Post

HackTheBox_Shocker | w/ Metasploit

HTB - Shocker

Overview

Untitled

Shocker is a Linux machine on Hack The Box, focusing on exploiting the Shellshock vulnerability. The machine is a good practice for privilege escalation techniques.

Enumeration

nmap scan results

Untitled

Directory busting results

The following directories were found during enumeration:

1
2
3
4
5
- /
- /cgi-bin/  → user.sh
- /icons/
- /icons/small/

Untitled

There might be potential for script execution here:

Untitled

Vulnerabilities

PORT 40/TCP

PORT 2222/TCP

Directory Vulnerability

  • /cgi-bin/user.sh - Shellshock

Exploitation

Exploiting Shellshock vulnerability

Untitled

User Flag

Starting with the user flag:

Untitled

Privilege escalation

Initially, access to the root directory was restricted, indicating lower privileges:

Untitled

After escalating privileges:

Untitled

Root Flag

Finally, the root flag was captured:

Untitled

Pwned.

This post is licensed under CC BY 4.0 by the author.

Comments powered by Disqus.