8081
Last updated
Last updated
Searching for vulnerabilites we found: https://github.com/v1k1ngfr/exploits-rconfig/blob/master/rconfig_CVE-2020-10220.py
Modifying request to verify=False to prevent SSL errors.
We get an admin hash.
We can crack it.
Now we can use this exploit after modifying all request.get() by adding verify=False
Running linpeas:
using gtfobins: