-
You’ll find this vm in HackMyVM
https://hackmyvm.eu/machines/machine.php?vm=CelebritySoup -
Difficulty : easy
Port scan
1 | |
Dir scan
1 | |
Robots.txt
1 | |
Zsteg
1 | |
Binary to Ascii using perl
1 | |
SSH attempt
username master (like image name) and password the decoded binary
1 | |
Searching for the username
creating bash script
1 | |
run the script
1 | |
[Username is puppetmaster and not master]
SSH login
1 | |
Priv Esc
1 | |
strings
1 | |
Root
1 | |