Sep 01, 2023, 01:15 PM
looool perfect .. thanks !!
|
[FREE] HTB Zipping - DETAILED WRITE-UP
by Mandelio - Monday August 28, 2023 at 12:55 AM
|
|
Sep 01, 2023, 01:15 PM
looool perfect .. thanks !!
Sep 01, 2023, 03:35 PM
(Aug 28, 2023, 07:02 PM)randomname188 Wrote:(Aug 28, 2023, 05:33 PM)PK6CfvT8 Wrote: Heey, thanks a lot! I was stuck on the RCE exploit for hours, thank you so much for this! (Aug 30, 2023, 07:42 AM)spooky_fruit Wrote: How to reverse engineer the stock executable to get that shared object path and name? I've been trying various decompilers without luck. Should I debug it in runtime?You shouldn't debug it in runtime. You have to use ghidra https://ghidra-sre.org/ (or similar app to it). Open binary, go to functions and find 'main'. There you will find XOR function call and hardcoded parameters. XOR output gives full path to shared object. void XOR(long param_1,ulong param_2,long param_3,long param_4)
Sep 01, 2023, 05:04 PM
machine pwned!!
Sep 02, 2023, 06:50 PM
I still don't understand how the pdf bypass works. I can't even upload a legitimate pdf compressed as zip without it telling me to "include a single pdf file". An explanation would be appreciated because I have been stuck all day, and using the script without knowing how the bypass works feels like cheating
Sep 03, 2023, 11:15 AM
Thx for sharing!
Sep 03, 2023, 03:11 PM
Thanks so mcuh!
Sep 04, 2023, 03:55 PM
thanks a lot!
Sep 04, 2023, 05:48 PM
(Aug 28, 2023, 12:55 AM)Mandelio Wrote: Hi guys! I'm releasing my second writeup on here. Thanks! I really needed a nudge
Sep 04, 2023, 08:41 PM
(Aug 31, 2023, 08:30 PM)Azad23 Wrote:(Aug 30, 2023, 07:42 AM)spooky_fruit Wrote: How to reverse engineer the stock executable to get that shared object path and name? I've been trying various decompilers without luck. Should I debug it in runtime? Can you elaborate your 'basic "file check up"'? It's true you can find password with 'strings' and path with 'strace'. But how to understand you have to forge shared object? BTW there is no ltrace on server. |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 40 | 3,288 |
22 minutes ago Last Post: MK_U |
||
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 28 | 2,638 |
23 minutes ago Last Post: MK_U |
||
| [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot | 95 | 8,701 |
4 hours ago Last Post: zxACASD |
||
| CBBH Write Ups | 26 | 6,678 |
Today, 08:45 AM Last Post: d39ug |
||
| [FREE] HackTheBox Dante - complete writeup written by Tamarisk | 606 | 94,614 |
Today, 08:36 AM Last Post: Gotoschool |
||