[HackTheBox] Bashed

--

This is quite an elementary box to do on HTB.

Even before the nmap scans came back I saw this and had only one thing in my mind : “The Foothold is mine”

Dirbuster soon came up with these results and now basically i had a webshell.

ezpz

Priviledge Escalation:

This Is A two step process on this box, but none the less its really elementary.

Basically /bin/bash gave us lateral privEsc.

Now this was interesting.

Updated that script just in case :D

On a different note, I could use pspy to scout out when this gets executed if at all since this wasnt present in the /etc/crontab.

Now this was sad…

A few moments later I got a revShell. huh….

Sign up to discover human stories that deepen your understanding of the world.

Free

Distraction-free reading. No ads.

Organize your knowledge with lists and highlights.

Tell your story. Find your audience.

Membership

Read member-only stories

Support writers you read most

Earn money for your writing

Listen to audio narrations

Read offline with the Medium app

--

--

Siddharth Johri
Siddharth Johri

Written by Siddharth Johri

To hack the world, first you need to make coffee

No responses yet

Write a response