Armageddon From Hack The Box
Hello everyone, welcome to my second blog. In this blog I'm gonna show you how to get root for armageddon machine which is a easy machine from Hack The Box, done by Bertolis. Lets begin, Lets start with nmap scan So there are only 2 ports open 1) 22 : SSH 2) 80 : HTTP Since we have an open HTTP port lets add our target machine to our /etc/hosts file and start enumerating. Now after a lot of enumeration on the website I got nothing then I went to search what server and what CMS inlcuding its version, this website is using using wappalyzer. We can also find what CMS and what version, it is using from the source code. This website is using Drupal CMS version: 7 After knowing the Drupal version lets recon for any known vulnerabilities. After some time looking for exploits in google I finally found the correct exploit in rapid7. And yes we will be doing this machine using Metasploit. After some time I will post how to do this machine without using Metasploit. Let's fire...