Boardlight #
User #
FFuF was doing this
so i added -c -fs 15949
ffuf -u http://board.htb -H "Host:FUZZ.board.htb" -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -c -fs 15949
found a poc for authenticated rev shell so had to get in
Googled default creds which were admin/admin and it worked
made a test page with a rev and ran it
got foothold now onto priv esc
db name = dolibarr db username = dolibarrowner db password = serverfun2$2023!!
larissa password = serverfun2$2023!!
Root #
And thats Pwnd.
Thanks for reading