Enumeration
Run Nmap Scan
View Website

Directory Bruteforcing (Run Gobuster)
Visit /host-manager

Default Credentials
Exploitation
Visit /manager
Use the default credentials, we gained from the “/host-manager” page
Finding a File Upload Menu

Generating Reverse Shell
Uploading our Reverse Shell

Listen to Reverse Shell and Execute the Reverse Shell
