Oh My WebServer

Room Link: https://tryhackme.com/room/ohmyweb

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/80 - HTTP

Kali

Initial Shell

Exploit: https://www.exploit-db.com/raw/50383

Kali

Kali

Get autocomplete

Privileges Escalation

Exploit: https://gtfobins.github.io/gtfobins/python/

Victim

Nmap

Scanned the gateway

Kali

Victim

Privileges Escalation / Breakout of Docker

shell.sh

Kali

Victim

Kali

Victim

Last updated