Cypher Hack the Box Season 7 (Linux Medium)
by RedBlock - Saturday March 1, 2025 at 01:37 PM
#11
(Mar 01, 2025, 01:37 PM)RedBlock Wrote: ## User.txt

ssh graphasm@cypher.htb

Pass: cU4btyib.20xtCMCXkBmerhK

## Root.txt

sudo /usr/local/bin/bbot -cy /root/root.txt -d --dry-run

hi sir i get this respond:
GET /?username=graphasm&hash=9f54ca4c130be6d529a56dee59dc2b2090e43acf

How do you get the cleartext?
Reply
#12
How did you manage to find the exact command needed to exploit login cypher injection ? Did you use cyphermap.py.? If so in my case it does not seems to be working can you share the command that you gave it to make it work?
Reply
#13
(Mar 02, 2025, 02:40 AM)OffensiveBias Wrote: How did you manage to find the exact command needed to exploit login cypher injection ? Did you use cyphermap.py.? If so in my case it does not seems to be working can you share the command that you gave it to make it work?


If you already found the jar file you may notice that its titled 'custom-apoc-extension...' I didn't realize it at first, but this is a good clue about how to leverage the injection. The post below is a good primer on cypher injection and using APOC modules. 
https://www.varonis.com/blog/neo4jection...d-exploits
Reply
#14
Sorry, worth mentioning that none of the APOC payloads on the page i mentioned above will work on their own. Still good food for thought :v:
Reply
#15
(Mar 01, 2025, 10:07 PM)d4rkc1ph3r Wrote:
(Mar 01, 2025, 08:50 PM)slimeylimey Wrote: You can also obtain a shell via the /api/cypher endpoint, optionally.

thanks matthew appreciate your skills

matthew is a cool name, i'll go by it from now on.
Reply
#16
root:
sudo /usr/local/bin/bbot --custom-yara-rules /root/root.txt -d
Reply
#17
Is there a way to get a reverse as root?
Reply
#18
Yo Red Block Did You recognize me? Big Grin
Reply
#19
the root privesc was so straightforward cool box
Reply
#20
the privesc was too easy, not a medium machine the only hard was finding the weird payload for the cypher injection, theres no much information about it...
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 42 3,391 51 minutes ago
Last Post: 0x5k1z0
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 385 95,829 3 hours ago
Last Post: rasa420
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 96 8,805 4 hours ago
Last Post: rasa420
  [FREE] CPTS 12 FLAGS pulsebreaker 86 3,108 4 hours ago
Last Post: Mr_root
  [FREE] HackTheBox Academy - CAPE Path Study Techtom 45 4,534 4 hours ago
Last Post: BlazeFury

Forum Jump:


 Users browsing this forum: 1 Guest(s)