π’Armageddon
Recon & Enum
port scan
PORT STATE SERVICE
22/tcp open ssh
80/tcp open httpdirectory scan
/.html (Status: 403) [Size: 207]
/index.php (Status: 200) [Size: 7440]
/misc (Status: 301) [Size: 233] [--> http://10.10.10.233/misc/]
/themes (Status: 301) [Size: 235] [--> http://10.10.10.233/themes/]
/modules (Status: 301) [Size: 236] [--> http://10.10.10.233/modules/]
/scripts (Status: 301) [Size: 236] [--> http://10.10.10.233/scripts/]
/sites (Status: 301) [Size: 234] [--> http://10.10.10.233/sites/]
/includes (Status: 301) [Size: 237] [--> http://10.10.10.233/includes/]
/install.php (Status: 200) [Size: 3172]
/profiles (Status: 301) [Size: 237] [--> http://10.10.10.233/profiles/]
/update.php (Status: 403) [Size: 4057]
/README.txt (Status: 200) [Size: 5382]
/robots.txt (Status: 200) [Size: 2189]
/cron.php (Status: 403) [Size: 7388]
/INSTALL.txt (Status: 200) [Size: 17995]
/LICENSE.txt (Status: 200) [Size: 18092]
/CHANGELOG.txt (Status: 200) [Size: 111613]
/xmlrpc.php (Status: 200) [Size: 42]
/COPYRIGHT.txt (Status: 200) [Size: 1481]
/.html (Status: 403) [Size: 207]
/UPGRADE.txt (Status: 200) [Size: 10123]
/authorize.php (Status: 403) [Size: 2824]website

http://10.10.10.233/CHANELOG.TXT
shell as apache
searchsploit
CVE 2018 - 7600
privesc apache => brucetherealadmin
privesc brucetherealadmin => root
sudo -l
creating malicious package
Last updated
