10.200.101.150 [git-serv]

sshuttle -r [email protected] --ssh-cmd "ssh -i opt/wreath_key" 10.200.101.0/24

Password spray

  • admin:admin

  • admin:password

  • root:root

Possible exploits

Intended Route

Use the uploaded PHP RCE exploit to execute commands

Unintended Route