0:00 Start
0:26 Initial scans
1:59 Webserver enumeration
3:35 PHP Info Output
6:15 PHP Backdoor Module
12:49 Initial Access
17:25 Privilege Escalation - Sudo Service
19:20 Privilege Escalation - Sudo Joe
20:41 We are root
21:06 Wrap-up
You can download the challenge VM from the following link:
https://vulnyx.com/#infected
Download the file, then unzip the file and deploy the VM using VirtualBox or VMware. You will also need to have an "attacker" VM with security tools installed on it, e.g., Kali Linux, deployed to the same VM network.
The following links are related to topics covered in this challenge:
PHP Info Official Documentation:
https://www.php.net/manual/en/functio...
Github Repository For PHP Backdoor Module:
https://github.com/WangYihang/Apache-...
GTFObins Entry For Service Command:
https://gtfobins.github.io/gtfobins/s...
GTFObins Entry For Joe Command:
https://gtfobins.github.io/gtfobins/j...
Join this channel to get access to perks:
/ @theshyhat
Donations:
https://streamlabs.com/theshyhat/tip
Donations are always appreciated, but never required! All donations will go towards developing new HackerFrogs courses and cybersecurity video content!
HackerFrogs Links:
Twitch:
/ theshyhat
Kick:
https://kick.com/theshyhat
Reddit:
/ hackerfrogs
Watch video VulNyx: Infected - PHP Module Backdoors - Sudo Service and Joe online without registration, duration hours minute second in high quality. This video was added by user theshyhat 08 March 2025, don't forget to share it with your friends and acquaintances, it has been viewed on our site 30 once and liked it 3 people.