Welcome to our OffSec Live session on Readys, a PG Practice machine: https://portal.offsec.com/labs/practice.
Join OffSec Live on Fridays: / offsecofficial .
We do demonstrations and walkthroughs of course topics and Proving Grounds machines. Additionally, sessions offer career guidance, including how to build a resume, how to break into #cybersecurity, and interview tips.
This session involved performing an Nmap scan and exploring open ports like HTTP, SSH, and Redis.
The walkthrough included steps to exploit a vulnerable WordPress plugin, which led to local file inclusion (LFI), accessing the Redis configuration, and eventually achieving remote code execution.
We then demonstrated how to combine Redis access with LFI to gain a reverse shell, followed by enumeration and privilege escalation techniques.