Mr Robot CTF

Room Link: https://tryhackme.com/room/mrrobotarrow-up-right

Scanning

Kali

nmap -A $VICTIM

Scan all ports

No other ports found.

Kali

HTTP port 80

This ran for the majority of the time I was working on the box, I found the wordpress and checked robots.txt manually and the scan didn't really find anything of interest.

Kali

Key 1

Downloaded fsocity.dic

If you refresh the page you'll go to a wordpress site.

Test to see what users exist in wordpress, if the user doesn't exist it will give an error saying the user is invalid.

Kali

Because there were so many entries in fsocity.dic I tried to reduce it as much as I could by removing duplicates and passwords that I thought would be unlikely.

Kali

Kali

Reverse Shell

Reverse Shell Failed Attempt

revshell.php code

Kali

Connection is made but it isn't stable.

Reverse Shell

wpscan found out that twentyfifeen is installed.

Kali

Kali

Added the same shell to footer.php which should appear on every page visited. Then I just went back to http://$VICTIM/join and it worked.

Get autocomplete

Victim

Victim

Kali

Victim

LinPeas

Kali

Victim

Privilege Escalation

Victim

Last updated