3000
Last updated
Last updated
We have grafana 8.3.0 vulnerable to LFI
Now we have grafana.db
Now trying ssh:
Checking data_source table: We have a hashed credential
Using this exploit We can decrypt it:
Now checking groups we belong to: We can get access to root files:
Now we can access root through ssh: