infraProhard

Основа (Foundation)

hackerlab

Task: Windows Server 2016 DC running BoidCMS on Apache/XAMPP with default admin credentials and CVE-2023-38836 file upload RCE. Solution: Used existing webshell to discover Firefox saved passwords for Administrator, then read split flag via PowerShell Invoke-Command with stolen credentials.

$ ls tags/ techniques/
default_credentials_logincve_2023_38836_file_upload_rcefirefox_saved_password_extractionpowershell_remoting_with_stolen_credentialscredential_reuse_lateral_movement

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups