HackMyVM
Enumeration
Port 80
Wireshark
On TCP stream 2. We can see a zip
file
File > Export Objects > HTTP → Download the file
This zip has a image and it’s a QRCode, go to https://zxing.org/w/decode.jspx and decode this image
User
This file it’s the jackob private key
Root - Part 1
We can create a new attack.sh file and add /bin/bash
inside this file
Changed the file of attack.sh to attack.bkp
Create a new file called attack.sh and add:
Now use sudo has kratos
Root - Part 2
The cppw binary allows us to changed passwd or shadow file
We can use makepasswd
to create a new passwd and changed /etc/passwd
file
Get the output password and create a file with it