Enumeration

Enumerate the ports

  • rustscan -a $ip

Pasted image 20240609145513

Local.txt

Find login credentials for the Gogs service

Note the POST data used when creating an account:

authenticity_token=pR8JHMdHN-duxwY2UT7Kd5JPwOz61k5fcjR79C-tPYT87LDqLvI3VgylAkUhINhKxz9W9nZYUMhAcBXyFVNL4g&user%5Busername%5D=new_user&user%5Bpassword%5D=new_password&user%5Bpassword_confirmation%5D=new_password&button=
Obtain a reverse shell via the Gogs service

Proof.txt