URL : https://app.hackthebox.eu/machines/Beep

IP : 10.129.1.226

Recon

  • 80 port is a login pageElastix

Find Payload

LFI

RCE

  • Find RCE Codehttps://github.com/infosecjunky/FreePBX-2.10.0—Elastix-2.2.0—Remote-Code-Execution/blob/master/exploit.pyTurn nc to receive reverse shell-

Privilege Escalation

  • sudo -l check , we can sudo nmapsudo nmap --interactive