Wekor
Room Link: https://tryhackme.com/room/wekorra
Initial Scan
Kali
nmap -A $VICTIM
Scan all ports
Kali

TCP/80 - HTTP
Kali

Kali
Kali
Kali
Kali
Kali
Kali
Kali
Kali
Kali



Save request into a file

SQL Injection

List

Get version
Sql

Display all database names
Sql

Display tables inside wordpress database
Sql

Display all columns of wp_users table
Sql

Display results of userlogin, user_pass, and user_activation_key columns
Sql


We have some credentials but they don't work for SSH. So there is info we are missing
Kali

Sql


I added just the wekor site since the others are .com sites so I doubt they are being used.

We can see the site

We can login with all accounts but yura is a admin
Credentials

Initial Shell


Kali


Get autocomplete
Victim

TCP/11211 - Memcache
Victim

Lateral Movement
I couldn't ssh into the host but could su from www-data
Victim
Privilege Escalation
Victim

I couldn't really do anything with the bitcoin application itself but I could move the folder desktop and then replace the bitcoin with bash
Victim

Last updated