> For the complete documentation index, see [llms.txt](https://pnpt.adot8.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pnpt.adot8.com/external-pentest-playbook/wreath-try-hack-me/pivoting/10.200.101.100/exploit.md).

# Exploit

<figure><img src="/files/NmLCoRXgFsPdsUGz9ipv" alt=""><figcaption></figcaption></figure>

Use previously discovered credentials

<figure><img src="/files/tAK1qcaAO4n6mC4YRNxb" alt=""><figcaption></figcaption></figure>

Add PHP shell code to image

<figure><img src="/files/RW8M1YkMtQGOPMv0Hbmz" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/TRI2IowesXvE2GwWgbRP" alt=""><figcaption><p>SHELL CODE IS POSSIBLE</p></figcaption></figure>

## Obfuscation

{% embed url="<https://www.gaijin.at/en/tools/php-obfuscator#result>" %}

Obfuscate php code and upload payload

<figure><img src="/files/43Mf6k4uPp7fMojBg6dD" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/orYVdeyfLuVKyL6uFl02" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/P2PgarumTey4NlTAa6qz" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/k3l0OwICpEwlaOKSpWg9" alt=""><figcaption></figcaption></figure>
