grep -l "MotionEye" ./machines (1)

CCTV [Linux]
Easy
Default ZoneMinder credentials lead to RCE as www-data. Lateral movement via cracked bcrypt hash to SSH as mark, then sniffing Docker inter-container traffic for sa_mark credentials. Privilege escalation by abusing motionEye running as root to inject a reverse shell into camera event hooks.
ZoneMinderDefault CredentialsDockermotionEyeCredential SniffingRCE
● pwned