HTB - Shibboleth Walkthrough 🥷
🔍 Initial Recon
🔎 TCP Scan
80/tcp open http syn-ack Apache httpd 2.4.41
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
|_http-title: Did not follow redirect to http://shibboleth.htb/
|_http-server-header: Apache/2.4.41 (Ubuntu)
Service Info: Host: shibboleth.htb623/udp open asf-rmcp🌐 Subdomain Discovery
ffuf -u http://shibboleth.htb -H 'Host: FUZZ.shibboleth.htb' -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt -fw 18🔁 Circle Back to UDP (623/IPMI)
🔐 Zabbix Login
🖥️ Reverse Shell via Zabbix

🔄 Priv Esc - Switching Users
🧪 Enumeration & Dead Ends
🤯 Moment of Clarity: MariaDB Version Exploit (CVE-2021-27928)
🧠 Lessons Learned
Last updated