Revenge (SQLi + sudoedit .service config)
#1 FLAG 1
PORT SCAN

RUNNING GOBUSTER ON PORT 80


RUNNING SQLMAP


ENUMERATION DATABASES

ENUMERATING TABLES

DUMPING ALL DATA FROM A DATABASE


#2 FLAG 2

CRACKING HASH WITH HASHCAT

LOGGING AS USER SERVER-ADMIN


#3 FLAG 3
PRIVILEGE ESCALATION
sudo -l

shell.sh

CURRENT CONTENT OF THE FILE

CHANGED CONTENT

RESTARTING THE SERVICE

Checking /tmp/
GETTING A ROOT SHELL

GETTING THE FINAL FLAG

CHANGING INDEX.HTML
CHECKING ROOT DIRECTORY

READING THE FLAG

PreviousYear of the Owl (SNMP + onesixtyone + snmpwalk + crackmapexec + RecycleBin + pwdump.py)NextOpacity (RFI nullbyte bypass + .kdbx hash crack + pspy64 backup process LPE)
Last updated