InfoSec Prep: OSCP Walkthrough
reference | InfoSec Prep: OSCP |
target ip | 192.168.1.10 |
Scan with nmap
:
data:image/s3,"s3://crabby-images/28917/2891796caa0855d22d8c748bc3f9c6964208bf53" alt="nmap"
Scan with nmap
ssh-auth-methods
:
data:image/s3,"s3://crabby-images/bd437/bd4372b7291e5b03a59db4a024ed08f159df6989" alt="nmap_ssh"
Enumerate HTTP with gobuster
:
data:image/s3,"s3://crabby-images/13ec4/13ec4aa51b7054e2b771b5f21ba6ddb03b1290a8" alt="gobuster"
Request http://192.168.1.10/secret.txt
, which is a base64 encoded file:
1 | curl -s http://192.168.1.10/secret.txt | base64 -d > id_rsa |
data:image/s3,"s3://crabby-images/ea2c5/ea2c5d316334c27507697cc2870812879b3b329f" alt="id_rsa"
Enumerate wordpress, and find username from http://192.168.1.10/index.php/2020/07/09/oscp-voucher/
:
data:image/s3,"s3://crabby-images/4d5ea/4d5ea6e093d34d94abfaf9b8ed1bc0afec60832a" alt="wordpress"
Login into the system via SSH:
data:image/s3,"s3://crabby-images/8bc07/8bc07688d09c2f45a1641312ee2d2dd16cd2f4b0" alt="ssh_oscp"
Escalate from user oscp to user root, and /root/flag.txt
:
data:image/s3,"s3://crabby-images/daa6c/daa6c019cade1942061c01d66c7ff602921b3248" alt="flag.txt"
/var/www/html/wp-config.php
:
data:image/s3,"s3://crabby-images/a582b/a582beeb26172135caf786932ecd9dad56a78735" alt="wp-config.php"