Instant

Recon

nmap_scan.log|h-50%_styled

HTTP

Writeup.png

APK

Decompile APK with https://www.decompiler.com/jar/3b652ecd27c6422cb944b974af1945a1/instant.apkarrow-up-right

Writeup-1.png

Update hosts:

API actions:

More subdomains:

Writeup-2.png
Writeup-3.png

Possible LFI:

Writeup-4.png

SSH

User.txt

Privilege Escalation

Hashes doesn't seem crackable...

SolarPuttyDecrypt - Blog Postarrow-up-rightSolarPuttyDecrypt - GitHubarrow-up-right

Reverse Engineering Solar-PuTTY 4.0.0.47arrow-up-right

Creds: root:12**24nzC!r0c%q12

Root.txt

Hashes

Past Root

C# -> Python

Last updated