Kioptrix Level 2 Walkthrough
Kioptrix level 2 is a boot-to-root machine. Let's hack this machine! Setup is same as kioptrix level 1. So first, we need to find the ip address of the machine. So,192.168.56.103 is the ip address of the Kioptrix level 2 machine. Let's run nmap scan: 192.168.56.103 As per our scan, we have SSH, a website , CUPS and MySql running. I tried connecting to ssh, nothing happened. Also, I couldn't find the exploit for this version openssh. Website Let's check out the website: http://192.168.56.103:80 Well, the website has a login form. Let's see if it is vulnerable for sql injection. Boom!! We got in! This might be vulnerable for command injection. Let's try. Well, it is vulnerable to command injection!! We have apache user permissions. So, we need to try escalate our privileges to root by using a local privilege escalation. For that, let's find the details of OS version and linux kernel. So, we have know that li...