Muddy
Enumeration
80/tcp open http Apache httpd 2.4.38 ((Debian))
|_http-server-header: Apache/2.4.38 (Debian)
|_http-title: Did not follow redirect to http://muddy.ugc/
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
...
8888/tcp open http WSGIServer 0.1 (Python 2.7.16)
|_http-server-header: WSGIServer/0.1 Python/2.7.16
|_http-title: Ladon Service Catalog
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS$ gobuster dir -u http://muddy.ugc -w /usr/share/wordlists/dirb/big.txt
/webdav (Status: 401) [Size: 456] http://192.168.84.161:8888 -> Powered by Ladon for Python
$ searchsploit ladon
$ searchsploit -m xml/webapps/43113.txtInitial Access
PrivEsc
Last updated