[HTB] Sea - Machine
by RedTeamer - Friday August 9, 2024 at 08:04 PM
#91
people saying it has smth to do with wondercms and they are referencing xss to rce, but idk how they got to that conclusion other than the img. help plz
Reply
#92
for root access, intercept the request to port 8080, and where you call the acces.log file, use command injection (;nc ....) and call your reverse-shell, thank you, you're welcome, now give reputation
Reply
#93
root log analyzer's source code: /root/monitoring/index.php

Hidden Content
You must register or login to view this content.
Reply
#94
Escape
;your_command;id
Reply
#95
a shit box i ever seen in my life

there is simple trick to get user

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Selling in HTB | Trying to sell information posted for free
Reply
#96
(Aug 10, 2024, 11:21 PM)mhsoraa Wrote: Any hits for command injection on root...

amay@sea:~$ curl http://127.0.0.1:8080

Unauthorized accessa
may@sea:~$

It's because it require credentials, portforward to access it
Reply
#97
(Aug 10, 2024, 11:38 PM)upl04d3r Wrote:
(Aug 10, 2024, 11:35 PM)elburro Wrote: any hints on foothold i found a page /contact.php  it does call back my machine but i can't  think of any thing to do with it

machine is slow, callback comes after some time and then repeats

I still can't find a usable command injection Undecided
"No suspicious traffic patterns detected in /root/flag.txt"

Finaly im root. Interesting box Smile

how you bypass the filter?
Reply
#98
(Aug 10, 2024, 09:32 PM)l3rka Wrote: login page
http://sea.htb/index.php?page=loginURL

bro how you find WonderCMS lol please tell
Reply
#99
For those asking me in DM for hints, i've got a 403 when i want to send an answer Confused. So I will answer here

Basically, for port forwarding you can check this : https://www.ssh.com/academy/ssh/tunnelin...forwarding

For OS injection, check for previous post, there is a lot of hints about it.

P.S : anybody knows how to solve my 403 problem with my DM ?
Reply
(Aug 11, 2024, 04:24 AM)fuckhackthebox Wrote: lol cheatlesian and niggerlte at it again

user: get some cuck htb employee to leak writeups to you so you know themes/revshell-main/rev.php exists by default (go check im not bullshitting)

root: basic command injection in the service on localhost:8080 (use an ssh forward)

LOL man. It's always funny to read your posts. Big Grin 

and yeah.. this is what it means to have "appropriate friends"  Diogo

(Aug 11, 2024, 05:39 AM)DeDeLaPouille Wrote: For those asking me in DM for hints, i've got a 403 when i want to send an answer Confused. So I will answer here

Basically, for port forwarding you can check this : https://www.ssh.com/academy/ssh/tunnelin...forwarding

For OS injection, check for previous post, there is a lot of hints about it.

P.S : anybody knows how to solve my 403 problem with my DM ?

blacklist in DMs aren't allowing certain stuff like when you're trying 'php injections' (or what black filter thinks it is) or javascript and such.
you can put your code into pasterbin or related services instead and send a link toy it.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 66 1,790 6 hours ago
Last Post: vlka
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 370 92,595 11 hours ago
Last Post: lifolifo007
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,218 Yesterday, 02:10 PM
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,526 Apr 29, 2026, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 416 Apr 29, 2026, 10:36 PM
Last Post: op334

Forum Jump:


 Users browsing this forum: 1 Guest(s)