$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Pentest machine with Pluck CMS 4.7.13 on web and SSH service. Solution: Brute force CMS password, exploit CVE-2020-29607 for RCE, find base64-encoded SSH credentials, escalate to root via SUID cp binary to overwrite /etc/passwd.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar