Bizness - HTB
by paven - Saturday January 6, 2024 at 01:03 PM
#1
Bizness - Linux - Easy

Good luck everyone! Let's tackle this together!
https://app.hackthebox.com/machines/Bizness
Reply
#2
Guys, let's go, we can do it.
Reply
#3
Is there anyone who can access the machine? It keeps displaying a network error message whenever I tries to connect.
Reply
#4
https://bizness.htb/control/login
Reply
#5
(Jan 06, 2024, 08:07 PM)ElBakhaw Wrote: got user


anyone get something for root ?

how did u get user ?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#6
(Jan 06, 2024, 08:07 PM)ElBakhaw Wrote: got user


anyone get something for root ?

I'm not sure but...

ofbiz@bizness:~/l$ getcap -r / 2>/dev/null
/usr/bin/ping cap_net_raw=ep
/home/ofbiz/l/python3 cap_setuid=eip
Reply
#7
its apache ofbiz exploit for user
Reply
#8
(Jan 06, 2024, 08:20 PM)ElBakhaw Wrote:
(Jan 06, 2024, 08:13 PM)betecito Wrote:
(Jan 06, 2024, 08:07 PM)ElBakhaw Wrote: got user


anyone get something for root ?

I'm not sure but...

ofbiz@bizness:~/l$ getcap -r / 2>/dev/null
/usr/bin/ping cap_net_raw=ep
/home/ofbiz/l/python3 cap_setuid=eip

not vulnerable

btw did you manage to get a good shell ? mine breaks after 2 minutes it's soooo annoying

yes, https://github.com/abdoghazy2015/ofbiz-C...exploit.py shell option
shell option
Reply
#9
Yeah, it's that exploit for user. Use the RCE option of the exploit, also grab ysoserial for it and set temporarily java11... and then its just finding the right payload for revshell. Easy user.

But for rooting meh... cap_setuid=eip is juicy but doesn't work as it should so has to be something else.
Reply
#10
@ElBakhaw You need to be using java 11
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 46 3,661 3 hours ago
Last Post: fuck_you_bytetobreach
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 98 9,043 10 hours ago
Last Post: Zacker90
  SVCHOST Injector 2026 opsecmaster67 0 81 Yesterday, 01:41 PM
Last Post: opsecmaster67
  Cold Seal 5.6 cracked Sensitive information can be exposed or stolen opsecmaster67 0 71 Yesterday, 01:38 PM
Last Post: opsecmaster67
  EagleRAT v2.5 Create backdoor access points opsecmaster67 0 64 Yesterday, 01:37 PM
Last Post: opsecmaster67

Forum Jump:


 Users browsing this forum: 1 Guest(s)