HackTheBox - Shocker

If you want some more details about the actual ShellShock exploit, check out the Beep Video. 00:39 - Begin Nmap, OS Enum via SSH/HTTP Banner 05:00 - GoBuster 07:08 - Viewing CGI Script 08:50 - Begin NMAP Shellshock 09:50 - Debugging Nmap HTTP Scripts via Burp 11:10 - Fixing the HTTP Request & nmap script 14:45 - Performing Shellshock & more fixing 18:25 - Getting a reverse shell 21:19 - Running 23:00 - Rooting the box
Back to Top