Aug 17, 2024, 10:35 PM
|
[HTB] Lantern
by RedTeamer - Saturday August 17, 2024 at 10:14 AM
|
|
Aug 17, 2024, 10:37 PM
Aug 17, 2024, 10:38 PM
Aug 17, 2024, 10:42 PM
Identified a path
/home/tomas/LanternAdmin/bin/Debug/net6.0/LanternAdmin.dllI tried to download it through the aforementioned path traversal or loading that module via the admin panel, but neither worked for me
Aug 17, 2024, 10:46 PM
i'm trying to read FileUpload.dll - maybe there is a way to upload file not to static/images
(Aug 17, 2024, 10:42 PM)carbonzillioxide Wrote: Identified a path from path traversal it can't be done because www-data doesn't have rights to /home/tomas
Aug 17, 2024, 11:01 PM
(Aug 17, 2024, 10:48 PM)jsvensson Wrote: i'm trying to read FileUpload.dll - maybe there is a way to upload file not to static/images Datadb is probably with the binary. But then, that server is run by tomas, so www-data shouldnt have access to data.db either way.
Aug 17, 2024, 11:04 PM
use path traversal for shell..
This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Aug 17, 2024, 11:05 PM
Aug 17, 2024, 11:05 PM
can we have sqli so then we can run shell command using sqlite's .shell utility
|
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
|
|
[FREE] HackTheBox All Cheatsheets | 15 | 827 |
3 hours ago Last Post: 0x5k1z0 |
|
| CPTS-FLAG | 14 | 5,733 |
4 hours ago Last Post: Sukon |
||
| [FREE] CPTS 12 FLAGS | 78 | 2,615 |
4 hours ago Last Post: hitlerssecretsidechick |
||
| [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot | 91 | 8,295 |
4 hours ago Last Post: hitlerssecretsidechick |
||
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 381 | 94,565 |
7 hours ago Last Post: xixi75 |
||