inframedium

Скрипт-кидди (Script-kiddie)

hackerlab

Task: Pentest machine with WordPress site requiring initial access and privilege escalation. Solution: Exploited CVE-2019-9978 in Social Warfare plugin for RCE, used password reuse for SSH access, then GTFOBins nano privesc via sudo to read root flag.

$ ls tags/ techniques/
WordPress plugin vulnerability exploitation (CVE-2019-9978)Password reuse (DB credentials → SSH)GTFOBins nano privilege escalationTwo-part flag assembly

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]