#
File Upload
2 posts
Enigma — NFS credential leak, OpenSTAManager RCE, and OliveTin command injection to root
Unauthenticated NFS share leaks employee credentials → webmail credential reuse → OpenSTAManager RCE via unrestricted file upload → bcrypt hash cracking → OliveTin argument injection as root → SUID bash.
Media — NTLM Hash Capture via Malicious ASX File and SeTcbPrivilege Escalation
A malicious Windows Media Player playlist triggers an outbound SMB connection, leaking an NTLMv2 hash. Once inside, a Windows Junction Point attack redirects file uploads to the web root, delivering a PHP webshell that runs as LOCAL SERVICE with SeTcbPrivilege — enough to become Administrator.