Watch and track your favorite playlist.
Curated by: IppSec (543 videos)
00:00 - Introduction 00:50 - Start of nmap 02:00 - Website is opensource, taking a look at the source code 04:15 - The website uses js2py and the version running is vulnerable to CVE-2024-28397, which is a sandbox escape 08:00 - Shell returned on the website, dumping the SQLite database to get Marco's password 10:00 - Marco can run npbackup-cli via sudo, looking into it briefly 12:15 - Backing up and restoring the root directory