Watcher
Room Link: https://tryhackme.com/room/watcher
Initial Scan
Kali
nmap -A $VICTIM
Scan all ports
Kali

TCP/80 - HTTP
Kali

Kali

I used my wordlist of common found on LFI / RFI and confirmed I can view files on the server. I did not find anything useful
Kali

I remembered we had that secret file as well, I was able to read it and it had some credentials for FTP.

TCP/21 - FTP
Kali

Kali
Kali(ftp)


Get autocomplete
Victim

Lateral Movement - mat
Victim

Kali

Get autocomplete
Lateral Movement - will
Victim(mat)


Kali
Victim(mat)

Get autocomplete
Privilege Escalation
Victim(will)

Kali

Last updated