Fireworks
TryHackMe KoTH Machine - Fireworks
Port Scan -
Found an id_rsa private ssh key via ftp
id_rsa private ssh key via ftpSearching for music gallery site exploit
music gallery site exploitExploiting SQLI on endpoint /classes/Master.php -
/classes/Master.php -got admin hash after dumping the db
LFI after admin dashboard access -
Initial Foothold on the box as david user using the id_rsa we found earlier -
david user using the id_rsa we found earlier -escape the fireshell -
fireshell -privesc to root -
Fireshell
Port 8080 - mblog
Default Admin Creds for mblog 3.5.0 -
mblog 3.5.0 -SSTI - CVE-2024-28713
CVE-2024-28713Mysql db root pass -
Xwiki on port 8080 -
port 8080 -Default admin creds -
XWiki RCE (CVE-2024-31982) - exploit
Thomas user from docker -
Fireshell 3 - escape less
lessMagento 2.4.6 - Bitnami on port 8080 -
port 8080 -JWT Cryptographic key /bitnami/magento/app/etc/env.php
/bitnami/magento/app/etc/env.phpXXE Magento -
Last updated