80
Last updated
Last updated
There could be a possibility of LFI.
We get home.html
We don't mention .php here because it seems .php
is appended to the filename.
There seems to be .php added to the end We can also get upload.php the same way:
We can upload our reverse shell: We get click here to download the file: We get the name of the file. This zip will have our payload.php file.
To get a shell:
Running linpeas.sh: We find root running a cron job.
We can do a wildcard spare trick: Then we can use this to our advantage:
Already enox.zip was present and linked to /root/secret so the password was already present: We have the secret. Using the password: We are root