This script implements a lab automation where I exploit CVE-2021-43798 to steal user secrets and then gain privileges on a Linux system.# LabAutomationCVE-2021-43798
I make a script for pentest automation where i exploit CVE-2021-43798 (a path traversal on Grafana) to steal user secrets (SSH key) and then gain privileges on a Linux system (using SUID).
I automate this lab to share the pentest methodology.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view