HTB Writeup – MonitorsThree
Posted on 2024-08-25
RCE for CACTI monitor system, Auth bypass for Duplicati backup solution.
RCE for CACTI monitor system, Auth bypass for Duplicati backup solution.
Skipper Proxy SSRF, Blazor traffic exploit, Privesc from process monitor
CVE-2023-41425 for WonderCMS RCE with malicious themes module.
CVE-2024-32002 for Git RCE, CVE-2024-20656 for Visual Studio PE
Pluck CMS RCE, and fun Depix to reveal pixelized passwords.
USER Nmap does not give us much information but a domain: Then I went for sub