Version CVEs & Response Triggers
CMS / version enum: CMSeeK - cmseek → WPScan / searchsploit → Trickest CVE PoCs · Reference
Kernel / local exploit hints: linux-exploit-suggester → Dirty Pipe - CVE-2022-0847 · Baron Samedit - CVE-2021-3156 · Dirty COW - CVE-2016-5195 · pkexec - CVE-2021-4034 PwnKit
HTTP/1.1 403 Forbidden
resource exists but blocked → try:
- extensions
- alternate methods
- path traversal
- fuzzing
Set-Cookie: PHPSESSID=
Think:
> PHP app → LFI, upload, deserialization, weak auth patterns
Docker API on 2375
Think:
> container breakout / host compromise
Jenkins dashboard exposed
Think:
> script console RCE
uploads/avatar.php.jpg
Think:
> extension filtering weakness
JWT token uses alg=HS256
Think:
> weak secret, JWT attacks — [[Cookie Decoding]]
Cookie contains Base64 JSON / session=xxx.yyy.zzz
Think:
> Flask → [[Cookie Decoding]] flask-unsign -d -c
> JWT → jwt_tool / jwt.io
> tampering, weak secret, auth bypass
URL fetch feature
Think:
> SSRF immediately
Server: nginx/1.14.0 (Ubuntu)X-Powered-By: PHP/7.2
Think:
> old PHP version, possible known CMS vulns, upload abuse
OpenSSH 7.2p2 Ubuntu
Think:
> Probably not directly exploitable remotely
> Look for weak creds, reused keys, old crypto, user enumeration
Forgot Password
Think:
> reset poisoning, token prediction, email enumeration