Tokyo Ghoul
Room Link: https://tryhackme.com/room/tokyoghoul666
Initial Scan
Kali
nmap -A $VICTIM
Scan all ports
Kali

TCP/80 - HTTP
Kali



TCP/21 - FTP
Kali


Ghidra
Kali

Kali

Kali


CyberChef was able to idenfify it was morse code and from there it was obvious the next few steps.
Morse code -> Hex -> Base64


TCP/80 - HTTP
Kali





There was a filter so to bypass I url encoded the most of path to passwd


Kali

TCP/22 - SSH
Kali
Victim

Victim


Last updated