Exfiltrated
Last updated
Last updated
Found a webpage run on subrion cms Found robots.txt
Found login page with version disclosure:
Trying admin : admin
: We are logged in.
Now trying a file upload vulnerability https://www.exploit-db.com/exploits/49876:
Now transfering shell.sh:
and executing it:
We get a full a TTY:
Found some potential credentials: Found some info:
Running linpeas found cronjob: Now checking exiftool version: https://github.com/OneSecCyber/JPEG_RCE/tree/main ExifTool 7.44 to 12.23 are vulnerable.
Our exiftool version is vulnerable to this exploit. Using the exiftool exploit Transfer the required files:
create a malicious image:
in /var/www/html/subrion/uploads
Just because a script runs in cron and uses a specific binary it might not be tricking the script and might be about the version too