Horizontall
Last updated
Last updated
Enumeration machine.
Source code of home page.
To read the js code better, we can use js-beautify.
We have to add new dns to our hosts.
Dirsearch.
Source code of one of the results from dirsearch.
We can find version of Strapi CMS.
Searching exploit for it.
Running exploit.
First flag.
Privilege escalation.
netstat -a
The netstat command displays the contents of various network-related data structures for active connections.
Version of system architecture.
Now we have to make a pivoting / port forwarding to our machine.
Downloading Chisel.
Starting chisel on our machine.
Downloading chisel from our http server and connecting to our kali from victim machine.
New site discovered - Laravel.
We can find version of Laravel.
and exploit...
Running exploit and getting root flag.
To get an root account...
Linpeas results:
Running exploit and getting root.
Getting root.
Instruction: