Franco T.’s Post

View profile for Franco T., graphic

Especialista en Ciberseguridad @ UBA Psicologia

🎈 The web server on the default port 80 hosts a demo virtual host, accessible with guest credentials. While reviewing the links, I discover a MinIO Metrics section that is visible due to a Line Feed (LF) injection vulnerability. This allows me to analyze the logs, leading to the discovery of a new virtual host. This new virtual host uses the MinIO platform and reveals the service version, which is vulnerable to CVE-2023-28432. This is an information disclosure vulnerability that exposes the root user's credentials of the platform. After a thorough analysis, I determine that a specific version of a bucket leaks critical information related to an identity-based secrets and encryption management system. Finally, privilege escalation is achieved by leveraging a program that can be executed with elevated privileges by a user.

Owned Skyfall from Hack The Box!

Owned Skyfall from Hack The Box!

hackthebox.com

Reju Kole

Top 1% at TryHackMe Global • HTB | Elite Hacker • eJPTv2 • ICCA • CompTIA PenTest+ • CompTIA Security+ (SYO-601) • CompTIA CASP+ (CAS-004) • CompTIA Project+ (PKO-004) • Apache Spark (CVE-2022-33891)

3mo

Great man

To view or add a comment, sign in

Explore topics