HTB Writeup – MonitorsThree
Posted on 2024-08-25
RCE for CACTI monitor system, Auth bypass for Duplicati backup solution.
RCE for CACTI monitor system, Auth bypass for Duplicati backup solution.
Skipper Proxy SSRF, Blazor traffic exploit, Privesc from process monitor
CVE-2023-41425 for WonderCMS RCE with malicious themes module.
Pluck CMS RCE, and fun Depix to reveal pixelized passwords.
Cloud hacking: MinIO, Vault, Symlink Race, Linux MOTD Hijack
USER Nmap does not give us much information but a domain: Then I went for subdomain enumeration to dig out more useful information using ffuf: We have 3 subdomain entries: The &