Posts: 148
Threads: 12
Joined: Jan 2024
https://app.hackthebox.com/challenges/htbankThis forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Compromised - Malware Logs
Posts: 231
Threads: 18
Joined: Jul 2023
i tried ssti but nothing seems to work with user input!
Any ideas?
Posts: 148
Threads: 12
Joined: Jan 2024
No i am also STUCK. This forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Compromised - Malware Logs
Posts: 11
Threads: 0
Joined: Jan 2024
Look at home.js
xhr.open('GET', "https://api.etherscan.io/api?module=account&action=balance&address=0x5A0b54D5dc17e0AadC383d2db43B0a0D3E029c4c&tag=latest&apikey=FH12Z2IYGM3JKD1RN42NG6VHSXV73YX61H", true);
Posts: 148
Threads: 12
Joined: Jan 2024
(Jan 21, 2024, 12:39 AM)ZombieBear Wrote: Look at home.js
xhr.open('GET', "https://api.etherscan.io/api?module=account&action=balance&address=0x5A0b54D5dc17e0AadC383d2db43B0a0D3E029c4c&tag=latest&apikey=FH12Z2IYGM3JKD1RN42NG6VHSXV73YX61H", true);
This looks like web3 This forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Compromised - Malware Logs
Posts: 11
Threads: 0
Joined: Jan 2024
No, if you are looking at:
$('.bal').text(bal.toFixed(4));
Posts: 14
Threads: 0
Joined: Jan 2024
I tired ssti , nothin , also that api seems that have no permission to modify balance only allows to see the balance of the account, any ideas?
Posts: 14
Threads: 0
Joined: Jan 2024
(Jan 23, 2024, 11:32 AM)rat Wrote: it's super simple skid parameter pollution
Can u give me more details plz
Posts: 5
Threads: 0
Joined: Jan 2024
Posts: 14
Threads: 0
Joined: Jan 2024
(Jan 23, 2024, 08:56 AM)hotsweatyandready Wrote: poison the withdraw request, find the right amount
More details plz?
|