GitLab CVE-2023-7028 - Detailed Walkthrough - [TryHackMe LIVE!]
Tyler Ramsbey - Hack Smarter
0:00 / 0:00
GitLab CVE-2023-7028 - Detailed Walkthrough - [TryHackMe LIVE!]
1 908 просмотров · 2 года назад
Tyler Ramsbey - Hack Smarter
55,5 тыс. подписчиков
1 908 просмотров · 2 года назад
📚 Resources:
Enroll in my Courses (search for Tyler Ramsbey)
🔗 https://academy.simplycyber.io
Support me on Ko-Fi
🔗 https://ko-fi.com/tylerramsbey
Join Hack Smarter
🔗 https://hacksmarter.org/ Join the Hack Smarter community: https://hacksmarter.org
--- In this video, I work through the brand new TryHackMe room that explains CVE-2023-7028 which is a critical Gitlab vulnerability that allows an unauthenticated attacker to perform full account takeover on targeted accounts. This is a brand-new CVE that just released this month.
We then get hands-on and exploit the vulnerability ourselves and take over the administrator account for a Gitlab instance.
Finally, we take it a step further by then using SSH to connect to the victim machine and reading through the logs to identify how a blue team or SOC would identify if this exploit has happened in their environment.
Enjoy! ----------
This content is intended for educational purposes only. All demonstrations and techniques shown are designed to teach ethical hacking and improve cybersecurity. Any use of the information provided in these videos is done at your own risk and should be used responsibly. Unauthorized hacking, illegal activities, or violations of privacy are not endorsed or encouraged. Always ensure you have proper authorization before attempting any security testing or hacking.