The Trial Before Christmas

Web

Video

Resources

Challenges

Scan the machine. What ports are open?

nmap -sC -sV -T5 -p1-65535 10.10.243.219

What's the title of the hidden website? It's worthwhile looking recursively at all websites on the box for this step.

What is the name of the hidden php page?

What is the name of the hidden directory where file uploads are saved?

Bypass the filters. Upload and execute a reverse shell.

What is the value of the web.txt flag?

Upgrade and stabilize your shell.

Review the configuration files for the webserver to find some useful loot in the form of credentials. What credentials do you find? username:password

Access the database and discover the encrypted credentials. What is the name of the database you find these in?

Crack the password. What is it?

Use su to login to the newly discovered user by exploiting password reuse.

What is the value of the user.txt flag?

Check the user's groups. Which group can be leveraged to escalate privileges?

Abuse this group to escalate privileges to root.

What is the value of the root.txt flag?

Last updated

Was this helpful?