Mar 29, 2025, 09:17 AM
Let's solve together
|
HTB - Dusty Alleys
by x1rx - Saturday March 29, 2025 at 09:17 AM
|
|
Mar 29, 2025, 09:17 AM
Let's solve together
Mar 30, 2025, 02:32 AM
Mar 30, 2025, 10:07 AM
1 - nginx http1.0 information leak
2 - ssrf
Mar 30, 2025, 12:08 PM
What is the parameter to use?
Mar 30, 2025, 01:49 PM
#get vhost by downgrade to http1.0(Mar 30, 2025, 01:49 PM)ent0xE Wrote: i dont understand the downgrading to expose the vhost, can you explain ? (Mar 30, 2025, 03:28 PM)pop10189 Wrote:(Mar 30, 2025, 01:49 PM)ent0xE Wrote: Ohh nvm, now i understand In HTTP/1.0, the Host header is optional. If the client does not send it, Nginx does not know which vhost to serve and will default to the first defined server block, which is: server_name alley.$SECRET_ALLEY |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
|
|
[FREE] HackTheBox All Cheatsheets | 10 | 581 |
33 minutes ago Last Post: chufoni |
|
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 28 | 2,820 |
35 minutes ago Last Post: chufoni |
||
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 375 | 93,492 |
46 minutes ago Last Post: Johe |
||
| [FREE] HackTheBox Dante - complete writeup written by Tamarisk | 604 | 92,596 |
47 minutes ago Last Post: Johe |
||
| [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot | 87 | 7,987 |
2 hours ago Last Post: char0n1507 |
||