Grafana RCE CVE-2024-9264 Cronjob PrivEsc to Root | Planning HTB
Автор: CTF Security
Загружено: 2025-09-13
Просмотров: 128
In this video, I walk through a full HackTheBox machine from initial reconnaissance to root.
Planning is an easy difficulty Linux machine that features web enumeration, subdomain fuzzing, and exploitation of a vulnerable `Grafana` instance to [CVE-2024-9264](https://nvd.nist.gov/vuln/detail/CVE-.... After gaining initial access to a Docker container, an exposed password enables lateral movement to the host system due to password reuse. Finally, a custom cron management application with `root` privileges can be leveraged to achieve full system compromise.
00:00 Introduction
01:53 Scanning
04:18 Subdomain Enumeration
06:21 Investigating Grafana
08:06 Grafana RCE Exploit
12:50 Container Breakout
14:01 Initial Access (Enzo account)
18:07 SSH Local Port Forwarding
24:21 Privilege Escalation via Cronjob (root account)
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: