czwartek, 26 marca 2020

Postauth RCE in Symantec Web Gateway

Last time I decided to check Symantec Web Gateway (version I tried was Below you will find few notes from the journey. Here we go...
Today we'll start here:

In this document I described the way to exploit the bug I found (for postauth users) in Symantec Web Gateway (v. Quick intro for created 10 pages PDF:

Reader will be able to reproduce the attack 'step-by-step' to achieve similar results as presented on the screen below:

Yes, webshell. But don't worry. I also described quick way to get root. ;)

I hope you'll find IT useful.

See you next time!

