Snookums
Last updated
Last updated
Found an unusual print$ share
Website on port 80
So searching for exploits for this we end up with: https://github.com/beauknowstech/SimplePHPGal-RCE.py Now using it we didnt get a shell on most ports but port 21 works.
Found
Then using another shell to get a stable shell:
Now conencting to mysql:
now checking tables:
Now using this hash:
We can switch to our root user:
Now base64 decoding twice:
Now we can use this to ssh:
Then running linpeas we find writeable /etc/passwd: So adding our own user: