Backfire Hack the Box Season 7 (Linux medium)
by RedBlock - Saturday January 18, 2025 at 05:25 PM
#41
I think i'm at the same place Donde. Can hit the teamserver port on 40056 with SSRF, it even responds that websockets are available but when trying to send a manually request to upgrade it, it just fails every time. There is the tls note on 8000 that shows a git diff where they disabled TLS on the websocket interface on 40056 but... i'm still missing something.
Reply
#42
(Jan 18, 2025, 10:08 PM)llamamorg Wrote: I think i'm at the same place Donde. Can hit the teamserver port on 40056 with SSRF, it even responds that websockets are available but when trying to send a manually request to upgrade it, it just fails every time. There is the tls note on 8000 that shows a git diff where they disabled TLS on the websocket interface on 40056 but... i'm still missing something.

Pretty sure that note is just to tell us we are on the right way. If ssl was on you'd have to manage that in your code and that would be a horror.
Reply
#43
It's the "connection" header. If you change it from close to upgrade the server doesn't respond. Maybe there's a websocket header that we're missing
Reply
#44
(Jan 18, 2025, 10:08 PM)llamamorg Wrote: I think i'm at the same place Donde. Can hit the teamserver port on 40056 with SSRF, it even responds that websockets are available but when trying to send a manually request to upgrade it, it just fails every time. There is the tls note on 8000 that shows a git diff where they disabled TLS on the websocket interface on 40056 but... i'm still missing something.

how are you getting it to respond that websockets are available?

I can only get it to tell me if a URI exists or not
Reply
#45
(Jan 18, 2025, 11:23 PM)ZenMunk3y Wrote:
(Jan 18, 2025, 10:08 PM)llamamorg Wrote: I think i'm at the same place Donde. Can hit the teamserver port on 40056 with SSRF, it even responds that websockets are available but when trying to send a manually request to upgrade it, it just fails every time. There is the tls note on 8000 that shows a git diff where they disabled TLS on the websocket interface on 40056 but... i'm still missing something.

how are you getting it to respond that websockets are available?

I can only get it to tell me if a URI exists or not

did you read the prior code that said its a websocket? it earlier said that port 40056 is a websocket, on that file on port 8000.
Reply
#46
ok so just a thought, when you try to ssh to the box it doesn't ask you for a password and looks like it's set up to use id_rsa for authentication. So this makes me think we have to use the SSRF to be able to get that file somehow in order to get access as either ilya or sergej.
Reply
#47
Someone, pleaseee. Leak this fucking script
Reply
#48
(Jan 18, 2025, 11:44 PM)samuelballsiu1 Wrote: Someone, pleaseee. Leak this fucking script

write it yourself brotha
Reply
#49
(Jan 19, 2025, 01:32 AM)alexbobarszismyname Wrote:
(Jan 18, 2025, 11:44 PM)samuelballsiu1 Wrote: Someone, pleaseee. Leak this fucking script

write it yourself brotha

brother can you share with me i am having some problems it is giving me shell of my machine instead of target
Reply
#50
(Jan 19, 2025, 01:32 AM)alexbobarszismyname Wrote:
(Jan 18, 2025, 11:44 PM)samuelballsiu1 Wrote: Someone, pleaseee. Leak this fucking script

write it yourself brotha

Is the idea of combing the rce with the ssrf so we can reach the internal port correct?

Don't want to be wasting my time
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 73 2,332 4 hours ago
Last Post: louikizzz
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 89 8,099 4 hours ago
Last Post: Xploitd
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 10 626 8 hours ago
Last Post: chufoni
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 28 2,849 8 hours ago
Last Post: chufoni
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 375 93,674 8 hours ago
Last Post: Johe

Forum Jump:


 Users browsing this forum: 2 Guest(s)