ScriptKiddie is an easy difficulty Linux machine that presents a Metasploit vulnerability (CVE-2020-7384), along with classic attacks such as OS command injection and an insecure passwordless sudo configuration.
Initial foothold on the machine is gained by uploading a malicious .apk file from a web interface that calls a vulnerable version of msfvenom to generate downloadable payloads.
This user is allowed to run msfconsole as root via sudo without supplying a password, resulting in the escalation of privileges.
Hope you guys enjoyed the episode. For any questions feel free to ask them in comment section or on our social network.
------------------------------------------------------------------------------------------------------------
Social Networks:
Facebook- / hackerassoci. .
LinkedIn- / hack.... .
Twitter- / hackerasociate
------------------------------------------------------------------------------------------------------------
Thank you for watching. Stay connected.
#HTB #ScriptKiddies #Walkthrough