infrahard

Подземелье (Dungeon)

hackerlab

Task: Pentest machine with Pluck CMS 4.7.13 on web and SSH service. Solution: Brute force CMS password, exploit CVE-2020-29607 for RCE, find base64-encoded SSH credentials, escalate to root via SUID cp binary to overwrite /etc/passwd.

$ ls tags/ techniques/

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]