Pentesting Lab Exercises Series - Vulnhub
Virtual Machine Name: MuzzyBox: 1
Link: https://www.vulnhub.com/entry/muzzybo...
Tips:
1. This machine is amazing where we can learn NoSQL bypass, SSTI injection, etc.
2. I encountered very weird thing to get privileged shell. Maybe I need to do the machine again in the future.
3. You probably will have problem with tplmap:
Tplmap assists the exploitation of Code Injection and Server-Side Template Injection vulnerabilities with a number of sandbox escape techniques to get access to the underlying operating system.
https://github.com/epinna/tplmap
4. NoSQL authentication bypass:
https://book.hacktricks.xyz/pentestin...