xsspresso
xsspresso
Tags/ Default Creds

Default Creds

5 writeups tagged with Default Creds

MiscMediumLinux

VHL — FW01

IPFire firewall appliance with DNSmasq on port 53. Default/weak credentials on the admin panel lead to command execution.

#IPFire#Firewall#DNSmasq
Feb 16, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Mon02

Centreon IT monitoring platform on Red Hat. Default credentials lead to authenticated RCE via malicious poller command injection.

#Centreon#Default Creds#Command Injection
Feb 16, 2025Virtual Hacking Labs
MiscEasyWindows

VHL — Steven

Wing FTP Server on Windows. Default admin credentials allow access to the web admin panel, leading to command execution via scheduled tasks.

#Wing FTP#Default Creds#FTP
Feb 10, 2025Virtual Hacking Labs
MiscEasyLinux

HTB — UnderPass

daloRADIUS web interface default credentials expose user hashes. Cracked MD5 hash for SSH. Mosh binary sudo privesc for root shell.

#daloRADIUS#Default Creds#MD5
Jan 8, 2025HackTheBox
MiscEasyLinux

HTB — Keeper

Request Tracker default credentials expose SSH public key in ticket. KeePass 2.x CVE-2023-32784 memory dump extracts master password for root SSH key.

#KeePass#CVE-2023-32784#Memory Dump
Nov 25, 2024HackTheBox