Nov 02, 2024, 10:06 AM
(Nov 01, 2024, 11:24 PM)dannyk Wrote:(Oct 27, 2024, 07:45 PM)st123 Wrote:(Oct 23, 2024, 02:43 AM)olkn00b Wrote:(Oct 22, 2024, 03:50 PM)BFischer Wrote:(Oct 12, 2024, 01:22 AM)olkn00b Wrote: Here are hints if you stuck at creating the chain gadget
Object Chain Creation:
Use ArrayHelpers to manage a collection and set its callback to a function that can execute system commands.
Appending Commands:
Append a command that you want to execute to the ArrayHelpers instance.
Flavors Assignment:
Assign the ArrayHelpers instance to the flavors property of an IceCream object.
Invoke Behavior:
Make sure the IceCream object is invoked by passing it into another class.
Setting Sauce:
Use a Spaghetti object to hold the IceCream instance in its sauce property.
Pizza Class Usage:
Create a Pizza object and assign the Spaghetti instance to its size property.
Serialization:
Serialize the Pizza object and encode it to base64 for the payload.
Can you explain it more? It's slightly hard.
Have not solved it yet, that was hints from someone who has
going back to this now, yes it's slightly hard
This payload works locally when testing but I can't get it to work on the target, tried multiple commands (id & some rev shells)
Tzo1OiJQaXp6YSI6MTp7czo0OiJzaXplIjtPOjk6IlNwYWdoZXR0aSI6MTp7czo1OiJzYXVjZSI7Tzo4OiJJY2VDcmVhbSI6MTp7czo3OiJmbGF2b3JzIjthOjE6e2k6MDtPOjEyOiJBcnJheUhlbHBlcnMiOjI6e3M6NDoiZGF0YSI7YToxOntpOjA7czoxNToiY2F0IC9ldGMvcGFzc3dkIjt9czo4OiJjYWxsYmFjayI7czoxNToiZXhlY3V0ZV9jb21tYW5kIjt9fX19fQ==
Not sure what I am doing wrong here, they all work good locally as said above.
Hmm.
Hi, did u figure this out yet ?
Did you figure it out or do you still need help ?
i found it . thx