[HTB] Lantern
by RedTeamer - Saturday August 17, 2024 at 10:14 AM
#71
Guys anyone read cronjobs ? To know where to add that dll

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply
#72
(Aug 18, 2024, 01:33 AM)ir0nman4l1f3 Wrote:
(Aug 18, 2024, 01:27 AM)drunkp Wrote: Have you guys managed to build a dll with rev shell?

Used multiple tools to dissassemble and try to build but nothing worked.

What tools have you used?

(Aug 18, 2024, 01:24 AM)ir0nman4l1f3 Wrote: Has anyone tried to upload a pdf using msf and exploit/windows/fileformat/adobe_pdf_embedded_exe?

If tomas has login to the port on 3000, then it is likely that HTB has an automated "click" action for uploaded resumes?

It is not windows thoug

just an example - you can also update the payload to use a linux version as well for that one.

How can you set payload for linux in adobe_pdf_embedded_exe ? tried to 'set payload' for meterpreter and tcp but says incompatible. Also used the non js option same result.
Reply
#73
(Aug 18, 2024, 01:37 AM)osamy7593 Wrote: Guys anyone read cronjobs ? To know where to add that dll

u already can upload dll?
seems we need upload to /opt/components
and execute from lantern.htb:3000
Reply
#74
(Aug 18, 2024, 02:19 AM)olkn00b Wrote:
(Aug 18, 2024, 01:33 AM)ir0nman4l1f3 Wrote:
(Aug 18, 2024, 01:27 AM)drunkp Wrote: Have you guys managed to build a dll with rev shell?

Used multiple tools to dissassemble and try to build but nothing worked.

What tools have you used?

(Aug 18, 2024, 01:24 AM)ir0nman4l1f3 Wrote: Has anyone tried to upload a pdf using msf and exploit/windows/fileformat/adobe_pdf_embedded_exe?

If tomas has login to the port on 3000, then it is likely that HTB has an automated "click" action for uploaded resumes?

It is not windows thoug

just an example - you can also update the payload to use a linux version as well for that one.

How can you set payload for linux in adobe_pdf_embedded_exe ? tried to 'set payload' for meterpreter and tcp but says incompatible. Also used the non js option same result.

Yea I looked into this further afterwards and linux isn't suppored... based on the rapid7 post, it made it seem like other platforms were supported...
Reply
#75
GET /PrivacyAndPolicy?lang=../../../../../../&ext=./var/mail/tomas HTTP/1.1
Host: lantern.htb
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: http://lantern.htb/
DNT: 1
Connection: close
Upgrade-Insecure-Requests: 1
Sec-GPC: 1

From hr@lantern.htb Mon Jan 1 12:00:00 2023
Subject: Welcome to Lantern!

Hi Tomas,

Congratulations on joining the Lantern team as a Linux Engineer! We're thrilled to have you on board.

While we're setting up your new account, feel free to use the access and toolset of our previous team member. Soon, you'll have all the access you need.

Our admin is currently automating processes on the server. Before global testing, could you check out his work in /root/automation.sh? Your insights will be valuable.

Exciting times ahead!

Best.
Reply
#76
were are we puttting this dill file

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#77
(Aug 18, 2024, 04:05 AM)hackemall Wrote: were are we puttting this dill file

I believe we are uploading it inside the admin panel but how can we get it to execute at /var/www/sites/lantern.htb/static/images ? Must be an LFI mentioned earlier but I haven't found it.
Reply
#78
i have done that but is stuck there

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#79
(Aug 18, 2024, 04:44 AM)hackemall Wrote: i have done that but is stuck there

Did you got the shell ?
Reply
#80
i tried to load test.dll generated from msfvenom to /opt/components it worked but as i try to run it i get Bad IL Format
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 602 92,020 Yesterday, 06:48 PM
Last Post: sabero_exe
  [FREE] CPTS 12 FLAGS pulsebreaker 68 2,001 Yesterday, 09:54 AM
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 93,055 Yesterday, 08:48 AM
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,643 Yesterday, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,292 Apr 30, 2026, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)