<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Path-Traversal on kanyo's blog</title><link>https://chaelsoo.me/tags/path-traversal/</link><description>Recent content in Path-Traversal on kanyo's blog</description><generator>Hugo -- gohugo.io</generator><language>en-gb</language><lastBuildDate>Tue, 26 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://chaelsoo.me/tags/path-traversal/index.xml" rel="self" type="application/rss+xml"/><item><title>HackINI 2026: Corp Monitor</title><link>https://chaelsoo.me/writeups/hackini-corp-monitor/</link><pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate><guid>https://chaelsoo.me/writeups/hackini-corp-monitor/</guid><description>&lt;p&gt;A Linux machine running a Drupal intranet CMS with an anonymous FTP server sitting next to it. The FTP turned out to be more of a hint than an attack surface. The real entry was Drupalgeddon2, a 2018 RCE that still shows up everywhere. Once inside, Grafana 8.2.6 was hiding on port 3000, running an unauthenticated path traversal that handed over root&amp;rsquo;s SSH key directly.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Did this one with &lt;a href="https://www.linkedin.com/in/aymen-drid-36bba4243/"&gt;Aymen&lt;/a&gt;. Always more fun when someone&amp;rsquo;s hunting alongside you and just as locked in. Big shoutout to him.&lt;/em&gt;&lt;/p&gt;</description></item></channel></rss>