A structured lesson workspace with readable content, hands-on examples, and a clean path to completion.
You're staring at a PRTG Network Monitor instance on port 8080. Version 17.3.33.2830. The default credentials prtgadmin:prtgadmin didn't work, but prtgadmin:Password123 did. Now you're in the admin console. And this version is vulnerable to CVE-2018-9276.
This is blind command execution. You won't see output in the browser. You verify success by attempting to authenticate with the newly created account.
Pwn3d. Local admin confirmed. From here, RDP, WinRM, evil-winrm, wmiexec.py, psexec.py—take your pick for interactive access.
The notification can be scheduled to run at specific intervals. During a long-term engagement, this functions as a persistence mechanism. Modify the schedule in Account Settings to get your connection back daily.
PRTG has 26 CVEs total. Only four have public PoCs. But the authenticated command injection in the notification system is all you need when the credentials are weak. One semicolon. That's the entire exploit.
Finish the lesson once you have worked through the material. This awards ★ 30 XP.