GLITCH

Room Link: https://tryhackme.com/room/glitch

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

No other ports found

Kali

TCP/80 - HTTP

Kali

TCP/80 - HTTP

Looking into api directory we find a items page

Kali

Change the request from GET to POST and it gives an interesting message

Running the below shows it is vulnerable

Initial Shell

Kali

Burp

Get autocomplete

Lateral Movement

Victim

Netcat

Kali(receiving)

Victim(sending)

Kali

Victim

Victim

Victim

Privilege Escalation

I used doas to read the passwd file, make a backup called passwd.old just in case it broke and passwd.new and added a new user

Victim

Last updated