CyberSecLabs - Shock - Linux [Walkthrough]
PinkDraconian
ā¶ļø YouTube: https://www.youtube.com/c/PinkDraconian š¦ Twitter: https://twitter.com/PinkDraconian šµ TikTok: https://www.tiktok.com/@pinkdraconian ā¹ļø LinkedIn: https://www.linkedin.com/in/robbe-van-roey-365666195/ š Discord: PinkDraconian#9907 š· Instagram: https://www.instagram.com/robbevanroey/ šøļø Website: http://pinkdraconian.d4rkc0de.com/ šØāš» HackTheBox: https://www.hackthebox.eu/home/users/profile/129531 Twitter: https://twitter.com/PinkDraconian Discord: PinkDraconian#9907 Website: http://pinkdraconian.d4rkc0de.com/
Platform: CyberSecLabs
Platform Link: https://www.cyberseclabs.co.uk/
Category: Machine
OS: Linux
Challenge name: Shock
Difficulty: 1/10
00:00 Introduction 00:10 Nmap scan 00:40 Running gobuster to search for directories 01:20 We find cgi-bin folder, scanning that 02:10 Searching for apache cgi exploits, finding shellshock 02:50 Exploiting apache shellshock in metasploit 04:20 Explaining shellshock 06:40 Uploading and running linpeas using meterpreter 07:30 Sudo -l shows we can execute socat as root ... https://www.youtube.com/watch?v=AWyS60GMZzs
79140773 Bytes