Aug 10, 2024, 11:21 PM
not able to decode the hash in bcrypt anyone help p[lz
|
[HTB] Sea - Machine
by RedTeamer - Friday August 9, 2024 at 08:04 PM
|
|
Aug 10, 2024, 11:21 PM
not able to decode the hash in bcrypt anyone help p[lz
Aug 10, 2024, 11:21 PM
Any hits for command injection on root...
amay@sea:~$ curl http://127.0.0.1:8080(Aug 10, 2024, 11:21 PM)mhsoraa Wrote: Any hits for command injection on root... use port forwarding to show website on localhost (Aug 10, 2024, 11:21 PM)testerlion Wrote: not able to decode the hash in bcrypt anyone help p[lz find escape character
Aug 10, 2024, 11:27 PM
(This post was last modified: Aug 10, 2024, 11:31 PM by 7h31nqu1s171v3.)
FOR ROOT:
on local machine forward the port 8080 by using: then use burpsuit to intercept the request when analyzing log files.. u can inject code in the log_file param by using for example: harmless example to avoid spoiling others experience!! ENJOY
Aug 10, 2024, 11:27 PM
(Aug 10, 2024, 10:46 PM)kewlcat002 Wrote: Machine rooted feel free to DM me if need be (Aug 10, 2024, 10:56 PM)Witcher09 Wrote:(Aug 10, 2024, 10:45 PM)OffensiveBias Wrote:(Aug 10, 2024, 10:41 PM)Witcher09 Wrote:(Aug 10, 2024, 10:26 PM)Witcher09 Wrote: It is showing send the below link to admin, from wheresome one help me Can you tell me what to do actually I found the daily cron but not able to get what to do
Aug 10, 2024, 11:30 PM
(Aug 10, 2024, 11:27 PM)Witcher09 Wrote:(Aug 10, 2024, 10:46 PM)kewlcat002 Wrote: Machine rooted feel free to DM me if need be Plenty of hints regarding the entire machine in the thread, just start from page 1
Aug 10, 2024, 11:35 PM
any hints on foothold i found a page /contact.php it does call back my machine but i can't think of any thing to do with it
Aug 10, 2024, 11:38 PM
(This post was last modified: Aug 10, 2024, 11:38 PM by OffensiveBias.)
(Aug 10, 2024, 11:27 PM)Witcher09 Wrote:(Aug 10, 2024, 10:46 PM)kewlcat002 Wrote: Machine rooted feel free to DM me if need be Search for or ask chatgpt about command injection using curl and http://localhost:8080 is your way forward. Test for payloads to escape . Eventually you will find it. (Aug 10, 2024, 11:35 PM)elburro Wrote: any hints on foothold i found a page /contact.php it does call back my machine but i can't think of any thing to do with it machine is slow, callback comes after some time and then repeats I still can't find a usable command injection "No suspicious traffic patterns detected in /root/flag.txt" Finaly im root. Interesting box
|
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 23 | 2,170 |
1 hour ago Last Post: kkkato |
||
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 20 | 2,491 |
Yesterday, 11:06 PM Last Post: op334 |
||
|
|
[FREE] HackTheBox All Cheatsheets | 3 | 396 |
Yesterday, 10:36 PM Last Post: op334 |
|
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 369 | 92,003 |
Yesterday, 04:10 PM Last Post: sabbyahmed |
||
| CBBH Write Ups | 22 | 6,226 |
Yesterday, 06:39 AM Last Post: Usercomplex |
||