Lampiao
Hey we are targeting lampiao machine
Starting with an nmap scan (full scan took a million years to finish, i loked at a writeup to get the full scan result)

Looking at the webpage on port 1898, we can find 2 users has comments on the page (2 users) quickly

Try to create an account & we wait for admin approval, which isn’t playing nice with us
looking at /robots.txt we find a lot of stuff on there

visiting different endpoints found from /robots.txt & we find interesting stuff from /CHANGELOG.txt also /web.config
Here we see the cms runs drupal 7, looking around & we can see it’s associated with a lot of vulnurabilities, you can get foothold by exploiting drupal 7
What i did here was generate a wordlist using cewl & password spray the found usernames with generated wordlist & i got a valid password used to ssh as Tiago

Using found valid password to login ssh as tiago user & we can read local.txt
Also checking for sudo permisson shows that the user tiago may not run commands as sudo

Now getting linpeas & linux exploit suggester on target machine looking for privilege escalation means & there are a lot
I decided to exploit pwnkit A.K.A CVE-2021-4034 & become root!

####RESOURCES
https://portal.offensive-security.com/proving-grounds/play
Enjoy Reading This Article?
Here are some more articles you might like to read next: