-
You’ll find this vm in HackMyVM
https://hackmyvm.eu/machines/machine.php?vm=CelebritySoup
-
Difficulty : easy
Port scan
1 |
|
Dir scan
1 |
|
Robots.txt
1 |
|
Zsteg
1 |
|
Binary to Ascii using perl
1 |
|
SSH attempt
username master (like image name) and password the decoded binary
1 |
|
Searching for the username
creating bash script
1 |
|
run the script
1 |
|
[Username is puppetmaster and not master]
SSH login
1 |
|
Priv Esc
1 |
|
strings
1 |
|
Root
1 |
|