Shadow
This challenge demonstrates network scanning, web application enumeration and hostname resolution, exploiting OS Commerce 2.3.4.1 Remote Code Execution (RCE) with a modified exploit for a reverse shell, analyzing cron jobs using "pspy", leveraging a race condition to capture SSH keys for user pivoting, and performing Linux privilege escalation by abusing "sudo" permissions for "awk".
This challenge demonstrates network scanning, web application enumeration and hostname resolution, exploiting OS Commerce 2.3.4.1 Remote Code Execution (RCE) with a modified exploit for a reverse shell, analyzing cron jobs using "pspy", leveraging a race condition to capture SSH keys for user pivoting, and performing Linux privilege escalation by abusing "sudo" permissions for "awk".
1 Hour
Intermediate
Validation of Completion Included
Buy this course now
$19.00Challenge Overview
What You Will Learn
- Performing network scanning and enumeration to discover services, open ports, and potential vulnerabilities on the target Linux Ubuntu system.
- Identifying and exploiting vulnerabilities in OS Commerce 2.3.4.1 to gain unauthorized access to the web server.
- Using Remote Code Execution (RCE) techniques to execute commands on the compromised system.
- Establishing reverse shell access to gain interactive control over the target machine.
- Exploiting web application weaknesses and system misconfigurations to escalate privileges and obtain root access.
Program Curriculum
Buy this course now
$19.00Couldn't load pickup availability
Get Immediate access for one year today!
Upgrade to Pro Plans and Get Full Access Today!
Get this course, along with 900+ courses and 70+ learning paths and more in one subscription. Learn more
Unlock All AccessPlans start from $33/mo. Cancel anytime.
Join over 1 Million professionals from the most renowned Companies in the world!
Choose the Pro Plan That Fits Your Learning Journey
Invest in your future with flexible Pro subscription plans. Whether you're starting your cybersecurity journey or expanding your expertise, choose the membership duration that works for you and gain access to our complete learning platform.
Pro
Ideal for continuous learning, offering extensive resources with 900+ courses and diverse Learning Paths to enhance your skills.
What is included
- Access to 900+ Premium Short Courses
- 70+ Structured Learning Paths
- Validation of Completion with All Courses and Learning Paths
- New Courses Added Every Month
Pro +
Experience immersive learning with Practice Labs and CTF Challenges for comprehensive skill-building.
Everything in Pro and
- 500+ Practice Labs with Guided Instructions
- 400+ CTF Challenges with Detailed Walkthroughs
- New Practice Labs and Challenges Added Every Month
Pro
Ideal for continuous learning, offering extensive resources with 900+ courses and diverse Learning Paths to enhance your skills.
What is included
- Access to 900+ Premium Short Courses
- 70+ Structured Learning Paths
- Validation of Completion with All Courses and Learning Paths
- New Courses Added Every Month
Pro +
Experience immersive learning with Practice Labs and CTF Challenges for comprehensive skill-building.
Everything in Pro and
- 500+ Practice Labs with Guided Instructions
- 400+ CTF Challenges with Detailed Walkthroughs
- New Practice Labs and Challenges Added Every Month
Related CTF Challenges
-
This challenge focuses on Windows digital forensics and incident response. Participants analyze Security, System, and Task Scheduler event logs to identify attacker activity, trace a persistence mechanism involving scheduled tasks and services, correlate user activity with logon sessions, and reconstruct the attack timeline.
This challenge focuses on Windows digital forensics and incid...
$19.00Hello
-
This challenge focuses on network forensic analysis and investigating data exfiltration. Participants will use Wireshark to inspect a packet capture file, filter for HTTP traffic, and export transferred HTTP objects. The objective is to safely extract and analyze exfiltrated PDF documents to uncover a hidden flag.
This challenge focuses on network forensic analysis and inves...
$19.00Hello
-
This challenge provides a guided walkthrough of disk forensics and image analysis using Autopsy. Participants must load the forensic disk image, analyze web server logs to uncover malicious encoded payloads, identify anti-forensic techniques such as file extension mismatches, and perform file carving to recover deleted files.
This challenge provides a guided walkthrough of disk forensic...
$19.00Hello
-
As a cryptographic engineer at BrownLine IT Tech Solutions in Atlanta, your mission is to crack a vulnerable password-based authentication system created by a colleague. Use your skills to break the code, log in, and capture the flag.
As a cryptographic engineer at BrownLine IT Tech Solutions in...
$19.00Hello
-
This challenge focuses on service exploitation and system misconfiguration using various tools. Participants will demonstrate SMB password cracking, Hydra, and ssh2john techniques, along with evaluating SSH private key passwords. The exercise also includes SSH key brute-forcing and SMB enumeration to identify and exploit system vulnerabilities effectively.
This challenge focuses on service exploitation and system mis...
$19.00Hello
-
This challenge focuses on web and service exploitation using various tools to identify and exploit vulnerabilities. You will enhance network scanning skills to gather critical target information and apply SSH cracking techniques to uncover and exploit weaknesses. The exercise emphasizes essential penetration testing methods, including credential brute-forcing and service misconfiguration analysis.
This challenge focuses on web and service exploitation using ...
$19.00Hello
-
This challenge involves scanning and enumerating a ChatOps web app to find flaws. Intercept WebSocket traffic with Burp Suite, modify JSON payloads, and exploit a weak password reset to take over a supervisor account. Log in with elevated access and retrieve the flag.
This challenge involves scanning and enumerating a ChatOps we...
$19.00Hello
-
This challenge involves cryptography and a creative Linux privilege escalation path. Participants must first decrypt a Vigenère cipher found on a web page to obtain SSH credentials for initial access. Privilege escalation is then achieved by exploiting a combination of sudo permissions for the reboot command and a user-writable systemd service file to trigger a reverse shell upon reboot.
This challenge involves cryptography and a creative Linux pri...
$19.00Hello