YOUTUBE: This video is strictly for educational
purposes ONLY and for use on the HackTheBox cybersecurity training platform. I have 100% legal authorisation to use all systems shown in my videos.
Video demonstration of the exploitation of a Windows IIS Server, running Drupal Content Management System (CMS).
Level: Beginner/Intermediate
Tools used: Nmap, Wget, Metasploit.
Drupal 7.54 RCE exploit:
https://github.com/pimps/CVE-2018-7600
For vulnerable systems to practice
on, go to:
http://www.hackthebox.eu
Follow me on twitter:
/ tiger5tyle