HTB GreenHorn
by Unbutton8074 - Saturday July 20, 2024 at 07:50 PM
#21
(Jul 20, 2024, 10:27 PM)Tsirko Wrote: I cracked the password and i cant login with it on the login page with username as admin, I even tried the email I have found. Can someone help?

http://greenhorn.htb/login.php
Reply
#22
(Jul 20, 2024, 10:22 PM)spamdegratis5 Wrote: root password hint: remove the spaces Smile

(Jul 20, 2024, 10:14 PM)wtfduw Wrote:
(Jul 20, 2024, 10:11 PM)zivziv Wrote: is the password the full long one for root? it doesnt work (unblurred)

What image of depix did you use to get it to unblurr? And did you take a screenshot on the whole pdf or only the password section?

you can obtain the image just by dragging the password image to the terminal, it should write the actual path to the page, something like this
/tmp/atril-1203593/image.78KDR2.png

did that
I did get a readable long string, it just doesnt work
Reply
#23
(Jul 20, 2024, 10:32 PM)creeman Wrote: After executing 51592.py its telling file not found what is the error what we have to edit in 51592.py help me!!!

You need to modify the exploit with the correct password and url's.
Reply
#24
(Jul 20, 2024, 10:36 PM)ThreeCleaves Wrote:
(Jul 20, 2024, 10:32 PM)creeman Wrote: After executing 51592.py its telling file not found what is the error what we have to edit in 51592.py help me!!!

You need to modify the exploit with the correct password and url's.

Can you give the modified urls, i cant understand
Reply
#25
(Jul 20, 2024, 10:44 PM)creeman Wrote:
(Jul 20, 2024, 10:36 PM)ThreeCleaves Wrote:
(Jul 20, 2024, 10:32 PM)creeman Wrote: After executing 51592.py its telling file not found what is the error what we have to edit in 51592.py help me!!!

You need to modify the exploit with the correct password and url's.

Can you give the modified urls, i cant understand

login_url = "http://greenhorn.htb/login.php"
upload_url = "http://greenhorn.htb/admin.php?action=installmodule"
rce_url="http://greenhorn.htb/data/modules/mirabbas/miri.php"
Reply
#26
Can anyone tell me the root pasword??
Reply
#27
I get

Login account
ZIP file download.
Not found. 

When i run the exploit. And yes I change the rce_url="http://greenhorn.htb/data/modules/mirabbas/miri.php"
mirabbas = name of zip
miri.php = name of file
Reply
#28
(Jul 20, 2024, 11:02 PM)creeman Wrote: Can anyone tell me the root pasword??

If your having issues with Depix, try extracting the image with pdfimage from poppler-utils.

I was having an issue with my source image. Once I extracted it with pdfimage i was able to unblur the image.
Reply
#29
(Jul 20, 2024, 11:06 PM)ThreeCleaves Wrote:
(Jul 20, 2024, 11:02 PM)creeman Wrote: Can anyone tell me the root pasword??

If your having issues with Depix, try extracting the image with pdfimage from poppler-utils.

I was having an issue with my source image. Once I extracted it with pdfimage i was able to unblur the image.

This way it worked for me. Thank you. I just hated the last part of this machine
Reply
#30
(Jul 20, 2024, 11:16 PM)fuckhackthebox Wrote: if there are spaces in your root password remove them

May i ask when i run the exploit i get 
Login account
ZIP file download.
Not found.

My zip file correcly named gets upladed but it cant find the file in the modules to run the reverse shell...
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 4 473 2 hours ago
Last Post: Reminiscing
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 602 92,111 Yesterday, 06:48 PM
Last Post: sabero_exe
  [FREE] CPTS 12 FLAGS pulsebreaker 68 2,012 Yesterday, 09:54 AM
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 93,068 Yesterday, 08:48 AM
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,647 Yesterday, 05:08 AM
Last Post: popoler

Forum Jump:


 Users browsing this forum: 1 Guest(s)