Devvortex

Recon

nmap_scan.log

HTTP (80)

Seems to be a placeholder website.

Writeup.png

Enumerate subdomains:

Same vibes

Writeup-1.png

Seemed like Wordpress, but I guess not.

Writeup-2.png

Joomla

Googling The requested page can't be found.arrow-up-right led to discovery of Joomla.

It can be enumerated with joomscanarrow-up-right tool.

CVE-2023-23752

Joomla! CVE-2023-23752 to Code Executionarrow-up-right

Creds: lewis:P4ntherg0t1n5r3c0n##

RCE

System > Side Templates > Cassiopeia > Edit error.php (I used p0wny webshell)

To get webshell: http://dev.devvortex.htb/templates/cassiopeia/cassiopeia/error.phparrow-up-right

Writeup-3.png

Database Enumration

Enumerate database:

Crack the password for logan

SSH

logan is a valid user on the box

Creds: logan:tequieromucho

User.txt

Privilege Escalation

CVE-2023-1326-PoCarrow-up-right

Note: The dots kept printing, but if you just enter !/bin/bash the shell will spawn.

Last updated