Web Pentesting & Active Directory | SQLinjection,Python,cefdebug,BloodHound,PrivEsc

Опубликовано: 25 Апрель 2024
на канале: Osman Dağdelen
1,382
45

Multimaster is an insane difficulty Windows machine featuring a web application that is vulnerable to SQL Injection. This vulnerability is leveraged to obtain the foothold on the server. Examination the file system reveals that a vulnerable version of VS Code is installed, and VS Code processes and found to be running on the server. By exploiting debug functionality, a shell as the user `cyork` can be gained. A password is found in a DLL, which due to password reuse, results in a shell as `sbauer`. This user is found to have `GenericWrite` permissions on the user `jorden`. Abusing this privilege allows us to gain access to the server as this user. `jorden` is be member of `Server Operators` group, whose privileges we exploit to get a SYSTEM shell.


На этой странице сайта вы можете посмотреть видео онлайн Web Pentesting & Active Directory | SQLinjection,Python,cefdebug,BloodHound,PrivEsc длительностью часов минут секунд в хорошем качестве, которое загрузил пользователь Osman Dağdelen 25 Апрель 2024, поделитесь ссылкой с друзьями и знакомыми, на youtube это видео уже посмотрели 1,382 раз и оно понравилось 45 зрителям. Приятного просмотра!