zone-transfer

1 article
sort: new top best
clear filter
0 8/10
bug-bounty

A bug bounty hunter discovered unauthenticated Remote Code Execution via an HTTP PUT method on a staging web service running on a non-standard port, enabling file upload of a PHP web shell. The RCE was leveraged to gain a reverse shell, traverse the internal network using discovered zone transfer files, and achieve lateral movement to other systems using weak credentials embedded in system files.

nmap netcat ncat OPTIONS PUT phpinfo
blog.zsec.uk · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details