#
Credential-Reuse
2 posts
Enigma — NFS credential leak, OpenSTAManager RCE, and OliveTin command injection to root
Unauthenticated NFS share leaks employee credentials → webmail credential reuse → OpenSTAManager RCE via unrestricted file upload → bcrypt hash cracking → OliveTin argument injection as root → SUID bash.
Postman — Unauthenticated Redis to Webmin RCE
An unauthenticated Redis instance allows SSH key injection for initial access. A backup encrypted private key cracks to reveal credentials for user Matt, then Webmin 1.910 RCE (CVE-2019-12840) delivers a root shell.