December 2017
Intermediate to advanced
410 pages
11h 5m
English
Since there were several instances of the same application in the load-balanced environment, Harsh quickly decided to lock the index.php file with the chattr command so that it could not be modified.
The file uploaded functionality was only through port 8080 and was part of the basic authentication.
It seemed that the port 8080 was open to the public and that the attacker was able to bruteforce into the credentials.
Meanwhile, he removed the affected server from the load balancer and initiated a snapshot of the entire server, which will be used as evidence.
Read now
Unlock full access