HTB - Postman
TL;DR - Foothold through a misconfigured Redis instance by writing an SSH key into authorized_keys. From the redis user I find an id_rsa.bak belonging to Matt, crack its passphrase with john, and switch to Matt. Root comes from CVE-2019-15107 on Webmin, exploited through a Metasploit module. Recon Starting with a basic nmap scan with the following command: nmap -sV -sC -p- 10.129.2.1 -oA nmap/postman I got this output: ...