Photographer 1 📅 Aug 19, 2021 · ☕ 3 min read · ✍️ m0nk🏷️ Samba gobuster Koken CMS PHP Reverse Shel File Upload GTFObins PHP SUIDThis is a fun box where we have to exploit an authenticated file upload vulnerability to get a shell on the machine. The credentials for the authentication to the Koken CMS is revealed in an open file share.