Bamboo
Last updated
Last updated
Post 22 Port 3189 -- Squid
Using proxychains to add the squid proxy: Then using squidscan to check open ports:
We found 5 ports. Using proxychains to do nmap scan:
Now adding proxy in burpsuite:
Now we found a papercut exploit on github: https://github.com/horizon3ai/CVE-2023-27350/tree/main
Using this:
On port 9191:
Using linpeas there are writable e Now using authentication bypass: https://www.exploit-db.com/exploits/51391
Now in enable printing:
When clicking refresh servers In pspy64 we can see server-command get executed.
So editing it to get a reverse shell.