Zipping
Gaining Access
$ nmap -p- --min-rate 3000 10.129.114.241
Starting Nmap 7.93 ( https://nmap.org ) at 2023-08-27 17:27 +08
Nmap scan report for 10.129.114.241
Host is up (0.17s latency).
Not shown: 64643 closed tcp ports (conn-refused), 890 filtered tcp ports (no-response)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http$ nmap -p 80 -sC -sV --min-rate 4000 10.129.114.241
Starting Nmap 7.93 ( https://nmap.org ) at 2023-08-27 17:28 +08
Nmap scan report for 10.129.114.241
Host is up (0.17s latency).
PORT STATE SERVICE VERSION
80/tcp open http Apache httpd 2.4.54 ((Ubuntu))
|_http-title: Zipping | Watch store
|_http-server-header: Apache/2.4.54 (Ubuntu)Web Enumeration -> Zip File LFI





SQL Injection Fail

Null Byte Bypass -> RCE




Privilege Escalation
Sudo Privileges -> Stock Binary
Shared Library Exploit -> Root

Last updated