October 8, 2026
HTB โ Bank
LinPEAS
By CYBER_delta
2 min read
The Bank machine teaches a complete web-to-root attack path:
-
DNS enumeration โ discover
bank.htband perform DNS zone transfer (AXFR). -
Web enumeration โ use Gobuster/FFUF/Dirsearch to find virtual hosts and hidden directories.
-
Authentication bypass โ exploit EAR (Execution After Redirect) to access functionality without valid credentials.
-
Web exploitation โ identify PHP execution/configuration weaknesses and obtain initial access.
-
Reverse shell โ get a shell as
www-dataand upgrade it to a PTY. -
Linux enumeration โ inspect users, permissions, SUID binaries, and use LinPEAS.
-
Privilege escalation โ identify the unusual SUID binary and use it to reach root.
i guss THE bank.htb then seen somthing new popup on my browser
i don't type /login.php automatic pop_up
when i totally stuck what i do and don't find any other step then find somthing new
gobuster dir -u http://bank.htb -w /usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-medium.txt
Let's check the /balance-transfer
We have big data let's check size. then click randamly I found these credentials.
5&6.
We can upload a file let's check if we can upload a PHP file to take a reverse shell. then see opps
inspect anf find htb
UsEr FlAg:
RooT FLaG: