Use the credentials found in the web enumeration to log in via SSH or check the 9090 service. Flag 2: Frequently found in the user's home directory. 4. Privilege Escalation

Start your machine and identify its IP address. Use nmap to find open ports. nmap -sV

Run sudo -l to see what commands your user can run without a password.

Often located in a hidden directory found via enumeration (e.g., /passwords.html or /image.png containing text). 3. SSH Enumeration (Port 22/9090)

Download the rickandmortysbiggestfan.zip and extract the contents to your working directory.