Forum Discussion

GusC's avatar
GusC
Icon for Bronze III rankBronze III
9 months ago
Solved

CVE-2024-5910 (Palo Alto Expedition) – Defensive

Hello - I'm a bit stuck on 

CVE-2024-5910 (Palo Alto Expedition) – Defensive

I cannot see an obvious answer to 

After attempting to reset the admin credentials, which endpoint did the attacker attempt to connect to next?

any tips on how to complete? 

I'll do the offensive one now just in case that gives me something to pivot off. 

thanks - gus 

 

 

 

  • Hi GusC

    Each time the attacker attempts to reset the admin password (using the PHP file identified in task 2), they access the same endpoint immediately afterwards - which endpoint is it?

    Hope that helps!

4 Replies

  • Hi GusC

    Each time the attacker attempts to reset the admin password (using the PHP file identified in task 2), they access the same endpoint immediately afterwards - which endpoint is it?

    Hope that helps!

    • GusC's avatar
      GusC
      Icon for Bronze III rankBronze III

      ok got it thanks - I just didn't expect that answer, I was looking for a hostname of some sort. 

    • veryk's avatar
      veryk
      Icon for Bronze II rankBronze II

      I agree with GusC​ here, I was looking for an end point, hostname, URL, not what the answer was. Not until I read your hint did I even think about that could be the answer. Endpoint shouldn't be used and swapped out with what the answer is or at least added in to the question.