by the url and we can download it


Kali

Web Shell
Web

Kali
Get autocomplete

Victim

Shell
I was not able to su into charlie with the password, the credentials did work for the web login but it just brought me to the command page.
Victim
I copied the teleport private key to kali
Kali

Privilege Escalation
Exploit Link: https://gtfobins.github.io/gtfobins/vi/
Charlie can run vi with no passwd so I just followed the link above to become root
Victim


Last updated