Offsec Proving Grounds Walkthrough – Twiggy

🚨Walkthrough of the machine called “Twiggy” in the OffSec Proving Grounds…don’t watch unless you want help getting through the machine.
I had some issues with figuring out how to take advantage of the exploit but eventually prevailed after some experimentation. We take advantage of a RCE in ZeroMQ ZMTP software and get creative by adding ourselves to the passwd file to gain root access.  ***SPOILERS*** I show you how to pwn the box, so if you don’t want help with it do not watch this video. Hope this helps someone and I hope you enjoy.🚨