[HTB] Sea - Machine
by RedTeamer - Friday August 9, 2024 at 08:04 PM
#11
(Aug 10, 2024, 07:54 PM)AdenBilal Wrote: there is ssrf on the website parameter in contact.php. start python server in your machine and enter that IP in the website with idnf
http://10.10.16.51:1235/idnf

why idnf?////////////

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply
#12
(Aug 10, 2024, 07:58 PM)osamy7593 Wrote:
(Aug 10, 2024, 07:54 PM)AdenBilal Wrote: there is ssrf on the website parameter in contact.php. start python server in your machine and enter that IP in the website with idnf
http://10.10.16.51:1235/idnf

why idnf?////////////

That's just the file they're calling
Reply
#13
(Aug 10, 2024, 08:01 PM)vainyyyyyy Wrote:
(Aug 10, 2024, 07:58 PM)osamy7593 Wrote:
(Aug 10, 2024, 07:54 PM)AdenBilal Wrote: there is ssrf on the website parameter in contact.php. start python server in your machine and enter that IP in the website with idnf
http://10.10.16.51:1235/idnf

why idnf?////////////

That's just the file they're calling


sorry for the delay idnf is just an identifier.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#14
At this point we all know the website parameter in the post request is the way forward
Reply
#15
i am receiving hits back to my server multiple times which either means the website URL I enter is getting fetched multiple times or it is getting stored anywhere and it is auto-execute for that.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#16
(Aug 10, 2024, 08:21 PM)gihimlek Wrote:
(Aug 10, 2024, 08:19 PM)AdenBilal Wrote: i am receiving hits back to my server multiple times which either means the website URL I enter is getting fetched multiple times or it is getting stored anywhere and it is auto-execute for that.

Is getting stored

Trying brute forcing ssh with velik71 user, but without any expectation

how you found velik71 user

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#17
(Aug 10, 2024, 08:23 PM)AdenBilal Wrote:
(Aug 10, 2024, 08:21 PM)gihimlek Wrote:
(Aug 10, 2024, 08:19 PM)AdenBilal Wrote: i am receiving hits back to my server multiple times which either means the website URL I enter is getting fetched multiple times or it is getting stored anywhere and it is auto-execute for that.

Is getting stored

Trying brute forcing ssh with velik71 user, but without any expectation

how you found velik71 user

Home page
Reply
#18
(Aug 10, 2024, 08:25 PM)kewlcat002 Wrote:
(Aug 10, 2024, 08:23 PM)AdenBilal Wrote:
(Aug 10, 2024, 08:21 PM)gihimlek Wrote:
(Aug 10, 2024, 08:19 PM)AdenBilal Wrote: i am receiving hits back to my server multiple times which either means the website URL I enter is getting fetched multiple times or it is getting stored anywhere and it is auto-execute for that.

Is getting stored

Trying brute forcing ssh with velik71 user, but without any expectation

how you found velik71 user

Home page

yeah but ig that may or may not be ssh user.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#19
(Aug 10, 2024, 08:23 PM)AdenBilal Wrote:
(Aug 10, 2024, 08:21 PM)gihimlek Wrote:
(Aug 10, 2024, 08:19 PM)AdenBilal Wrote: i am receiving hits back to my server multiple times which either means the website URL I enter is getting fetched multiple times or it is getting stored anywhere and it is auto-execute for that.

Is getting stored

Trying brute forcing ssh with velik71 user, but without any expectation

how you found velik71 user

Dude it's in the banner of the webpage.
Reply
#20
apache server is apache/2.4.41

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 370 92,360 3 hours ago
Last Post: lifolifo007
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,199 6 hours ago
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,503 Yesterday, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 404 Yesterday, 10:36 PM
Last Post: op334
  CBBH Write Ups hiddenhacker 22 6,237 Yesterday, 06:39 AM
Last Post: Usercomplex

Forum Jump:


 Users browsing this forum: 1 Guest(s)