Samba 4.6.3 with a writable guest share, vulnerable to SambaCry (CVE-2017-7494): a client that uploads a shared library to the share can make smbd load it by naming its server-side path as a named pipe.
Pas commencéDockercommit 4803e9dx86_64 · aarch64Secret
Exploit CVE-2017-7494 (SambaCry) to get a shell on the Samba server.
Le brief de ce lab se trouve dans son dépôt.