xsspresso
xsspresso
Tags/ CHM

CHM

1 writeup tagged with CHM

WebMediumWindows

HTB — Sniper

PHP RFI via language parameter loads SMB share for RCE. Lateral movement via credential in web config. CHM file drops reverse shell as Administrator.

#RFI#SMB#CHM
Nov 21, 2024HackTheBox