type
status
date
slug
summary
tags
category
icon
password
Catagory
Materials
Retired
Retired
Due date
Jan 16, 2024 05:30 AM
Status
Belong in

Progress

Reconnaissance

notion image

Scan the box; how many ports are open?

6

What version of the squid proxy is running on the machine?

3.5.12

How many ports will Nmap scan if the flag -p-400 was used?

400

What is the most likely operating system this machine is running?

Ubuntu

What port is the web server running on?

3333

What is the flag for enabling verbose mode using Nmap?

-v

Locating directories using gobuster

notion image
notion image
notion image
notion image

Compromise the Web server

notion image
notion image

What common file type you'd want to upload to exploit the server is blocked? Try a couple to find out.

.php

Run this attack, what extension is allowed?

notion image
fuzz the extensions
notion image
notion image
notion image

User flag

prepare the webshell & upload
notion image
notion image
notion image
notion image
notion image

Privilege Escalation

 
notion image

On the system, search for all SUID files. Which file stands out?

/bin/systemctl
notion image
notion image
notion image

Root Flag

a58ff8579f0a9270368d33a9966c7fd5

Reference

OutlookOperation ModuleTryHackMe - GameZone