Mindgames

Room Link: https://tryhackme.com/room/mindgamesarrow-up-right

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/80 - HTTP

Nothing really found, the pages listed are all broken links

Kali

https://www.dcode.fr/brainfuck-languagearrow-up-right

Encode

Kali

Encode

Get autocomplete

LinPeas

Kali

Victim

Privilege Escalation

Exploit: https://chaudhary1337.github.io/p/how-to-openssl-cap_setuid-ep-privesc-exploit/arrow-up-right

We found openssl has cap_setuid+ep in Linpeas

We can also run the below command to validate

Victim

openssl-exploit-engine.c

Kali

Victim

Last updated