Sitemap

TryHackMe Box Walkthrough : Inclusion

3 min readJun 14, 2021

A basic level LFI challenge for beginner.

Press enter or click to view image in full size

Lets launch the machine before launching the machine make sure your vpn is connected. After Launching we will get ip of the machine.

Press enter or click to view image in full size

Reconnaissance

Starting with a simple nmap scan

Command : nmap -sC -sV -p- — min-rate=10000 -oN nmap <machine_ip>

Press enter or click to view image in full size

We see that 2 ports are open 22 (SSH), 80 (http). It means there must be a webpage.

Press enter or click to view image in full size

We get this page and as we know it is an LFI challenge but there is no parameter in the URL to inject our LFI payload. So when we click on the LFI-attack to see we get any parameter.

Press enter or click to view image in full size

we got a parameter ?name=lfiattack. As we went inside the LFI attack we found some information about how LFI vulnerabilty works. So I will try LFI attack on this webpage.

../../../etc/passwd

Press enter or click to view image in full size

We will use this credentials to login with SSH.

ssh falconfeast@<IP>

rootpassword

Press enter or click to view image in full size

We found our first flag now copy and paste the flag in THM.

Press enter or click to view image in full size

Privilege escalation

To escalate our privilege we will what commands can we run as root.

sudo -l

I will go to GTFO Bins to see what payload or command is available for /usr/bin/socat.

Press enter or click to view image in full size

sudo socat stdin exec:/bin/sh

Successfully Escalated Privilege to Root now I will look for root flag.

Finally we found the root flag. Copy and paste the flag in THM site and finish the challenge.

Press enter or click to view image in full size

If you found this usefull do leave a clap.

--

--

Aditya Kumar
Aditya Kumar

Written by Aditya Kumar

B.Sc IT Graduate with C.E.H certification currently pursuing Offensive Security (Red Team). Passion for MMA and Kick-boxing & Automobile Enthusiast.

No responses yet