DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Simple CTF - TryHackMe writeup

Beginner level ctf

EasyLinuxCVE-2019-9053SQL injectionSudo abuse6 min read

Open the room on TryHackMe ↗ View on GitHub

Task 1. Simple CTF

Deploy the machine and attempt the questions!

How many services are running under port 1000?

2

What is running on the higher port?

ssh

What's the CVE you're using against the application?

CVE-2019-9053

As a result, we will find a page http://10.10.10.10/simple/ when we go to it, in the lower left corner, we see what CMS this page was created, it turned out to be "CMS Made Simple 2.2.8" google - CMS Made Simple 2.2.8. Exploit The very first page https://www.exploit-db.com/exploits/46635 shows that this The CMS is vulnerable to SQL injection and a python exploit has been prepared for this vulnerability (you can find a copy of the file https://github.com/BEPb/tryhackme/blob/master/01.easy/Simple%20CTF/exploit.py) command to download the file to

To what kind of vulnerability is the application vulnerable?

sqli

What's the password?

secret

Where can you login with the details obtained?

ssh

What's the user flag?

G00d j0b, keep up!

Is there any other user in the home directory? What's its name?

sunbath

What can you leverage to spawn a privileged shell?

vim

What's the root flag?

W3ll d0n3. You made it!

Done 😄