Expose
Room Link: https://tryhackme.com/room/expose
Initial Scan
Kali
nmap -A $VICTIM
Scan all ports
Kali

TCP/1337 - HTTP
Kali




Kali

There are two URLs here, the second one needs a username which we don't have so we'll start with the first one.

Brower - /file1010111/index.php

Browser




Browser - /upload-cv00101011/index.php


Kali






Get autocomplete

Kali
Privilege Escalation
Victim


Last updated