> For the complete documentation index, see [llms.txt](https://lyethar.gitbook.io/ut99/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://lyethar.gitbook.io/ut99/enumeration/web-services.md).

# Web Services

![](https://2908053610-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYHYrY7W6LPyh4URSZJKR%2Fuploads%2FbotfGaHcaCr8Q7CNAYFH%2F2022-07-11_13-06.png?alt=media\&token=9db384d6-a223-4e7c-880a-9da946f7f781)

Port 80 and 443, were hosting some sort of gaming forum where there some mentions of a videogame that they were playing foreshadowing to the exploitation of Unreal Tournament 99. Morever I tried to exploit different vulnerabilities that this "DragonFly" CMS is vulnerable to but I was not able to get anyting out of it.&#x20;

![](https://2908053610-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYHYrY7W6LPyh4URSZJKR%2Fuploads%2FqlRzCoHYG3E58THkg6ew%2F2022-07-11_13-08.png?alt=media\&token=653db188-26da-4583-bfa7-925881ae9413)

Notice the RCE exploit at the top.&#x20;

![](https://2908053610-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYHYrY7W6LPyh4URSZJKR%2Fuploads%2FENoqw02Ndfx5YwMs7rE7%2F2022-07-11_13-17.png?alt=media\&token=71f6710d-5216-4e12-8c22-29159c6c9a8b)

![](https://2908053610-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYHYrY7W6LPyh4URSZJKR%2Fuploads%2FqVKuigSOxrB5O3WHwBnz%2F2022-07-11_13-18.png?alt=media\&token=0318c5af-211b-4436-9c4c-d0ebaeac5b71)

I unfortunately did not have access to the install.php parameter that the exploit was refering to.&#x20;

I didn't want to get hardstuck on making this exploit work so I just went away and enumerated more.&#x20;

![](https://2908053610-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYHYrY7W6LPyh4URSZJKR%2Fuploads%2FNxJyYx1AlrjeY9WPEG3x%2F2022-07-11_13-31.png?alt=media\&token=458bcda9-da59-4d45-b752-76eb1522a82f)

/phpmyadmin/&#x20;

VERSION 4.4 was not vulnerable to any public exploits so besides bruteforcing the login portal was not able to do much.
