192.168.249.127
Find open ports
Port 8000
Landing page (admin account not set)
Admin account is not set
Set the admin account (bubbleman:bubbleman)
Credentials of bubbleman:bubbleman
Success
Edit the home page to inject a Lua reverse shell
Once logged in, reload the home page, then click the Edit page icon
Click “Expert” button
Select “Enable LSP” button
Generate a Lua reverse shell (Lua 1 didn’t work)
Inject the reverse shell
Click Save
Root
Catch a reverse shell as root
Catch it
Obtain local.txt and proof.txt