Posts

Showing posts from May, 2022

DC-1 Walkthrough - By darkxploiter

Image
  Hello all, I would like to thank you for reading this blog. Today I am going to complete another boot2root challenge of a box known as “DC-1” and all the credit goes to @DCAU for creating this box. So, our challenge is to get root access to this machine. To download this go to vulnhub.com Or  https://www.vulnhub.com/?q=dc-1 This is a beginner-level machine. Methods taken: nmap For IP discovery Network Scanning with nmap HTTP port surfing (port number 80) Finding Drupal CMS Finding Drupal version Finding exploit for Drupal version Exploiting with metasploit to get a reverse shell as a normal user Finding a way to get into the root shell Taking root shell and capturing the flag Walkthrough steps: Step 1: IP discovery: nmap -sn 192.168.56.1/24 Step 2: Network Scanning: Step 3: If we look at the nmap result we can see port 80 is open. So, we can go through this port to see what is up there. To check this I am going to open the IP on my web browser. So, here we can see a Drupal C...