A step-by-step walkthrough of the TryHackMe 'Publisher' CTF room, covering the full attack chain from initial reconnaissance to root access. The process involves nmap scanning, directory fuzzing with Gobuster, identifying a vulnerable SPIP CMS version, exploiting CVE-2023-27372 for unauthenticated RCE to upload a webshell, obtaining a reverse shell, pivoting to the 'think' user via an exposed SSH private key, and finally escalating to root by bypassing an AppArmor profile restriction. The AppArmor bypass involves copying bash to /var/tmp to escape the confined ash shell profile, then injecting commands into a world-writable SUID-called script.
Table of contents
1. Scanning & EnumerationWeb2. Exploitation3. Privilege EscalationGet Huzaifa Malik ’s stories in your inbox6 Impressions