[HackTheBox] Nibbles

--

This box didn’t Require any reconnaissance since I looked at the home page of the website and knew exactly what was to be done.

nibbleblog has a very cliched RCE which only requires some credentials which I hoped to guess.

admin:nibbles worked.

After that it was the most basic exploit.

Now lets work on Privilege Escalation.

Privilege Escalation:

This file was owned by me hence I could edit it.

PWNED!!

Apart from the guessing part this was pretty easy.

Sign up to discover human stories that deepen your understanding of the world.

Free

Distraction-free reading. No ads.

Organize your knowledge with lists and highlights.

Tell your story. Find your audience.

Membership

Read member-only stories

Support writers you read most

Earn money for your writing

Listen to audio narrations

Read offline with the Medium app

--

--

Siddharth Johri
Siddharth Johri

Written by Siddharth Johri

To hack the world, first you need to make coffee

No responses yet

Write a response