Skip to main content

MAGIC BYTE

OFFSEC - Proving Grounds - PWNLAB
·2531 words·12 mins
OFFSEC PG PRACTICE PHP WRAPPER MYSQL MAGIC BYTE PHP REVERSE SHELL DIRTYCOW CVE-2016-5195
Exploited PHP wrappers/LFI to access DB credentials, extract web credentials, upload a malicious GIF/PHP reverse shell, gain access, then exploit DirtyCow (CVE-2016-5195) for root.
OFFSEC - Proving Grounds - PRESS
·1470 words·7 mins
OSCP OFFSEC PG PRACTICE MAGIC BYTE
FlatPress on port 8089 allows login with weak credentials, PHP reverse shell upload via GIF magic byte, and privilege escalation to root using sudo apt-get.