HackTheBox - Dog

00:00 - Introduction 00:57 - Start of nmap, discovering an open .git directory 04:15 - Using git-dumper to download the source code and discovering MySQL credentials 06:00 - Trying to enumerate usernames but running into bruteforce protection in the login and reset password functionality 12:45 - Looking for other ways to enumerate users, finding BackDropScan which shows another endpoint which is unprotected 17:00 - Logging into backdrop, then installing a malicious module 21:00 - Getting a shell on the box and then password re-use lets us switch to a different user 24:45 - We can run Bee with Sudo, finding out it has an eval command that lets us run commands 28:20 - Showing another way to find valid users, searching the git files for emails and getting tiffany.