Enumeration

1
export target=10.129.48.60

Port Scanning

1
rustscan -a $target --ulimit 10000 -g
1
nmap -Pn -sC -sV -n -p22,80 -T5 $target

Initial Foothold

PHP version is 8.1.0-dev

It has a RCE exploit (www.exploit-db.com/exploits/49933)

Persistence

1
ssh-keygen -t ed25519 -f persist -N ''
1
2
3
4
5
6
7
$ mkdir ~/.ssh

$ chmod 700 ~/.ssh

$ echo "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINxWXXtr3AsLHPThSrbfRuFUTfqCcghxiINCr9pz5rEg burak@kali" > ~/.ssh/authorized_keys

$ chmod 600 ~/.ssh/authorized_keys

Privilege Escalation

GTFOBins

Key Takeaways

  • Check technology and version info in HTTP response headers; backdoored versions like PHP 8.1.0-dev can give instant RCE.
  • Look up every binary from sudo -l output on GTFOBins; even niche tools like knife can have shell escape methods.
  • After getting your initial shell, establish persistence with an SSH key; you won’t need to re-run the exploit if your reverse shell drops.