Dav

Room Link: https://tryhackme.com/room/bsidesgtdavarrow-up-right

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

No other ports found

Kali

TCP/80 - HTTP

Kali

We were able to login with the following default credentials

I tried cracking the hash but it wasn't working

Kali

Using the credentials found earlier I was able to access the site using cadaver and upload a shell.

Kali

Kali

Kali

Victim

Get autocomplete

Victim

I first tried reading shadow to crack the users credentials but it wasn't working so I ended up just reading the flag.

Victim

Last updated