InfoSec Write-ups
Read post

Intro. Hey everyone! Today we’re solving the…

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A beginner-friendly walkthrough of the TryHackMe RootMe CTF room covering web enumeration with Nmap and Gobuster, exploiting a file upload vulnerability by bypassing a PHP extension filter using .php5, deploying a pentestmonkey PHP reverse shell to gain initial access as www-data, and escalating privileges to root by abusing a SUID bit set on Python2.7 using a GTFOBins technique.

    #security#php
Aug 05•9m read time•From infosecwriteups.com
Post cover image
Table of contents
Task 3 — Getting a ShellExploring the WebsiteTesting the UploadPreparing a PHP Reverse ShellFirst Attempt — Permission DeniedBypassing the FilterUpload Successful!Setting Up the ListenerTriggering the Reverse ShellGet Krish Gupta ’s stories in your inboxFinding user.txt
1.6K Impressions
InfoSec Write-ups's image
InfoSec Write-ups

InfoSecWriteUps' platform is dedicated to providing insights and resources for cybersecurity profes...

977 Followers

•

4.1K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard