infraProhard
Основа (Foundation)
hackerlab
Task: Windows Server 2016 DC running BoidCMS on Apache/XAMPP with default admin credentials and CVE-2023-38836 file upload RCE. Solution: Used existing webshell to discover Firefox saved passwords for Administrator, then read split flag via PowerShell Invoke-Command with stolen credentials.
$ ls tags/ techniques/
phpfile_uploadwebshellboidcmscve_2023_38836active_directorywindows_server_2016powershellfirefox_decryptcredential_extractioninvoke_commandxampp
default_credentials_logincve_2023_38836_file_upload_rcefirefox_saved_password_extractionpowershell_remoting_with_stolen_credentialscredential_reuse_lateral_movement
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [infra][Pro]Пространство (Expanse)— hackerlab
- [infra][Pro]Революция (Revolution)— hackerlab
- [infra][Pro]Грань (Fringe/Edge)— hackerlab
- [infra][Pro]Потерянный (Lost)— hackerlab
- [infra][Pro]Бункер (Bunker)— hackerlab