Napping

Room Link: https://tryhackme.com/r/room/nappingis1337

Scans

Initial scan

Kali

nmap -A $VICTIM

Longer scan

Kali

TCP/80 - HTTP

Find Pages

Kali

Kali

red.htm

redir.html

Kali

For victim to download our red.html file

Kali

To host our fake login page

Kali

Wireshark filter

TCP/22 - SSH

Kali

Lateral Movement

there is another user on this box. In their home directory they have a python script that looks like it checks the website. I added the following to the code to get a reverse shell.

query.py

Kali

Full TTY

Privilege Escalation

Exploit: https://gtfobins.github.io/gtfobins/vim/

Victim(adrian)

Victim(adrian)

Last updated