We enumerate valid usernames via the legacy Finger protocol, obtain initial access through weak SSH credentials, harvest password hashes from an exposed shadow backup to crack credentials for lateral movement, and escalate privileges to root by abusing sudo permissions on wget via askpass execution.