DC-2 VulnHub Walkthrough

Today we will explore the DC-2 machine. This takes us from a WordPress site to a restricted shell, and finally to a binary with minimal sudo permissions.

Phase 1: Recon

Nmap revealed only two open ports: an HTTP server and an SSH server.

The website at first appears to be down, and by default, it points us toward another site. It is not part of the CTF, and it is someone’s private site. Do not attempt anything on this site, it is potentially illegal and just plain rude.

Website

Tags: DC-2 VulnHub