Mr Robot CTF
Room Link: https://tryhackme.com/room/mrrobot
Scanning
Kali
nmap -A $VICTIM
Scan all ports
No other ports found.
Kali

HTTP port 80
This ran for the majority of the time I was working on the box, I found the wordpress and checked robots.txt manually and the scan didn't really find anything of interest.
Kali

Key 1

Downloaded fsocity.dic

If you refresh the page you'll go to a wordpress site.



Test to see what users exist in wordpress, if the user doesn't exist it will give an error saying the user is invalid.

Kali


Because there were so many entries in fsocity.dic I tried to reduce it as much as I could by removing duplicates and passwords that I thought would be unlikely.
Kali
Kali

Reverse Shell
Reverse Shell Failed Attempt
revshell.php code
Kali


Connection is made but it isn't stable.

Reverse Shell
wpscan found out that twentyfifeen is installed.
Kali

Kali
Added the same shell to footer.php which should appear on every page visited. Then I just went back to http://$VICTIM/join and it worked.

Get autocomplete
Victim
Victim

Kali

Victim

LinPeas
Kali
Victim

Privilege Escalation
Victim


Last updated