Aug 17, 2024, 10:35 PM
|
[HTB] Lantern
by RedTeamer - Saturday August 17, 2024 at 10:14 AM
|
|
Aug 17, 2024, 10:37 PM
Aug 17, 2024, 10:38 PM
Aug 17, 2024, 10:42 PM
Identified a path
/home/tomas/LanternAdmin/bin/Debug/net6.0/LanternAdmin.dllI tried to download it through the aforementioned path traversal or loading that module via the admin panel, but neither worked for me
Aug 17, 2024, 10:46 PM
i'm trying to read FileUpload.dll - maybe there is a way to upload file not to static/images
(Aug 17, 2024, 10:42 PM)carbonzillioxide Wrote: Identified a path from path traversal it can't be done because www-data doesn't have rights to /home/tomas
Aug 17, 2024, 11:01 PM
(Aug 17, 2024, 10:48 PM)jsvensson Wrote: i'm trying to read FileUpload.dll - maybe there is a way to upload file not to static/images Datadb is probably with the binary. But then, that server is run by tomas, so www-data shouldnt have access to data.db either way.
Aug 17, 2024, 11:04 PM
use path traversal for shell..
This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Aug 17, 2024, 11:05 PM
Aug 17, 2024, 11:05 PM
can we have sqli so then we can run shell command using sqlite's .shell utility
|
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| SVCHOST Injector 2026 | 0 | 39 |
2 hours ago Last Post: opsecmaster67 |
||
| Cold Seal 5.6 cracked Sensitive information can be exposed or stolen | 0 | 42 |
3 hours ago Last Post: opsecmaster67 |
||
| EagleRAT v2.5 Create backdoor access points | 0 | 41 |
3 hours ago Last Post: opsecmaster67 |
||
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 43 | 3,466 |
3 hours ago Last Post: qwertyuiop0987654321 |
||
| CBBH Write Ups | 27 | 6,731 |
3 hours ago Last Post: qwertyuiop0987654321 |
||