DevOps Articles

Curated articles, resources, tips and trends from the DevOps World.

Pwning a Backend with a Backdoor

4 years ago 0xinfection.medium.com
Pwning a Backend with a Backdoor

Summary: This is a summary of an article originally published by the source. Read the full original article here →

In this quick blog post, I detail an unusual way in which I was able to escalate access to several production instances behind a properly secured network. It all started with me casually checking some traffic data for a tool I authored on GitHub.

The first thing that I always do in these situations is to verify whether or not my target site has a security contact.

Fiddling around a bit, but carefully, I figured that I was logged in with admin privileges.

Always look out for weird behavior in web-apps and try messing around with it.

Made with pure grit © 2024 Jetpack Labs Inc. All rights reserved. www.jetpacklabs.com