Kitty

Room Link: https://tryhackme.com/r/room/kittyarrow-up-right

Scans

Initial scan

Kali

nmap -A $VICTIM

Longer scan

Kali

TCP/80 - HTTP

Find Pages

Kali

Payload

A few of the options above work but I choose this one, I can login but there's nothing developed

Payload

Retrieving database name from boolean sqli

So, the plan is to know the name of the database. However, manual attempts will be terribly time-consuming, so I decided to practice scripting. After some time spent trying different payloads, this one worked:

Statement

Was able to get the database name using this script

Kali

script.py

Kali

Table enumeration

Statement

script.py

Kali

Password enumeration

We already know the username “kitty,” so let’s go straight to the password.

Statement

script.py

Kali

TCP/22 - SSH

Kali

Kali

Kali

proxychains.conf

Kali

Privlege Escalation

We already know the username “kitty,” so let’s go straight to the password.

Kali

Victim

Option #1

Kali

Option #2

X-Forwarded-For

Add the following line to the payload

Last updated