CDNio HTB
by cavour13 - Saturday January 11, 2025 at 09:37 AM
#11
(Jan 30, 2025, 01:51 PM)bxdman Wrote: Can anyone help me with a hint?

check bot_runner. make bot request a page and cache it.
Reply
#12
I know the principle is a Cache spoofing attack, but I'm having a bit of trouble making a cache using /visit, there's no way to make one correctly. My payload is being returned with a 400 status code. Can anyone give a little hint on this? Confused
Reply
#13
(Feb 09, 2025, 12:45 PM)akared666 Wrote: I know the principle is a Cache spoofing attack, but I'm having a bit of trouble making a cache using /visit, there's no way to make one correctly. My payload is being returned with a 400 status code. Can anyone give a little hint on this? Confused

Well, I've got the flag, if you encounter the same 400 status code as me just need to modify your http header, if the error is “invalid token” then send a few more requests on the line, the reason is not clear!
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 10 597 1 hour ago
Last Post: chufoni
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 28 2,824 1 hour ago
Last Post: chufoni
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 375 93,498 1 hour ago
Last Post: Johe
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 604 92,606 1 hour ago
Last Post: Johe
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,994 3 hours ago
Last Post: char0n1507

Forum Jump:


 Users browsing this forum: 1 Guest(s)