#
 
Nmap Output:
 
 
ftp
 
 
Let's download the files from ftp to our own machine
 
 
We can see that the clean.sh script works over time if we look at the contents of the removed_files.log file.
 
Let's create the clean.sh reverse shell bash script from our own machine and put it in FTP with the same name.
 
 
wait for the shell and boom!
 
 
In the output of the if command, we see that the lxd container service is running on the machine. This solution is also available on the site. "gaming_server".
 
 
Let's scan SUID files.
 
 
GTFObins
 
 

/path/to/env /bin/sh -p