13.Prtg-network-monitor
Introduction
1. Discovery and Enumeration
Nmap Scan
sudo nmap -sV -p- --open -T4 10.129.201.50EyeWitness Scan
cURL Version Check
curl -s http://10.129.201.50:8080/index.htm -A "Mozilla/5.0 (compatible; MSIE 7.01; Windows NT 5.0)" | grep version2. Exploiting CVE-2018-9276 (Authenticated Command Injection)
Login
Navigate to Notifications
Add a New Notification
Test Notification
3. Verification
Using CrackMapExec (SMB)
Alternative Verification Methods
4. Reverse Shell (Alternative Payload)
Start Netcat Listener
Key Points
Last updated