HackTheBox - Greenhorn

00:00 - Introduction
02:14 - Discovering Pluck CMS, getting the version then looking for exploits
05:44 - Finding Pluck's password in Gitea (iloveyou1)
08:33 - Logging into pluck and uploading a php shell as a module
13:00 - Shell returned on the box
15:00 - Trying iloveyou1 as the password for junior and discovering a PDF
16:30 - Talking about why pixelation is a bad way to censor/redact things and finding Depix on GitHub
20:30 - Running Depix
25:20 - Trying the password as the root and getting in

Support the originator by clicking the read the rest link below.