HTB - Codify
by chillywilly - Saturday November 4, 2023 at 07:13 PM
#21
(Nov 04, 2023, 09:37 PM)chillywilly Wrote: i got mysql pwd but cant log in directly :/

How did u find it?
Reply
#22
(Nov 04, 2023, 09:44 PM)gotti1312 Wrote:
(Nov 04, 2023, 09:37 PM)chillywilly Wrote: i got mysql pwd but cant log in directly :/

How did u find it?
bruteforcing the script
Reply
#23
Any hints for root ? Im going mad
Reply
#24
(Nov 04, 2023, 10:10 PM)ruh32vygzblbc5xhg2 Wrote: script pw is not properly escaped

not seeing where this being passed in a context where shell globbing or expansion could occur in an unintended way
Reply
#25
has anyone got any ideas for root? the backup.sh file seems to be the one but can't find anything wrong with it
Reply
#26
Unescaped variable use in conditionals can be influenced to always validate true.
Reply
#27
(Nov 04, 2023, 11:36 PM)ajasjas Wrote: Unescaped variable use in conditionals can be influenced to always validate true.

I found this poc, "https://gist.github.com/arkark/c1c57eaf3e0a649af1a70c2b93b17550" But i don't know how to use.
Can you help for foothold user
Reply
#28
(Nov 04, 2023, 11:49 PM)nenandjabhata Wrote:
(Nov 04, 2023, 11:36 PM)ajasjas Wrote: Unescaped variable use in conditionals can be influenced to always validate true.

I found this poc, "https://gist.github.com/arkark/c1c57eaf3e0a649af1a70c2b93b17550" But i don't know how to use.
Can you help for foothold user

I used this 
https://gist.github.com/leesh3288/381b23...90cc8bb244

only change the command "touch"
Reply
#29
here is useful link for root:
https://tldp.org/LDP/abs/html/comparison-ops.html
Reply
#30
(Nov 04, 2023, 11:57 PM)blade33 Wrote: here is useful link for root:
https://tldp.org/LDP/abs/html/comparison-ops.html

nice link ...

user hints : 
there are two ways :all the  PoCs  here valid and working , or u can use require('node:child_process')  and write your own ... each them end up whit RCE 

Root : 
2 ways : exfill char by char , manually or via script  OR u can use  2 ssh session and pspy but may is the unintended way,faster for sure 

p.s. if u want learn do a jucy script to exfill chars

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | https://breachforums.ai/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 66 1,785 4 hours ago
Last Post: vlka
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 370 92,546 9 hours ago
Last Post: lifolifo007
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,215 Yesterday, 02:10 PM
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,525 Apr 29, 2026, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 414 Apr 29, 2026, 10:36 PM
Last Post: op334

Forum Jump:


 Users browsing this forum: 1 Guest(s)