InfoSec Write-ups
Read post

Publisher: TryHackMe CTF Walkthrough

A step-by-step walkthrough of the TryHackMe 'Publisher' CTF room, covering the full attack chain from initial reconnaissance to root access. The process involves nmap scanning, directory fuzzing with Gobuster, identifying a vulnerable SPIP CMS version, exploiting CVE-2023-27372 for unauthenticated RCE to upload a webshell, obtaining a reverse shell, pivoting to the 'think' user via an exposed SSH private key, and finally escalating to root by bypassing an AppArmor profile restriction. The AppArmor bypass involves copying bash to /var/tmp to escape the confined ash shell profile, then injecting commands into a world-writable SUID-called script.

Yesterday•7m read time•From infosecwriteups.com
Post cover image
Table of contents
1. Scanning & EnumerationWeb2. Exploitation3. Privilege EscalationGet Huzaifa Malik ’s stories in your inbox
6 Impressions
InfoSec Write-ups's image
InfoSec Write-ups

InfoSecWriteUps' platform is dedicated to providing insights and resources for cybersecurity profes...

977 Followers

•

4.1K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard