Exfiltrated
Last updated
Was this helpful?
Last updated
Was this helpful?
Nmap scan
Had to add 192.168.116.163 exfitrated.offsec to /etc/hosts
Dirbuster scan
Robots.txt
Found at /panel/
Admin:Admin allows me to log in here.
Found this CMS has known exploits.
Getting a normal shell.
Stabilized shell.
Dropped and ran Linpeas on machine. Found interesting cron job.
After about an hour I had to get a hint here. I could not figure out how to get the exif data into a jpg.
Re-uploaded through admin panel.
And a minute later when the cron job ran.
Was able to add reverse shell to the jpg file.