c_klvn
@k_l3vin
Offensive Security
ID: 2591023835
08-06-2014 03:02:03
3,3K Tweet
273 Followers
683 Following
Rooted Build Vulnlab on HackTheBox! Learned tons from enumerating & exploring Jenkins, Rsync, containers environments, and an interesting privilege escalation path. a solid box for practicing pivoting and cool attack chains labs.hackthebox.com/achievement/ma⦠#HackTheBox #htb #InfoSec
404 page to RCE. A report by spaceraccoon | Eugene Lim He chained two old CVEs to achieve RCE: - Found a 404 page mentioning an obscure CMS, discovered /josso/signin login - Triggered CVE-2007-0450 (directory traversal in mod_proxy) using a %5C../ to bypass the internal proxy - Reached
From Zero Creds to Enterprise Admin, by Ivan Spiridonov xbz0n.sh/blog/from-zeroā¦