infraProhard

Подземелье (Dungeon)

hackerlab

Task: Pentest machine with Pluck CMS 4.7.13 on web and SSH service. Solution: Brute force CMS password, exploit CVE-2020-29607 for RCE, find base64-encoded SSH credentials, escalate to root via SUID cp binary to overwrite /etc/passwd.

$ ls tags/ techniques/

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups