HackMyVM
Enumeration
Port 80
Home page return a 403 code. So start to fuzzing
upload.html
Upload a php reverse shell
Intercept the request and go to the final of the request. Change the uploads/
to ./
a
Start the listerner and access $IP/reverse.php
User
Putting our private key to melisa’s authorized_keys
SSH
Has a service running on port 4444
We can check using nc
Root
We can use man binary to spawn a shell has a root