[THM] Magician box write-up ctf

[THM] Magician box write-up ctf

·

1 min read

First let's enumerate the machine with an nmap scan

image.png

add the ip to the correct DNS as the box want in /etc/hosts file

image.png

image.png

as we can see is a simple site to convert .png to .jpg, to began let's find a payload related to file upload after searchs i've find this who using netcat to send the connection

image.png

after uploading with receive the connection !

image.png and we can get the user flag will simply go to user folder

after searching trough many ways to privesc i've found that the machine has a weird port open

image.png so lets make pivoting with chisel, after that we will simply get a shell and we will need to cat the /root/root.txt to get the root flag encoded in base64, juste decode it with cyberchef and here we go ! we are root