Hack Me Please : 1
Description ⤵️
💡 Hack Me Please: 1 ➡️
Difficulty: Easy
Description: An easy box totally made for OSCP. No bruteforce is required.
Aim: To get root shell
Let’s find the IP Address first »
1
IP : 10.0.2.27
Port Scan Results ➡️
1
2
3
4
OPEN PORTS >
80 HTTP
3306 mysql
33060 mysqlx
Web Enumeration ⤵️
I did directory listing with Feroxbuster
Tool.
While checking the source code of /js/main.js
file, I got a hint for a directory.
/seeddms51x/seeddms-5.1.22/
With hid & try
method I used seeddms
as username & password →
Employee_id | Employee_first_name | Employee_last_name | Employee_passwd |
---|---|---|---|
1 | saket | saurav | Saket@#$1337 |
I was now able to crack the password So I changed it → to admin
Now the updates credentials are →
Lets try it now →
I got the access →
Added the reverse shell →
Now it is time to load the shell file →
ROOT !!
Summery Notes →
💡
- Tricky part was to find the
/js/main.js
file . After that the path becomes very easy .- And also the updation of password was new for me .
- rest all was very easy peasy ..
If you have any questions or suggestions, please leave a comment below. Thank You !
This post is licensed under CC BY 4.0 by the author.