Jan 12, 2024, 11:09 PM
Hi everybody. How to get cookies from Proxmox site ??? Thanks advance.
http://10.9.0.1:8006|
Corporate - HTB
by chillywilly - Saturday December 16, 2023 at 06:06 PM
|
|
Jan 12, 2024, 11:09 PM
Hi everybody. How to get cookies from Proxmox site
http://10.9.0.1:8006(Jan 12, 2024, 11:09 PM)monkeythefirst Wrote: Hi everybody. How to get cookies from Proxmox siteThat is the last step in finishing the box. It assumes you did everything required before. You also found the backup zip. Which means you can access it. So you did the prerequisities. Once extracted it has everything required for a POC to be edited, adapted just a little bit, in order to forge the cookie. You forge cookies FOR the proxmox site, not FROM the site. And finally use that cookie to login, be root, do your thing. and probably feeling achievement finishing the longest box of past year...
Jan 13, 2024, 09:30 PM
Does anybody have a writeup for this box?
Jan 15, 2024, 04:07 AM
(This post was last modified: Jan 15, 2024, 04:08 AM by CubeMadness3.)
Anyone with write-up i can follow to root this machine? I already have the foothold (user) i'm stuck for 2 weeks now finding ways to root this machine. I already sent message to some folks around this forum asking for help rooting this machine. If anyone have detailed write-up or guide on rooting part. please thank you! Just Send me a message ?
Jan 18, 2024, 04:34 AM
thanks a lot
Jan 29, 2024, 06:15 PM
(Jan 25, 2024, 08:23 AM)berlik Wrote: Hi all. Help is needed. Stuck on ldap payload. I received all the flags and am now studying LDAP injections. I can’t find how to give injections in the dn. Please point me in the right direction or write me a personal message on how to reset the sysadmin password. Thank you. you can't do this through ldap directly as the unintended has been patched. you'd want to access gitea, get the secret to forge an engineer cookie for SSO, then you can reset the password. If you look at the code from gitea you'll see that the password will be updated in ldap by the app, so you can ssh in as engineer.
Feb 01, 2024, 01:23 PM
how to get the rsa key ?
Feb 21, 2024, 08:09 PM
This machine is insane lol.
Feb 23, 2024, 02:54 PM
(Feb 02, 2024, 06:23 PM)KayKay Wrote: you can't do this through ldap directly as the unintended has been patched. i have the Pin and the source code, and trying the reset the password for kian.rodriguez but steps not working. can someone share the steps again. [/quote] Hey did you manage to get root. im stuck on bruting bitwarden. its taking too long and killing my cpu. (Feb 23, 2024, 04:33 PM)Th35t0rm Wrote: I cant find JWT_SECRET at gitea From commits "people" repo. If you need help hit me up a DM.(Feb 23, 2024, 02:54 PM)st123 Wrote:(Feb 02, 2024, 06:23 PM)KayKay Wrote: you can't do this through ldap directly as the unintended has been patched. Hey did you manage to get root. im stuck on bruting bitwarden. its taking too long and killing my cpu. [/quote] You have disabled private messages. @st123 |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 23 | 2,187 |
2 hours ago Last Post: kkkato |
||
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 20 | 2,495 |
Yesterday, 11:06 PM Last Post: op334 |
||
|
|
[FREE] HackTheBox All Cheatsheets | 3 | 398 |
Yesterday, 10:36 PM Last Post: op334 |
|
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 369 | 92,014 |
Yesterday, 04:10 PM Last Post: sabbyahmed |
||
| CBBH Write Ups | 22 | 6,229 |
Yesterday, 06:39 AM Last Post: Usercomplex |
||