Wekor

Room Link: https://tryhackme.com/room/wekorraarrow-up-right

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/80 - HTTP

Kali

Kali

Kali

Kali

Kali

Kali

Kali

Kali

Kali

Kali

Save request into a file

SQL Injection

List

Get version

Sql

Display all database names

Sql

Display tables inside wordpress database

Sql

Display all columns of wp_users table

Sql

Display results of userlogin, user_pass, and user_activation_key columns

Sql

We have some credentials but they don't work for SSH. So there is info we are missing

Kali

Sql

I added just the wekor site since the others are .com sites so I doubt they are being used.

We can see the site

We can login with all accounts but yura is a admin

Credentials

Initial Shell

Kali

Get autocomplete

Victim

TCP/11211 - Memcache

Victim

Lateral Movement

I couldn't ssh into the host but could su from www-data

Victim

Privilege Escalation

Victim

I couldn't really do anything with the bitcoin application itself but I could move the folder desktop and then replace the bitcoin with bash

Victim

Last updated