VulnNet

Room Link: https://tryhackme.com/room/vulnnet1arrow-up-right

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/80 - HTTP

Kali

Kali

Browsing gobuster we can see a subdomain, broadcast.vulnnet.thm

Fuzz Subdomain

We can see broadcast again when we scan for it.

Kali

LFI

One of the other js files shows we can use referer to look at files.

Confirmed it works

Kali

Kali

Crack Hash

Kali

TCP/80 - HTTP

Kali

Initial Shell

exploit: https://www.exploit-db.com/raw/44250arrow-up-right

Kali

Kali

Get autocomplete

Lateral Movement

Victim

Netcat

Kali(receiving)

Victim(sending)

Kali

Kali

Kali

Privilege Escalation

exploit: https://gtfobins.github.io/gtfobins/tar/arrow-up-right

Victim

Victim

Victim

shell.sh

Victim

Once the cronjob runs are new root user will be created.

Victim

Last updated