Mindgames

Room Link: https://tryhackme.com/room/mindgames

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/80 - HTTP

Nothing really found, the pages listed are all broken links

Kali

https://www.dcode.fr/brainfuck-language

Encode

Kali

Encode

Get autocomplete

LinPeas

Kali

Victim

Privilege Escalation

Exploit: https://chaudhary1337.github.io/p/how-to-openssl-cap_setuid-ep-privesc-exploit/

We found openssl has cap_setuid+ep in Linpeas

We can also run the below command to validate

Victim

openssl-exploit-engine.c

Kali

Victim

Last updated