> For the complete documentation index, see [llms.txt](https://lyethar.gitbook.io/methodology/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://lyethar.gitbook.io/methodology/readme/exploitation/web-applications/collection-of-vulnerable-apps/argus-surveillance-dvr-4.0.md).

# Argus Surveillance DVR 4.0

The Argus Surveillance DVR 4.0 web application allows for Local File Inclusion when backspacing with ..%2F, which is jut ../ url encoded.&#x20;

{% embed url="<https://www.exploit-db.com/exploits/45296>" %}

Focus on this exploit if you encournter it, the others are elevation exploits. Look around for different services that we can look for credentials, maybe SAM, maybe ssh, maybe FTP.

Also look keep attention at the application and the users. Although this could not be the case, the application could display users that we could use to brute force services.&#x20;

Take a look at DVR4.&#x20;

We were able get the User/.ssh/id\_rsa and use that to log in to the ssh server.&#x20;

<details>

<summary>Examples of Argus Exploitation </summary>

[https://app.gitbook.com/s/v5OsoS0EWRil2VLfWYhH/exploitation](https://lyethar.gitbook.io/dvr4/exploitation)

</details>
