Перейти к содержимому

Vulnhub - InfoSecPrep: OSCP | Beginner Friendly | Road to OSCP #44

mutatedknutz

0:00 / 0:00

Vulnhub - InfoSecPrep: OSCP | Beginner Friendly | Road to OSCP #44

1 346 просмотров · 6 лет назад
mutatedknutz
1,58 тыс. подписчиков
1 346 просмотров · 6 лет назад
This is a Beginner friendly pentesting video where we will be gaining system access on Vulnhub - InfoSecPrep: OSCP machine. We will gain user access by using a base64 encoded private key. We will exploit the SUID for bash for privilege escalation. We will also exploit LXD group permissions for privilege escalation. 0:00 Intro 0:42 Enumeration using AutoRecon 03:00 Enumerating port 80 web application 04:34 Analyzing robots.txt file 06:08 Extracting openssh private key from base64 encoded secret.txt 07:50 ssh in the box as user OSCP and manual enumeration 09:17 Transferring and executing LinEnum 12:26 Finding interesting SUID binary on bash 14:20 Looking at GTFObins for bash SUID 15:02 Getting root with SUID bash 16:05 Exploiting lxd group to gain root 16:58 Locating lxd and lxc 18:28 Downloading and creating alpine build 23:18 Creating lxc image for privilege escalation 30:08 Getting access to flag.txt 30:32 lxd container explanation #vulnhub #infosecpreposcp