Pickle Rick

Room Link: https://tryhackme.com/room/picklerickarrow-up-right

Scanning

Initial Scan

nmap -A $VICTIM

Scan all ports

No other ports found.

HTTP port 80

Found Ricks username in the page source of the main page

robots.txt just had this, could be a password.

Ran the same dirb scan again except looking for .php files, I was able to find some pages.

Login worked

First ingredient found, also tried doing a reverse shell with netcat but not working

Clue to look around.

Second ingrediant found

www-data can actually run any command with sudo without entering a password.

The last ingredient is found in the root directory.

SSH port 22

Tried logging in with the username and potential password we found but ssh fails right away before entering a password.

Last updated