Posts

Showing posts from May, 2021

Helping Rick find his ingredients: PICKLE RICK CTF

Image
Hello Hackers,  Today we are going to solve the challenge  PICKLE RICK  by  TRYHACKME . So the story goes like this: Our friend Rick has turned into Pickle [Really don't know how he ended up being a Pickle :P] and our goal is to find him 3 Secret ingredients so that he can go back to his original form. Let's jump into the CTF. First things first  CONNECT TO OPENVPN & DEPLOY THE MACHINE😂 We'll see this page as we put the IP address into our browser. REMEMBER:  Whenever you visit a webpage, don't forget to check the source code. Sometimes, developers leave sensitive information such as credentials in the form of comments. You can either do Right-Click --> View page source or press Ctrl+u. You'll see that the username is leaked in the source code of that page! Now let's try to scan the ports and see if we find something interesting. Command used: nmap -sV -A -T5 {ip} You'll see that ports  22 & 80 are open. Wait, can the username be for the ssh

Defeating RootME

Image
Hello hackers, Recently I started practicing on  Tryhackme  and came across this easy yet interesting machine named RootME by  ReddyyZ . I strongly recommend the beginners to try this machine out as it would clear the following several concepts of yours one of them being how to bypass file upload functionality and gain a reverse shell on the target system. Not only that, but you'll also have a basic idea about how privilege escalation works. So without taking up any more time of yours, let's jump into the walkthrough.                                                                                        : TASK 1 : Deploying the machine😅 While some of you might think what madness this is we already know that!! My dear friend, you're free to skip this portion then😊😌. Step 1: Connect to OpenVPN [Check the OpenVPN room so that you have an idea] Command used: openvpn {your openvpn file}   Step 2: Click on Start Machine or Start Attack Box. [ I think you can do this:) ] Step