crowd42 is a user on infosec.exchange. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.
crowd42 @crowd42

That moment when your conducting a pentest, gain access to a development server but not the production one and then you try ssh user@serverIP and it works...

· Web · 3 · 4

@tinker it gets even better /o\ checked the .bash_history file on the prod file -> mysql -u root -h IP -p
Remote connection to the mysql server is enabled and uess what's the pwd? "toor"!

I swear its the truth /o\

@crowd42 - FUUUUUU....

Hurts. Great find! But shit... 😝