Nov. 19, 2022, 2:58 p.m. | IppSec

IppSec www.youtube.com

00:00 - Intro
00:50 - Start of nmap
04:00 - Navigating to the page
05:00 - Discovering the forgot password feature enables people to enumerate valid users
06:45 - Finding the default credentials for mojo portal and then logging in as admin
07:50 - Uploading an ASPX Webshell but finding out the aspx extension is blacklisted
10:30 - Looking at the GitHub issues for MojoPortal
12:00 - Copying a file to bypass the bad extension filter of uploaded material and …

hackthebox

Information Security Engineers

@ D. E. Shaw Research | New York City

Embedded Penetration Tester - Cyber Security Team [BGSW]

@ Bosch Group | Warszawa, Poland

Staff Cybersecurity Engineer

@ Torc Robotics | Blacksburg, VA; Remote, US

Cybersecurity Engineer

@ Tiro Solutions Group LLC | Downers Grove, Illinois, United States

Director, Network Compliance

@ Marriott International | Bethesda, MD, United States

Cybersecurity Manager

@ Tiro Solutions Group LLC | Downers Grove, Illinois, United States