Lazy Admin

front

https://tryhackme.com/room/lazyadmin

Open Ports:

Port 80:

  1. find sub-doamisn and directories using dirb
    • ip/content (we find sweetrice)
    • ip/content/as (login Page)
    • ip/content/inc/mysqlbackup (found username and password) mysqlbackup.png

Gaining Access:

SweetRice has a Remote Code Execution vulnerablitiy

Privilege Escalation: