Walkthrough of the machine called “Cobbles” in the OffSec Proving Grounds…don’t watch unless you want help getting through the machine. We take advantage of Zoneminder using a python exploit, then use enumeration to figure out the proxy situation. We end up privilege escalating using the exact same exploit by taking advantage of a poorly designed docker proxy setup.
Posted inDocker Ethical Hacking Hacking Linux Networking Offsec Python Security Tutorial Walkthrough