Checker Hack the Box Season 7 (Linux Hard)
by RedBlock - Saturday February 22, 2025 at 02:24 PM
#31
I guess the vector attack is LFR (Local FIle Read) via ssrf https://fluidattacks.com/blog/lfr-via-bl...ook-stack/, but I edited the exploit and it didn't work as expected, I still believe that the intended way
Reply
#32
(Feb 22, 2025, 09:19 PM)0xdaniii Wrote:
(Feb 22, 2025, 08:11 PM)HRS4156453 Wrote: I have got bookstack creds:
bob:mYSeCr3T_w1kI_P4sSw0rD

how did you got this ?

Its in Teampass
Reply
#33
yes exploit works, modify the script to send payloads with request format, and it'll read file, it's kinda slow, but that's the exploit
Reply
#34
New subdomain Unlocked:
vault.checker.htb

XD
Reply
#35
(Feb 22, 2025, 09:29 PM)v3701 Wrote: yes exploit works, modify the script to send payloads with request format, and it'll read file, it's kinda slow, but that's the exploit

Can u show me ur changes?
Reply
#36
(Feb 22, 2025, 09:29 PM)v3701 Wrote: yes exploit works, modify the script to send payloads with request format, and it'll read file, it's kinda slow, but that's the exploit

Can you explain a little more?
Reply
#37
https://github.com/synacktiv/php_filter_...le_exploit
Reply
#38
did anyone manage to get the otp?
Reply
#39
anyone got the correct way in? im stuck...
Reply
#40
does any one have any way to get foothold is it ssrf?????
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 46 3,656 2 hours ago
Last Post: fuck_you_bytetobreach
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 98 9,036 10 hours ago
Last Post: Zacker90
  SVCHOST Injector 2026 opsecmaster67 0 80 Yesterday, 01:41 PM
Last Post: opsecmaster67
  Cold Seal 5.6 cracked Sensitive information can be exposed or stolen opsecmaster67 0 70 Yesterday, 01:38 PM
Last Post: opsecmaster67
  EagleRAT v2.5 Create backdoor access points opsecmaster67 0 63 Yesterday, 01:37 PM
Last Post: opsecmaster67

Forum Jump:


 Users browsing this forum: 1 Guest(s)