I logged into the server FROM my laptop using the panel web interface so it grabbed the browser session and my ssh keys were in known_hosts I guess I dont fully understand it either I just know it was bad
Classic lateral movement. You trusted the panel the panel had a payload the payload had network access. Your ssh keys were probably in ~/.ssh and the panel ran as root so it read everything. Standard post-exploitation just you supplied the exploit yourself.
Post a reply
You need an account to reply.
Log in or
register to join the conversation.