xsspresso
xsspresso
Tags/ Apache

Apache

8 writeups tagged with Apache

MiscEasyLinux

VHL — Core

Legacy Ubuntu server with Apache 2.2 and Dovecot POP3. Enumerated mail service for credentials enabling SSH access to root.

#Apache#POP3#Dovecot
Feb 16, 2025Virtual Hacking Labs
WebEasyWindows

VHL — WinAS01

XAMPP 1.8.1 on Windows with Apache and SSL. Exploited outdated XAMPP configuration and weak credentials for web shell upload.

#XAMPP#Apache#Web Shell
Feb 13, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Trails

Hiking Trails web application on Ubuntu. Directory traversal and file inclusion vulnerabilities lead to credentials and shell.

#LFI#Directory Traversal#Apache
Feb 12, 2025Virtual Hacking Labs
WebEasyWindows

VHL — Anthony

Windows 7 SP1 with Apache and multiple services. Enumerated web application vulnerabilities and exploited weak credentials for admin access.

#Apache#Windows 7#Credential Enum
Feb 12, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Quick

Quick.CMS v6.7 with a known authenticated RCE vulnerability. Admin credentials discovered via enumeration for initial access.

#CMS#RCE#Quick.CMS
Feb 10, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Web01-Prd

Production web server with anonymous FTP access. Weak credentials and misconfigured permissions lead to full compromise.

#FTP#Anonymous Login#Misconfiguration
Feb 9, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Web01-Dev

Development web server with FTP credentials leaked via anonymous login. Credential reuse and web shell upload for root.

#FTP#Web Shell#File Upload
Feb 8, 2025Virtual Hacking Labs
WebEasyLinux

HTB — OpenAdmin

OpenNetAdmin 18.1.1 RCE via command injection in web console. Internal Apache vhost with SSH key in password-protected page for lateral movement.

#OpenNetAdmin#Command Injection#RCE
Jan 18, 2025HackTheBox