THM | CMess
Last updated
Last updated
This is a Linux box. You can find it here.
Enumerating CMS (Gila)
Escalation via Cron Wildcards
/robots.txt
/src/
We can see there is Apache 2.4.18
/login/
on wfuzz for subdomain we found dev
dev.cmess.thm
we have the cred, now login and /admin
found this https://www.exploit-db.com/exploits/51569
and we are in
Nothing intersting was found, now let's look for find sensitive files
found .password.bak
found Andre's password
and we are in as Andre
found user.txt
let's look at crontab
I made a mistake in cmd we need '=sh\ runme.sh'
after a minute or 2, we have a bash file
and we are the root