All playbooks

Playbook · intermediate · half day

Web foothold → host privesc (lab)

Full narrative on an authorized lab box: map web app, gain RCE/file foothold, escalate on Linux, document each stage with fixes.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Scenario

A vulnerable lab web app (Juice Shop advanced chain, DVWA, Metasploitable service, or similar) is in your host-only network. You will treat it like a mini engagement: recon, exploit, privesc, report — no flags-only mindset.

Goals

Map the app and pick a realistic entry

Obtain a shell or code execution in lab

Escalate to root/admin with a reasoned path

Produce multi-finding notes with remediations

Requirements

Isolated lab (Lab Zero)

Target VM/container authorized for exploit

Note template ready

Safety

Never run this playbook against production without a contract

Snapshot before exploitation

Prefer understanding over copy-paste Metasploit auto-magic

Steps

Step 1

Scoping and mapping

Intent: Start like a professional, not a payload sprayer.

Actions

  • Confirm host-only IP and isolation
  • Staged nmap; identify web port(s)
  • Proxy browse; build role/function notes
Expected: Site map + 3 hypotheses ordered by impact.
Step 2

Initial access

Intent: Convert a vuln class into execution or sensitive access.

Actions

  • Test high-value sinks (upload, command, SQLi, SSTI, file include) as applicable
  • Use sqlmap/manual techniques only when hypothesis is solid
  • Catch shell with care; record exact vector
Expected: Shell or equivalent access with reproducible steps.

Pitfalls

  • Destroying the app so privesc cannot be practiced
  • Skipping evidence capture
Step 3

Linux privilege escalation

Intent: Move from www-data/user to root with methodology.

Actions

  • Run identity + sudo -l + SUID checks
  • linpeas/pspy; validate findings manually
  • Exploit one path; snapshot proof (id)
Expected: Root proof + written path explanation.
Step 4

Report package

Intent: Ship client-quality narrative.

Actions

  • Split into findings: web entry, weak perms, privesc root cause
  • Each with impact, repro, fix
  • Add attacker path diagram in text form
Expected: 2–4 findings + executive path paragraph.

Remediation outcomes

Patch/remove vulnerable endpoint; parameterized queries; safe uploads

Least privilege for app user; no secrets in webroot

Fix sudo/SUID/cron root causes; patch kernel if relevant

Add detection notes (web logs + auth logs)