type
status
date
slug
summary
tags
category
icon
password
Catagory
Materials
Retired
Retired
Due date
Jan 16, 2024 05:32 AM
Status
Belong in

Progress

Scan the valid services

notion image
notion image
notion image
notion image
notion image

Searching the RCE payload

notion image
first try to get rce
notion image
notion image
☝🏻
system() function was disabled. That’s try other function

Create the paylods using msfvenom

notion image

Payloads

notion image

Get reverse shell

notion image

Root.txt

notion image

save registry record

notion image
notion image

back to the attack machine to get the file

notion image

samdump2 to dump hash

notion image

using john the ripper to brute force the hash

notion image

Reference

osCommerce-2.3.4-Remote-Command-Execution
nobodyatall648Updated Aug 14, 2023
Tryhackme - WonderlandRunspace練習