Napping
Room Link: https://tryhackme.com/r/room/nappingis1337
Scans
Initial scan
Kali
nmap -A $VICTIM
Longer scan
Kali

TCP/80 - HTTP
Find Pages
Kali

Kali


red.htm
redir.html
Kali
For victim to download our red.html file
Kali
To host our fake login page
Kali

Wireshark filter


TCP/22 - SSH
Kali
Lateral Movement
there is another user on this box. In their home directory they have a python script that looks like it checks the website. I added the following to the code to get a reverse shell.

query.py

Kali

Full TTY
Privilege Escalation
Exploit: https://gtfobins.github.io/gtfobins/vim/
Victim(adrian)

Victim(adrian)

Last updated