HTB Download
by WurumDurum - Sunday August 6, 2023 at 10:38 AM
#1
Someone on Download? Found something useful as a potential direction?
#2
i got an hint about prototype pollution. but i dont know much about it so still trying
#3
You want to use this: https://github.com/DigitalInterruption/cookie-monster

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Spamming | Contact us via http://breachedmw4otc2lhx7nqe4wyxfhpvy32ooz26opvqkmmrbg73c7ooad.onion/contact if you feel this is incorrect.
#4
Trying to enumerate the admin creds ..{id = 1, username= "admin"}.., inject it through the cookie and upload into his Panel
#5
(Aug 06, 2023, 07:18 PM)hooneyman Wrote: Some hints for root?

check the ssl certificates
[Image: 1PTq7EN.png]
#6
(Aug 06, 2023, 07:25 PM)DataNinja Wrote:
(Aug 06, 2023, 07:18 PM)hooneyman Wrote: Some hints for root?

check the ssl certificates
[Image: 1PTq7EN.png]

Hey any nudge for the user flag?
#7
(Aug 06, 2023, 08:11 PM)ByteBuster Wrote:
(Aug 06, 2023, 07:25 PM)DataNinja Wrote:
(Aug 06, 2023, 07:18 PM)hooneyman Wrote: Some hints for root?

check the ssl certificates
[Image: 1PTq7EN.png]


How, only editing the postgresql.conf file and pg_reload_conf(); ?

when you connect to the postgres server if you check the privileges you have the pg_write_server_files role and can copy files as postgres and for example you can copy the /bin/bash file and give it suid permissions and be able to access as postgres user
check this
https://book.hacktricks.xyz/network-serv...le-writing
#8
update on root from postgres?
#9
(Aug 07, 2023, 05:22 PM)0001 Wrote:
(Aug 06, 2023, 05:33 PM)cutty Wrote: You want to use this: https://github.com/DigitalInterruption/cookie-monster

hey man how did you manage to download cookie monster it is not being installed on my end

try using node v8.17, it runs fine with that
#10
(Aug 07, 2023, 05:22 PM)0001 Wrote:
(Aug 06, 2023, 05:33 PM)cutty Wrote: You want to use this: https://github.com/DigitalInterruption/cookie-monster

hey man how did you manage to download cookie monster it is not being installed on my end

open `/cookie-monster/bin/` and run in terminal ./cookie-monster.js


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 602 92,016 Yesterday, 06:48 PM
Last Post: sabero_exe
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,998 Yesterday, 09:54 AM
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 93,053 Yesterday, 08:48 AM
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,642 Yesterday, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,292 Apr 30, 2026, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)