Apache ActiveMQ 5.11.1 (with cron running), vulnerable to CVE-2016-3088: the fileserver application accepts PUT uploads anonymously, and its MOVE method moves the uploaded file to any path, so a file lands in the web root, a cron directory or an SSH key file.
Pas commencéDockercommit 1017982x86_64 · aarch64Secret
Exploit CVE-2016-3088 to write a file where it runs, get a shell on the ActiveMQ server and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.