VulnNet
Room Link: https://tryhackme.com/room/vulnnet1
Initial Scan
Kali
nmap -A $VICTIM
Scan all ports
Kali

TCP/80 - HTTP
Kali

Kali

Browsing gobuster we can see a subdomain, broadcast.vulnnet.thm

Fuzz Subdomain
We can see broadcast again when we scan for it.
Kali

LFI
One of the other js files shows we can use referer to look at files.

Confirmed it works
Kali

Kali



Crack Hash
Kali



TCP/80 - HTTP
Kali

Initial Shell
exploit: https://www.exploit-db.com/raw/44250
Kali
Kali


Get autocomplete
Lateral Movement
Victim

Netcat
Kali(receiving)
Victim(sending)
Kali

Kali

Kali

Privilege Escalation
exploit: https://gtfobins.github.io/gtfobins/tar/

Victim

Victim

Victim
shell.sh
Victim
Once the cronjob runs are new root user will be created.
Victim

Last updated