Playbook · intermediate · half day
Web foothold → host privesc (lab)
Full narrative on an authorized lab box: map web app, gain RCE/file foothold, escalate on Linux, document each stage with fixes.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Scenario
A vulnerable lab web app (Juice Shop advanced chain, DVWA, Metasploitable service, or similar) is in your host-only network. You will treat it like a mini engagement: recon, exploit, privesc, report — no flags-only mindset.
Goals
Map the app and pick a realistic entry
Obtain a shell or code execution in lab
Escalate to root/admin with a reasoned path
Produce multi-finding notes with remediations
Requirements
Isolated lab (Lab Zero)
Target VM/container authorized for exploit
Note template ready
Safety
Never run this playbook against production without a contract
Snapshot before exploitation
Prefer understanding over copy-paste Metasploit auto-magic
Steps
Scoping and mapping
Intent: Start like a professional, not a payload sprayer.
Actions
- Confirm host-only IP and isolation
- Staged nmap; identify web port(s)
- Proxy browse; build role/function notes
Initial access
Intent: Convert a vuln class into execution or sensitive access.
Actions
- Test high-value sinks (upload, command, SQLi, SSTI, file include) as applicable
- Use sqlmap/manual techniques only when hypothesis is solid
- Catch shell with care; record exact vector
Pitfalls
- Destroying the app so privesc cannot be practiced
- Skipping evidence capture
Linux privilege escalation
Intent: Move from www-data/user to root with methodology.
Actions
- Run identity + sudo -l + SUID checks
- linpeas/pspy; validate findings manually
- Exploit one path; snapshot proof (id)
Report package
Intent: Ship client-quality narrative.
Actions
- Split into findings: web entry, weak perms, privesc root cause
- Each with impact, repro, fix
- Add attacker path diagram in text form
Remediation outcomes
Patch/remove vulnerable endpoint; parameterized queries; safe uploads
Least privilege for app user; no secrets in webroot
Fix sudo/SUID/cron root causes; patch kernel if relevant
Add detection notes (web logs + auth logs)