Ollie
Room Link: https://tryhackme.com/room/ollie
Initial Scan
Kali
nmap -A $VICTIM
Scan all ports
Kali

TCP/80 - HTTP
Kali

TCP/1337 - waste
Kali

TCP/80 - HTTP
Browser

Initial Shell
Exploit: https://www.exploit-db.com/raw/50963
Kali

We can run commands from the browser as well.

Got this php reverse shell, just changed the IP
Kali
Kali
We have access to write to the immaolllieeboyyy directory so we put our shell there.
Browser
Browser


Get autocomplete
Victim

We can login to mysql but didn't find anything
Victim
Victim

PSPY
Kali
Victim

Privilege Escalation


Kali


Last updated