OffSec Live | Wheels
Вставка
- Опубліковано 20 січ 2025
- Welcome to our OffSec Live session on Wheels, a PG Practice machine: portal.offsec.....
Join OffSec Live on Fridays: / offsecofficial .
We do demonstrations and walkthroughs of course topics and Proving Grounds machines. Additionally, sessions offer career guidance, including how to build a resume, how to break into #cybersecurity, and interview tips.
In this tutorial, we showcased vulnerabilities like XML injection and privilege escalation to achieve root access. We walked you through:
🟪 System Access: Registering and logging into an employee portal using domain-specific credentials.
🟪 Debugging & Queries: Troubleshooting XML errors, exploring XPath commands, and refining input payloads.
🟪 Data Retrieval: Accessing sensitive employee data and uncovering potential passwords.
🟪 Privilege Escalation: Enumerating the system, identifying vulnerabilities, and navigating limitations for root access.
🟪 Final Exploit: Exploiting password hashes to gain root privileges and manipulate files using custom binaries.