> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-silver-platter.md).

# THM - Silver Platter

```bash
PORT     STATE SERVICE    VERSION
22/tcp   open  ssh        OpenSSH 8.9p1 Ubuntu 3ubuntu0.4 (Ubuntu Linux; protocol 2.0)
80/tcp   open  http       nginx 1.18.0 (Ubuntu)
| http-methods: 
|_  Supported Methods: GET HEAD
|_http-server-header: nginx/1.18.0 (Ubuntu)
|_http-title: Hack Smarter Security
8080/tcp open  http-proxy
| fingerprint-strings: 
|   FourOhFourRequest, GetRequest, HTTPOptions: 
|     HTTP/1.1 404 Not Found
|     Connection: close
|     Content-Length: 74
|     Content-Type: text/html
|     Date: Thu, 05 Feb 2026 04:47:49 GMT
|     <html><head><title>Error</title></head><body>404 - Not Found</body></html>
|   GenericLines, Help, Kerberos, LDAPSearchReq, LPDString, RTSPRequest, SMBProgNeg, SSLSessionReq, Socks5, TLSSessionReq, TerminalServerCookie: 
|     HTTP/1.1 400 Bad Request
|     Content-Length: 0
|_    Connection: close
|_http-title: Error

```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5xs0bKPJApzYilBbbfbf%2Fimage.png?alt=media&amp;token=3fcb7813-18a0-46c7-a8c3-2ad81be2ce7e" alt=""><figcaption></figcaption></figure>

Username: scr1ptkiddy

Also mention of SilverPeas. A quick google search told **Silverpeas** is a platform that helps you to share and exchange information, communicate, and collaborate within your teams.

A quick google search gave that silver peas is exploitable to authentication bypass at the below repo

{% embed url="<https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2d>" %}

### SilverPeas Authentication Bypass

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDekA7BmsjJbXHSZABL0T%2Fimage.png?alt=media&amp;token=9a2a497d-e906-4116-88a4-cd634022294d" alt=""><figcaption></figcaption></figure>

checking if we get access by removing the password field.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvO4MLtM89pGyNLMb2kBs%2Fimage.png?alt=media&amp;token=83c0cc38-1fe8-4d70-9e8e-c26009b48193" alt=""><figcaption></figcaption></figure>

editing the password field gave access to the silver peas.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FA8vDDvsICjgylK8jtsMy%2Fimage.png?alt=media&amp;token=d5662a47-5f0e-49f4-8348-95bf4a49abfe" alt=""><figcaption></figcaption></figure>

There is a notification for scriptkiddy to read lets check it

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoDjixHx4vbub3Vyh8frN%2Fimage.png?alt=media&amp;token=2738c334-e9b7-44c4-ab5f-a4eae77af259" alt=""><figcaption></figcaption></figure>

in the url fied id parameter calls 1 which can be a potential check for IDOR.

### IDOR

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FytZmNksJna4AErJxNmNo%2Fimage.png?alt=media&amp;token=286c7eab-9758-4614-b681-30aaefadec1b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FszWv40GMyLSscHbsJJ3j%2Fimage.png?alt=media&amp;token=5889a514-d4b6-4ff3-8183-29d1f6b4e62a" alt=""><figcaption></figcaption></figure>

Got an SSH Password for tim

## Shell as Tim

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlU2a6QohSUEHVwZanba2%2Fimage.png?alt=media&amp;token=66450d93-224b-45b3-af8f-c400dcaecf02" alt=""><figcaption></figcaption></figure>

```bash
tim@ip-10-81-133-221:~$ whoami
tim
tim@ip-10-81-133-221:~$ ls
user.txt
tim@ip-10-81-133-221:~$ cat user.txt
THM{c4ca4238a0b923820dcc509a6f75849b}
tim@ip-10-81-133-221:~$ 
```

```bash
tim@ip-10-81-133-221:~$ id
uid=1001(tim) gid=1001(tim) groups=1001(tim),4(adm)
tim@ip-10-81-133-221:~$ 

```

tim is part of adm group which means we can read all logs.

Exploiting ADM Group

found pasword for tyler in the auth.log

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtOPWxvw2SfzBwYDSX1KX%2Fimage.png?alt=media&amp;token=5c85f0a5-5a93-4ef9-979c-14af1596127c" alt=""><figcaption></figcaption></figure>

## Shell as Tyler

```bash
tim@ip-10-81-133-221:~$ su tyler
Password: 
tyler@ip-10-81-133-221:/home/tim$ 
```

```bash
tyler@ip-10-81-133-221:/$ id
uid=1000(tyler) gid=1000(tyler) groups=1000(tyler),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),110(lxd)
```

Tyler is part of sudo group

```bash
tyler@ip-10-81-133-221:/$ sudo -l
Matching Defaults entries for tyler on ip-10-81-133-221:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User tyler may run the following commands on ip-10-81-133-221:
    (ALL : ALL) ALL

```

which means i can get to root without password

## Shell as Root

```bash
tyler@ip-10-81-133-221:~$ sudo su
root@ip-10-81-133-221:/home/tyler# 
```

```bash
root@ip-10-81-133-221:/# cd root
root@ip-10-81-133-221:~# ls
root.txt  snap  start_docker_containers.sh
root@ip-10-81-133-221:~# cat root.txt
THM{098f6bcd4621d373cade4e832627b4f6}
root@ip-10-81-133-221:~# 
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-silver-platter.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
