DIRTYCOW
OFFSEC - Proving Grounds - PWNLAB
·2531 words·12 mins
OFFSEC PG PRACTICE
PHP WRAPPER
MYSQL
MAGIC BYTE
PHP REVERSE SHELL
DIRTYCOW
CVE-2016-5195
Exploited PHP wrappers/LFI to access DB credentials, extract web credentials, upload a malicious GIF/PHP reverse shell, gain access, then exploit DirtyCow (CVE-2016-5195) for root.