HTB Eloquia User and Root Flags - Insane Box
by 69646B - Friday January 30, 2026 at 05:48 PM
#1
tldr:  
Hidden Content
You must register or login to view this content.



Attack Path:
Review Website
Register an account on the site
Register an account using the qooqle oath
Create malicious article with html injection to force admin to register new oauth token for you
Report article to admin so trigger CSRF
Change oauth registration, use callback code in CSRF
Get Admin session


create malicious dll to get rev shell
upload to a banner as admin (we can do this now since the checks are bypassed as admin)
start listener
Go to eloquia.htb/dev/sql-explorer
Load the dll using the following
SELECT load_extension('statis/assets/images.blog/malicious.dll');
get user shell
type user.txt
Hidden Content
You must register or login to view this content.

Creds are stored in browser
Copy local_state.json and login_data.json
Crack password
Olivia.KAT:S3cureP@sswdIGu3ss
Login with evil winrm


Failure2ban service is vulnerable to being overwritten.
Overwrite with simple exe to move flag to readable directory or make a new rev shell.

Hidden Content
You must register or login to view this content.
Reply
#2
thank u sm man its good

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply
#3
thank you for sharing

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply
#4
(Jan 30, 2026, 05:48 PM)69646B Wrote: tldr:  

Great thanks mate
thats much work
would you mind publishing any tutorial on this

PS: damn I am late to the party

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply
#5
thanks for the content bro
Reply
#6
thanks for this lil bro!

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply
#7
(Jan 30, 2026, 05:48 PM)69646B Wrote: tldr:  

Thank you so much for the writeup!! <3

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply
#8
(Jan 30, 2026, 05:48 PM)69646B Wrote: tldr:  


This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply
#9
(Jan 30, 2026, 05:48 PM)69646B Wrote: tldr:  

thankyou so much

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply
#10
thanks you mate, I will check it out

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 369 91,656 3 hours ago
Last Post: sabbyahmed
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 2 338 11 hours ago
Last Post: hibreackignos
  CBBH Write Ups hiddenhacker 22 6,205 Today, 06:39 AM
Last Post: Usercomplex
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 86 7,787 Yesterday, 11:39 PM
Last Post: my4ri0d0
  rev_dudidudida cavour13 1 246 Yesterday, 12:25 AM
Last Post: 0xcreep

Forum Jump:


 Users browsing this forum: 1 Guest(s)