Skip to content

2022

PG - Exfiltrated Walkthrough

exfiltrated-info

TL ; DR

  • Use Nmap to get the list of services running on the target.
  • On web app use default credentials to login.
  • Exploit CMS which is vulnerable to authenticated RCE.
  • Exploit Cronjob to escalate privilege to root.