Apache
HackTheBox – Undetected

HackTheBox – Undetected
#HackTheBox #Undetected
“IppSec”
00:00 – Intro
00:54 – Start of nmap
02:00 – Taking a look at the website
10:00 – Running gobuster against store.djewelry.htb and discovering a vendor directory that has phpunit
11:45- Exploiting phpunit to get a shell on the box
15:15 – Shell recieved on the box as www-data
17:20 – Looking for…
source