• XSS.stack #1 – первый литературный журнал от юзеров форума

Selling Access to IT-based web agency hosting 20+ client sites and databases.

В этой теме можно использовать автоматический гарант!

Статус
Закрыто для дальнейших ответов.

hackutron

CD-диск
Пользователь
Регистрация
01.09.2023
Сообщения
11
Реакции
0
Цена
10000
Контакты
all
🧨 [WTS] Full RCE Access – Dev Agency Server – 20+ Live WP Sites + DB + Docker – IT 🇮🇹

Initial Access:
Remote code execution via domain.com/?cmd= — injectable directly from the browser.
Possibility to get a stable reverse shell (tested with Meterpreter payload, without issues).

Host Details:
This is the production server of an active web development company based in Italy.
Manages infrastructure for over 20 different companies, including:

WordPress instances (isolated per client)
Multiple WooCommerce stores
Direct access to phpMyAdmin panels
Full access to MySQL database (credentials included)
1 exposed Docker container (unexplored, potential for lateral movement)

OS information:

Linux Ubuntu-2204-jammy-amd64-base
Kernel: 5.15. 0-100-generic #110-Ubuntu SMP
x86_64 GNU/Linux

Other notes:

Persistent access available (webshell, reverse, meterpreter)
No AV/EDR detected on host
Some contain PII, invoices, and payment gateway configurations
 
Статус
Закрыто для дальнейших ответов.
Верх