xsspresso
xsspresso
Tags/ RFI

RFI

2 writeups tagged with RFI

WebMediumWindows

HTB — Sniper

PHP RFI via language parameter loads SMB share for RCE. Lateral movement via credential in web config. CHM file drops reverse shell as Administrator.

#RFI#SMB#CHM
Nov 21, 2024HackTheBox
WebMediumLinux

HTB — Tartarsauce

Gwolle Guestbook WordPress RFI via robots.txt discovery. Lateral move through sudo tar with --checkpoint shell execution.

#WordPress#RFI#Sudo
Apr 13, 2022HackTheBox