Web Pentesting & Active Directory | SQLinjection,Python,cefdebug,BloodHound,PrivEsc

Published: 25 April 2024
on channel: Osman Dağdelen
1,382
45

Multimaster is an insane difficulty Windows machine featuring a web application that is vulnerable to SQL Injection. This vulnerability is leveraged to obtain the foothold on the server. Examination the file system reveals that a vulnerable version of VS Code is installed, and VS Code processes and found to be running on the server. By exploiting debug functionality, a shell as the user `cyork` can be gained. A password is found in a DLL, which due to password reuse, results in a shell as `sbauer`. This user is found to have `GenericWrite` permissions on the user `jorden`. Abusing this privilege allows us to gain access to the server as this user. `jorden` is be member of `Server Operators` group, whose privileges we exploit to get a SYSTEM shell.


On this page of the site you can watch the video online Web Pentesting & Active Directory | SQLinjection,Python,cefdebug,BloodHound,PrivEsc with a duration of hours minute second in good quality, which was uploaded by the user Osman Dağdelen 25 April 2024, share the link with friends and acquaintances, this video has already been watched 1,382 times on youtube and it was liked by 45 viewers. Enjoy your viewing!