> For the complete documentation index, see [llms.txt](https://manuelvazquez-contact.gitbook.io/oscp-prep/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://manuelvazquez-contact.gitbook.io/oscp-prep/hack-the-box/sunday/lessons-learned.md).

# Lessons Learned

Lessons Learned

* Finger is outdated and allows us to enumerate usernames without lockout mechanism.&#x20;
* Weak passwords can be cracked, users should have more secure passwords and the administrator should implement a passowrd policy
* SSH can be brute forced
* Don't let wget run as root and be careful on what you actually let users run as root.
* I also learned that slick wget \[server] -O \[place to write to] trick with wget. Can be useful down the road.&#x20;
* You can chain your privelege escalation. If a command can run as root, you can overwrite it with wget -O or read contents with wget -I&#x20;
