Expose

Room Link: https://tryhackme.com/room/expose

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/1337 - HTTP

Kali

Kali

There are two URLs here, the second one needs a username which we don't have so we'll start with the first one.

Brower - /file1010111/index.php

Browser

Browser - /upload-cv00101011/index.php

Kali

Get autocomplete

Kali

Privilege Escalation

Victim

Last updated