Logo
Web01
Ch4os1@web01:~/writeups/Knife
← Back to all write-ups

Knife

Lab Details

Tasks

Q1: How many ports on running on the target machine

Q3: What HTTP Header can you use to perform inject

Q4: What user is the web server running as?

Q5: Submit the flag located in the James user's home directory.

Q6: Submit the flag located in root's home directory.

╔══════════╣ Checking 'sudo -l', /etc/sudoers, and /etc/sudoers.d
╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-and-suid                                                                                                                                                
Matching Defaults entries for james on knife:                                                                                                                                                                                   
   env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User james may run the following commands on knife:
   (root) NOPASSWD: /usr/bin/knife