HTB- Intuition
by trevor69000 - Saturday April 27, 2024 at 06:46 PM
#11
https://sensepost.com/blog/2023/dress-co.../#jsdelivr
We can bypass it
Reply
#12
Access to dashboard with stolen cookie from webdev adam.
Can't crack his hash, and don't see anything exploitable in the /report /delete /resolve /backup or /change_priority endpoints yet.
Anyone have anything?
Reply
#13
(Apr 27, 2024, 09:25 PM)xxxbfacc Wrote: Access to dashboard with stolen cookie from webdev adam.
Can't crack his hash, and don't see anything exploitable in the /report /delete /resolve /backup or /change_priority endpoints yet.
Anyone have anything?

how did you get that webdev adam cookie?
Reply
#14
What method to obtain cookie?
Reply
#15
(Apr 27, 2024, 09:30 PM)ox9Days Wrote:
(Apr 27, 2024, 09:25 PM)xxxbfacc Wrote: Access to dashboard with stolen cookie from webdev adam.
Can't crack his hash, and don't see anything exploitable in the /report /delete /resolve /backup or /change_priority endpoints yet.
Anyone have anything?

how did you get that webdev adam cookie?

Probably via a xss bypassing jsdelivr in report
Reply
#16
cookie from report_bugs via img tag xss
Reply
#17
plz bro what payload u used
(Apr 27, 2024, 09:38 PM)xxxbfacc Wrote: cookie from report_bugs via img tag xss


This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply
#18
did you do a http server type payload?
Reply
#19
what after xss .........................................

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply
#20
I'm also very curious what the approach is with the XSS here. I feel like I've tried every XSS payload under the sun at this point.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 602 92,008 Yesterday, 06:48 PM
Last Post: sabero_exe
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,995 Yesterday, 09:54 AM
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 93,051 Yesterday, 08:48 AM
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,641 Yesterday, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,289 Apr 30, 2026, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)