Feedback
Last updated
Last updated
On port 8080: Now using gobuster we discover /feedback
This is vulnerable to [[Hacking/Web App Attacks/Log4Shell|Log4Shell]] (I didn't know this) Using this shell
And sending the payload in burp suite with url encoding. We get a shell
Now enumerating the box to find password: There is a file called tomcat-users.xml
in /opt/tomcat/conf
Now we get the root password and root shell: