TryHack3M: Sch3Ma D3Mon
Room Link: https://tryhackme.com/r/room/sch3mad3mon
A Public Computer with a VPN
goto Edit -> preferences -> protocols -> search for SSL or TLS -> select the ssl-key.log file and hit enter to decrypt the web traffic.

Filter

Connected Tables
Filter
Find Databse
Filter

Find Tables
Filter

Get fields
Filter

Get field info
Confirmed we're the only other user.
Filter

Filter

Filter

From DB to OS
URL

URL

Finding a Needle in a Malwarestack
We can see the files but if we cat them they get cut off.
URL

URL

URL

URL

If you use Burp the output will be nicer to copy over.


Kali


Operation Defang

Kali
URL

Victim
Victim

After reading the code I saw that we can defang the code just by changing the config.ini file fto debug=true so we can run the code without having to worry about what will happen.
Victim
Last updated