Symfonos 4 || VulnHub Walkthough
Автор: Techno Science
Загружено: 2025-01-11
Просмотров: 341
Hello, everyone! Welcome back to our VulnHub Walkthrough series. In today’s video, we’ll continue exploring the exciting VulnHub collection with SymfonOS. Specifically, we’re diving into the 4th virtual machine in the series, SymfonOS 4. This intermediate, OSCP-like, real-world scenario machine is designed to emphasize the importance of understanding vulnerabilities, and how to exploit them effectively.
To Learn More: https://www.cybersecmastery.in/2024/1...
Contribute to growing: https://www.buymeacoffee.com/mrdev
=========================================
Time Stamp
=========================================
0:00 Introduction
0:41 Settings Up
2:29 Enumeration
2:30 Identify the IP address and Conduct Network Scan
4:40 Web Enumeration and Directory Busting
7:19 Bypass Authentication using SQL Injection and Enumerating the Dashboard
9:02 Examining the URL Structure for Systematic Confirmation of LFI Vulnerability
10:21 Brute forcing the LFI vulnerability file path
12:44 Exploitation
12:45 Testing for Log Poisoning in SSH Logs
13:07 Leveraging SSH Log Poisoning with PHP RCE Injection
15:55 Foothold
15:56 Establish a Reverse Shell
17:42 Investigate the Target Directory
19:18 Privilege Escalation
19:19 Enumerating System Information
20:42 Analyzing Privilege Escalation Potential via the DIP Group
21:41 Exploiting DIP Group via Tunneling
25:08 Investigating the Cookie for Potential Deserialization Exploits
25:36 Privilege Escalation via Deserialization of Serialized Session Cookies
27:41 Verify the Privilege and obtain the Flag
===============================================
Find me:
Instagram: / amit_aju_
Facebook page: / technoscinfo
Linkedin: / amit-kumar-giri-52796516b
Chat with Telegram:https://t.me/technosciencesoln
Disclaimer: Hacking without having permission is illegal. This channel is strictly educational for learning about cyber-security in the areas of ethical hacking and penetration testing so that we can protect ourselves against real hackers.
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: