Information Gathering

  • 掃 Port觀察 80 port-
  • HFS 2.3

尋找 Exploit

  • 找到https://www.exploit-db.com/exploits/39161
  • 需要準備 ncwget https://github.com/int0x33/nc.exe/raw/master/nc.exe依照需求開 http server- python3 -m http.server 80
  • 放 nc執行腳本- 收到 Reverse shell- 取得 User flag-

提權