Personal Pentest Sample

Personal Hard 3/20/2023
#Cloud #Web

Summary

Personal pentesting engagement writeup.

Enumeration

  • Cloud asset discovery
  • Web app fuzzing

Foothold

Gained access via misconfigured API.

Privilege Escalation

Escalated using container breakout.

Post-Exploitation

Extracted sensitive data and maintained persistence.