If you're like me you enjoy a good CTF challenge VM from Vulnhub. What makes it more interesting is when it's intended for those studying for the OSCP! Such is the case with the AdmX 1.0.1 machine which you can download here
https://www.vulnhub.com/entry/admx-10...
Pentestmonkey PHP Reverse Shell
http://pentestmonkey.net/tools/web-sh...
#oscp #offensivesecurity #vulnhub #ctf #ctfwalkthrough #admx #hacking #cybersecurity #ethicalhacking #kali #kalilinux #pentesting #penetrationtesting #pentester #hacker #ethicalhacker #ethicalhacking
=========
Chapters
=========
0:00 CTF Description
2:02 Nmap Scan Results
2:24 My Basic Web App Testing Methodology
2:53 Directory Fuzzing with Gobuster
5:02 Vulnerability Scanning with Nikto
6:02 Gobuster and Nikto Results
6:58 Enumerate, Enumerate, Enumerate!!!
7:30 Back to Nikto and Gobuster Results
8:30 Scanning /tools dir with Nikto
10:08 A Word About Wordpress
10:42 Time Management Tip
11:10 Gobuster Scan Finishes
11:22 Fuzzing /tools dir with Gobuster
13:38 Inspecting phpinfo.php
17:41 Inspecting the Wordpress Site
18:19 This Is Where It Got Interesting
21:11 Why Does This Site Look Like Junk?
24:00 How Do I Fix This Site?
26:00 IPTables to the Rescue!
29:19 Vulnerability Scanning with WPScan
31:32 Rabbit Trails are Fun
35:41 Brute-Force Wordpress Login
37:40 Login to Wordpress Site
38:27 Get Reverse Shell
45:33 Start Priv Esc with User Enumeration
48:00 Horizontal Priv Esc
49:45 Vertical Priv Esc to Root
54:04 Run OS Commands in MariaDB
54:50 Closing Thoughts