
Merci pour le lien ! Oui, le dossier yggleak détaille tout : faille pre-prod (SphinxQL sans auth pour lire .env et configs), mot de passe admin dans sysprep_unattend.xml, escalade via SMB/RDP, pivot FileZilla vers tracker/web (CloudPanel CVE-2024-44765 + FastCGI). ~19 Go exfiltrés, 7 DB détruites. Clair et complet, merci du partage !
Post summary
The post reports a real exploitation chain involving SphinxQL, SMB/RDP, and CloudPanel CVE‑2024‑44765, with 19 GB exfiltrated and several databases destroyed, and refers to a detailed write‑up that likely contains a PoC.
