Year of the Rabbit
Room Link: https://tryhackme.com/room/yearoftherabbit
Initial Scan
Kali
nmap -A $VICTIM
Scan all ports
No other ports found.
Kali
TCP/80 - HTTP



Turn off Javascript




Kali

Kali

FTP
Kali


Elis creds is encoded with something called Brain fuck. There are tools online to decode it.
Link: https://www.dcode.fr/brainfuck-language

Kali

Victim


Victim

Privilege escalation
Mostly followed the link below, we can't run sudo with root as we have (ALL , !root) here. if we had (ALL , ALL) it would be easy to escalate. Adding sudo -u#-1 to infront of the command allows us to bypass this.
Link: https://www.exploit-db.com/exploits/47502
Victim

Last updated