Web Pentesting & Active Directory | SQLinjection,Python,cefdebug,BloodHound,PrivEsc

Publicado em: 25 Abril 2024
no canal de: Osman Dağdelen
1,382
45

Multimaster is an insane difficulty Windows machine featuring a web application that is vulnerable to SQL Injection. This vulnerability is leveraged to obtain the foothold on the server. Examination the file system reveals that a vulnerable version of VS Code is installed, and VS Code processes and found to be running on the server. By exploiting debug functionality, a shell as the user `cyork` can be gained. A password is found in a DLL, which due to password reuse, results in a shell as `sbauer`. This user is found to have `GenericWrite` permissions on the user `jorden`. Abusing this privilege allows us to gain access to the server as this user. `jorden` is be member of `Server Operators` group, whose privileges we exploit to get a SYSTEM shell.


Nesta página do site você pode assistir ao vídeo on-line Web Pentesting & Active Directory | SQLinjection,Python,cefdebug,BloodHound,PrivEsc duração hora minuto segundo em boa qualidade , que foi baixado pelo usuário Osman Dağdelen 25 Abril 2024, compartilhe o link com seus amigos e conhecidos, no youtube este vídeo já foi visto 1,382 vezes e gostou 45 espectadores. Boa visualização!