10 May 2021

Symfonos 5

Nmap scan for open ports + services

Webserver first

/home.php is redirected to /admin.php
response in burpsuite from home.php

A parameter (url) which can be used for local file inclusion (LFI).
Trying to read some local files, like /etc/passwd


This works, so trying for the admin.php file


Useful information for ldap

Credentials (base64 encoded)

If the binary is allowed to run as superuser by sudo, it does not drop the elevated privileges and may be used to access the file system, escalate or maintain privileged access (source = https://gtfobins.github.io/gtfobins/dpkg/)

Root acces. Final part.


