http [Initial Access]

Looking at the page

Looking for hidden directory

circle-info

All font end files are there.

Trying exploit [Failed]

Noting much found also there is not vaild exploit for this version which is mentioned on the website.

tried below one:

Failed !!

Trying exploit [Worked] πŸ†—

I ran the exploit as said but not getting a shell.

Reading exploit and doing manual exploitation.

I can see exploit code which is responsible for running php reverse shell.

Let's check if i can run it manually.

Getting this box suggests that the exploit is running but unable to load google.com.

let's Use RFI, To uplaod and run the reverse shell.

  1. Start the reverse shell on port 443

  1. Get the php reverse shell and change ip and port.

  1. Start python server on port 80

  1. Running command

Not worked on port 443. Trying port 21.

Got the shell.

Making a directory for myself and switching to the bash shell.

Last updated

Was this helpful?