Posts: 36
Threads: 1
Joined: Jun 2023
I guess the vector attack is LFR (Local FIle Read) via ssrf https://fluidattacks.com/blog/lfr-via-bl...ook-stack/, but I edited the exploit and it didn't work as expected, I still believe that the intended way
Posts: 72
Threads: 3
Joined: Jan 2025
(Feb 22, 2025, 09:19 PM)0xdaniii Wrote: (Feb 22, 2025, 08:11 PM)HRS4156453 Wrote: I have got bookstack creds:
bob:mYSeCr3T_w1kI_P4sSw0rD
how did you got this ?
Its in Teampass
Posts: 36
Threads: 1
Joined: Jun 2023
yes exploit works, modify the script to send payloads with request format, and it'll read file, it's kinda slow, but that's the exploit
Posts: 72
Threads: 3
Joined: Jan 2025
New subdomain Unlocked:
vault.checker.htb
XD
Posts: 9
Threads: 0
Joined: Feb 2025
(Feb 22, 2025, 09:29 PM)v3701 Wrote: yes exploit works, modify the script to send payloads with request format, and it'll read file, it's kinda slow, but that's the exploit
Can u show me ur changes?
Posts: 13
Threads: 0
Joined: Aug 2024
(Feb 22, 2025, 09:29 PM)v3701 Wrote: yes exploit works, modify the script to send payloads with request format, and it'll read file, it's kinda slow, but that's the exploit
Can you explain a little more?
Posts: 25
Threads: 5
Joined: Jan 2025
Posts: 72
Threads: 3
Joined: Jan 2025
did anyone manage to get the otp?
Posts: 25
Threads: 5
Joined: Jan 2025
anyone got the correct way in? im stuck...
Posts: 11
Threads: 0
Joined: Aug 2024
does any one have any way to get foothold is it ssrf?????
|