Chocolate Factory

Room Link: https://tryhackme.com/room/chocolatefactoryarrow-up-right

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

No other ports found

Kali

TCP/21 - FTP

Kali

TCP/80 - HTTP

Kali

We can run commands here and we see the key_rev_key file

We go there by the url and we can download it

Kali

Web Shell

Web

Kali

Get autocomplete

Victim

Shell

I was not able to su into charlie with the password, the credentials did work for the web login but it just brought me to the command page.

Victim

I copied the teleport private key to kali

Kali

Privilege Escalation

Exploit Link: https://gtfobins.github.io/gtfobins/vi/arrow-up-right

Charlie can run vi with no passwd so I just followed the link above to become root

Victim

Last updated