BigBang a Linux - Hard Machine
by StingEm - Saturday January 25, 2025 at 03:24 PM
#11
(Jan 25, 2025, 08:06 PM)BFischer Wrote: Where is that SSRF?

idk but i guess user needs to upload image to get ssrf
Reply
#12
Maybe this article will help...
https://medium.com/tenable-techblog/word...ecb5575ed8

Has anybody tried this?
Reply
#13
(Jan 25, 2025, 08:19 PM)potato_moose Wrote: Maybe this article will help...
https://medium.com/tenable-techblog/word...ecb5575ed8

Has anybody tried this?

Yes - but so far I just keep getting errors - I am going thru the code now.
Reply
#14
(Jan 25, 2025, 08:19 PM)potato_moose Wrote: Maybe this article will help...
https://medium.com/tenable-techblog/word...ecb5575ed8

Has anybody tried this?

Tried not work for me
Reply
#15
(Jan 25, 2025, 08:19 PM)potato_moose Wrote: Maybe this article will help...
https://medium.com/tenable-techblog/word...ecb5575ed8

Has anybody tried this?

Yes....
I am thinking its get admin dash then upload plugin then deserialize?
Reply
#16
{"status":"FAILED","response":"File type  is not allowed."}
Reply
#17
http://blog.bigbang.htb/wp-login.php/ login page

http://blog.bigbang.htb/wp-login.php/ login page
Kappa
Reply
#18
(Jan 25, 2025, 08:19 PM)potato_moose Wrote: Maybe this article will help...
https://medium.com/tenable-techblog/word...ecb5575ed8

Has anybody tried this?

It seems, but I didn't find a public call chain for insecure deserialization. phpggc didn't help
Reply
#19
there's this

https://www.ambionics.io/blog/iconv-cve-2024-2961-p1

I think we have to go after the file read vuln
Reply
#20
(Jan 25, 2025, 09:00 PM)thedubb1313 Wrote: there's this

https://www.ambionics.io/blog/iconv-cve-2024-2961-p1

I think we have to go after the file read vuln
Agreed, big question is how to write his binary to web exploit ...  We need to adapt cnext-exploit.py

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 66 1,772 2 hours ago
Last Post: vlka
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 370 92,495 7 hours ago
Last Post: lifolifo007
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,208 10 hours ago
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,521 Apr 29, 2026, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 414 Apr 29, 2026, 10:36 PM
Last Post: op334

Forum Jump:


 Users browsing this forum: 1 Guest(s)