↓Skip to main content

DIRTYCOW

OFFSEC - Proving Grounds - NULLBYTE
·2634 words·13 mins
OFFSEC PG PRACTICE EXIFTOOL HYDRA SQLMAP DIRTYCOW CVE-2016-5195
Exiftool reveals a hidden directory. Hydra bypasses the key, SQL injection dumps a hash, which is cracked for SSH access. DirtyCow (CVE-2016-5195) is exploited to gain root.
OFFSEC - Proving Grounds - PWNLAB
·2527 words·12 mins
OFFSEC PG PRACTICE PHP WRAPPER MYSQL MAGIC BYTE PHP REVERSE SHELL DIRTYCOW CVE-2016-5195
Exploited PHP wrappers/LFI to access DB credentials, extract web credentials, upload a malicious GIF/PHP reverse shell, gain access, then exploit DirtyCow (CVE-2016-5195) for root.