Thompson

Room Link: https://tryhackme.com/room/bsidesgtthompsonarrow-up-right

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

No other ports found

Kali

TCP/8080 - HTTP

Kali

Tomcat default passwords

I clicked manager app and tried some default credentials

Kali

Get autocomplete

There is a script run by root in jacks folder

Victim

The script is writable by everyone so I added a the below line to reach back to my kali.

Victim

Kali

Last updated