Oh My WebServer

Room Link: https://tryhackme.com/room/ohmywebarrow-up-right

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/80 - HTTP

Kali

Initial Shell

Exploit: https://www.exploit-db.com/raw/50383arrow-up-right

Kali

Kali

Get autocomplete

Privileges Escalation

Exploit: https://gtfobins.github.io/gtfobins/python/arrow-up-right

Victim

Nmap

Scanned the gateway

Kali

Victim

Privileges Escalation / Breakout of Docker

shell.sh

Kali

Victim

Kali

Victim

Last updated