Pentesting Lab Exercises Series - Vulnhub
Virtual Machine Name: Napping: 1.0.1
Link: https://www.vulnhub.com/entry/napping...
Tips:
1. Tabnabbing attack
Tabnabbing is a type of phishing attack that targets the inactive tabs in your browser. While you're focused on your current tab, the link to the previous one can be hijacked, and you'll be redirected from the intended site to a malicious one resembling the real thing.
2. Take advantage of vim to elevate privilege:
https://gtfobins.github.io/gtfobins/v...