TryHackMe - Ignite - Walkthrough

preview_player
Показать описание
Hack into a webserver in this boot-to-root machine. Powered by Fuel CMS, we are even given valid credentials to get in the Admin panel to find XSS is one of the few vulnerabilities that are possible to exploit. We can also do Remote Code Execution(RCE) to load a PHP shell to get access as www-data, and they are kind enough to tell us where they store the database file that stores the root password. From there we switch-user(su) to root and grab the root flag.

*****Don't just watch me!*****
Ping me on TryHackMe Discord: Sevuhl
Рекомендации по теме
Комментарии
Автор

Nice walkthrough! You make very good walkthroughs! Keep up with the hard work, you deserve way more subscribers.

jamiefong
Автор

Thanks for the solution! I'm wondering why you tried to find XSS? When I logged in, I tried to change the home page to a reverse shell and it didn't work. I never thought there was an XSS. If you explain that, that will be awesome.

sekmekci
Автор

Thank you! great job! it was very helpful

ElektroDrrrEL