In this hands-on walkthrough I solve the DC-2 CTF from Vulnhub. I enumerate a WordPress site, discover user accounts with enumeration tools, brute-force credentials using WPScan, then reuse those credentials to get SSH access to the server. This is a full CTF-style walkthrough aimed at pentesting learners and CTF players.
What you’ll learn:
• How to identify exposed WordPress targets for further testing (high-level).
• How WPScan can reveal usernames and weak auth vectors (tool overview).
• Why credential reuse matters and how it leads to server access (conceptual).
• How to structure a methodical CTF approach: Recon → Enumerate → Exploit → Escalate Privileges.
Resources / Tools mentioned (overview):
================================================================
• WPScan (WordPress vulnerability scanner) — overview only.
• SSH (credential reuse concept) — overview only.
• VulnHub DC-2 VM — get it and run it locally for legal, educational practice.
🔗 Resources and Download
================================================================
Download DC-2 (VulnHub): https://download.vulnhub.com/dc/DC-2.zip
Previous Video (DC-1): • Beginner Friendly CTF Walkthrough
The Complete Pentest Plus (PT0-003) Course: https://academy.simplycyber.io/l/pdp/...
👍 Please Like and Subscribe! Your support helps us create more free, high-quality Pentesting tutorials and career-focused labs!
Chapters
================================================================
00:00 What We're Doing Today
00:35 Host Discovery w/Nmap
01:50 Scan for Open Ports w/Nmap
03:22 Enumerate Services w/Nmap
06:45 Wordpress Vuln Scan w/WPScan
08:38 Create Custom Wordlist w/Cewl
10:50 Brute-Force Login w/WPScan
15:31 Initial Access using Password Reuse
17:18 Jail Shell Escape
24:39 Horizontal Privilege Escalation
26:10 Root Privilege Escalation
#PentestingSkills #PentestingJob #CybersecurityCareer #EthicalHacking #OSCPPrep #PenTestPlus #HackingTutorial #DC2 #BootToRoot #CTFWalkthrough #BeginnerHacking #PrivilegeEscalation #Vulnhub #OffensiveSecurity #CEH #certifiedethicalhacker #oscp #ejpt #pjpt #hacker #hacking #learnhacking