GLITCH
Room Link: https://tryhackme.com/room/glitch
Initial Scan
Kali
nmap -A $VICTIM
Scan all ports
No other ports found
Kali
TCP/80 - HTTP
Kali





TCP/80 - HTTP
Looking into api directory we find a items page
Kali


Change the request from GET to POST and it gives an interesting message


Running the below shows it is vulnerable

Initial Shell
Kali
Burp


Get autocomplete
Lateral Movement
Victim
Netcat
Kali(receiving)
Victim(sending)
Kali

Victim

Victim

Victim

Privilege Escalation
I used doas to read the passwd file, make a backup called passwd.old just in case it broke and passwd.new and added a new user
Victim

Last updated