HYDRA
OFFSEC - Proving Grounds - NULLBYTE
·2634 words·13 mins
OFFSEC PG PRACTICE
EXIFTOOL
HYDRA
SQLMAP
DIRTYCOW
CVE-2016-5195
Exiftool reveals a hidden directory. Hydra bypasses the key, SQL injection dumps a hash, which is cracked for SSH access. DirtyCow (CVE-2016-5195) is exploited to gain root.
OFFSEC - Proving Grounds - BORN2ROOT
·1871 words·9 mins
OFFSEC PG PRACTICE
HYDRA
Initial access is gained via an SSH key in icons. A cronjob is abused for a jimmy shell, then Hydra finds hadi’s reused password, enabling root access.
OFFSEC - Proving Grounds - FOWSNIFF
·2734 words·13 mins
OFFSEC PG PRACTICE
POP3
HYDRA
MOTD
GitHub credentials enable POP3 access to retrieve an SSH password. Hydra finds valid credentials for SSH access. A writable cube.sh used by the MOTD is abused to gain root.
OFFSEC - Proving Grounds - POSTFISH
·3193 words·15 mins
OFFSEC PG PRACTICE
SMTP-USER-ENUM
USERNAME_GENERATOR
HYDRA
IMAP
IMAPS
SENDEMAIL
PWNKIT
Website PostFish on port 80 and SMTP on port 25 reveal usernames. Hydra finds credentials, sending an email with a reset link grants brian access. Pwnkit (CVE-2021-4034) escalates to root.
OFFSEC - Proving Grounds - BANZAI
·2971 words·14 mins
OFFSEC PG PRACTICE
HYDRA
GOBUSTER
MYSQL
MYSQL UDF
GCC
FTP on port 21 with weak credentials holds web dirirectory for port 8295. Upload PHP shell to gain initial access. MySQL UDF exploit sets SUID on bash and allows us to escalates to root.