CMesS
Last updated
Last updated
Room Link:
Kali
Kali
Kali
Mostly junk
Fuzzed with a long subdomain list then filtered to reduce the amount of results. Only one stands out, dev.
Kali
I added dev.cmess.thm to my host file and found this page
We were able to login to the admin portal with these credentials
The shell they use is bad so I upload a new one to get a reverse shell instead
Kali
Get autocomplete
We find andre's password in a backup file
Victim
Kali
Victim
Victim
shell.sh
Victim
Exploit:
Shell Link:
Exploit: