MAQUINA MYBB (Virtual Host - MYBB 1.8.35 RCE CVE-2023-41362 - PrivEsc Sudo rb)
Reconocimiento y Enumeración
```BASH
nmap -p- --open --min-rate 2000 -n -Pn -sSCV 172.17.0.2 -oN fullscan.txt
Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-22 20:40 -03
Nmap scan report for 172.17.0.2
Host is up (0.0000050s latency).
Not shown: 65534 closed tcp ports (reset)
PORT STATE SERVICE VERSION
80/tcp open http Apache httpd 2.4.58 ((Ubuntu))
|_http-title: MyBB
|_http-server-header: Apache/2.4.58 (Ubuntu)
MAC Address: 02:42:AC:11:00:02 (Unknown)```BASH
nmap -p80 --script=http-enum.nse 172.17.0.2 -oN directory.txt
Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-22 20:40 -03
Nmap scan report for 172.17.0.2
Host is up (0.000061s latency).
PORT STATE SERVICE
80/tcp open http
| http-enum:
| /css/: Potentially interesting directory w/ listing on 'apache/2.4.58 (ubuntu)'
| /images/: Potentially interesting directory w/ listing on 'apache/2.4.58 (ubuntu)'
|_ /js/: Potentially interesting directory w/ listing on 'apache/2.4.58 (ubuntu)'
MAC Address: 02:42:AC:11:00:02 (Unknown)


Explotación




Post Explotación (mov lateral y escalado de priv)


Last updated