FIRED! Offsec: Proving Grounds Practice
FIRED! Offsec: Proving Grounds Practice
HTB Academy Referal: https://referral.hackthebox.com/mz8ED35
TJ Nulls OSCP Prep List
https://docs.google.com/spreadsheets/...
============
My Certifications:
Practical Network Penetration Tester (PNPT) : TCM Security - https://certifications.tcm-sec.com/pnpt/
Practical Junior Penetration Tester (PJPT): TCM Security - https://certifications.tcm-sec.com/pjpt/
Practical Junior Web Tester (PJWT): TCM Security - https://certifications.tcm-sec.com/pjwt/
Certified Ethical Hacker (CEH): EC-Council
--------------------
Socials:
Tryhackme: https://tryhackme.com/p/NoxLumens
Hackthebox: https://app.hackthebox.com/profile/17...
Twitch: / noxlumens
0:00 MUTED!!!!
1:49 UNMUTED - Nmap scan
2:24 TTL OS Discovery
3:40 nmap -sC -sV -vv -p 22,9090,9091 address -oN nmap.md
6:54 Versions
7:35 OpenFire!
8:30 OpenFire Default Creds
10:20 OpenFire exploit search
10:48 CVE-2023-32315
13:36 Run the Exploit
20:07 Code Review CVE-2023-32315
20:45 Finally Logged in!
24:49 Vulnerable Plugin Enumeration
26:15 Java Reverse Shell? Im Reaching
26:56 msfvenom jsp payload Hacktricks
28:20 Installing Metasploit Framework for msfvenom
29:55 Trying to upload reverse.jsp to plugins
30:33 Installing rlwrap | rlwrap nc -nlvp 9001
31:40 Try everything | ssh'ing
32:30 Openfire application setting enumeration
33:50 Incognito Login
35:20 Openfire Search Exploit Enumeration
36:21 OPENFIRE SERVER TAB FINALLY!!
37:53 OpenFire PassBack Attack!
39:20 ROOTED!