Password Backup File
PEAS has discovered an interesting file located at the /opt
directory
www-data@cmess:/tmp$ cd /opt
www-data@cmess:/opt$ ll
total 12K
4.0K drwxr-xr-x 2 root root 4.0K Feb 6 2020 .
4.0K -rwxrwxrwx 1 root root 36 Feb 6 2020 .password.bak
4.0K drwxr-xr-x 22 root root 4.0K Feb 6 2020 ..
www-data@cmess:/opt$ cat .password.bak
andres backup password
UQfsdCB7aAP6
The .password.bak
file contains what appears to be the password of the andre
user
I will validate the credential via SSH