TryHackMe | h4cked

Task 1 | Oh no! We’ve been hacked!

Download the .pcap file and load it up in wireshark.

FTP port 21 connections in pcap
follow tcp stream to reveal password
ftp.command display filter
follow ftp.command TCP stream
TCP stream of STOR revealing shell.php contents
shell.php callback information
shell.php callback

Task 2 | Hack your way back into the machine

First we need to deploy the machine Deploy the machine.

nc listener
shell returned
Escalate to root



