Muddy
Enumeration
80/tcp open http Apache httpd 2.4.38 ((Debian))
|_http-server-header: Apache/2.4.38 (Debian)
|_http-title: Did not follow redirect to http://muddy.ugc/
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
...
8888/tcp open http WSGIServer 0.1 (Python 2.7.16)
|_http-server-header: WSGIServer/0.1 Python/2.7.16
|_http-title: Ladon Service Catalog
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS$ gobuster dir -u http://muddy.ugc -w /usr/share/wordlists/dirb/big.txt
/webdav (Status: 401) [Size: 456] http://192.168.84.161:8888 -> Powered by Ladon for Python
$ searchsploit ladon
$ searchsploit -m xml/webapps/43113.txtMain name: muddy -> urn: checkout (soap11 description) -> Change related parts
Enumerated related parts with exploring the website.
/var/www/html/webdav/passwd.dav -> via Apache Configuration File
Initial Access
https://www.revshells.com/ - PHP cmd
PrivEsc
Writable cronjob path and using relative path.
https://www.revshells.com/ - nc mkfifo
Last updated