The Trial Before Christmas

Web

Video

Resources

Challenges

Scan the machine. What ports are open?

nmap -sC -sV -T5 -p1-65535 10.10.243.219
circle-check

What's the title of the hidden website? It's worthwhile looking recursively at all websites on the box for this step.

circle-check

What is the name of the hidden php page?

circle-check

What is the name of the hidden directory where file uploads are saved?

circle-check

Bypass the filters. Upload and execute a reverse shell.

circle-check

What is the value of the web.txt flag?

circle-check

Upgrade and stabilize your shell.

circle-check

Review the configuration files for the webserver to find some useful loot in the form of credentials. What credentials do you find? username:password

circle-check

Access the database and discover the encrypted credentials. What is the name of the database you find these in?

circle-check

Crack the password. What is it?

circle-check

Use su to login to the newly discovered user by exploiting password reuse.

circle-check

What is the value of the user.txt flag?

circle-check

Check the user's groups. Which group can be leveraged to escalate privileges?

circle-check

Abuse this group to escalate privileges to root.

circle-check

What is the value of the root.txt flag?

circle-check

Last updated