HTB Sightless - Quick Sumary
by macavitysworld - Sunday September 8, 2024 at 05:56 AM
#1
  • sqlpad template injection to rce to get access on docker
  • Crack hash for user found in shadow file
  • Get user flag
  • admin.sightless.htb running on 8080
  • Portforward to access the vhost
  • Intended (xss to get credentials)
  • (Unintended) use metasploit chrome debugger to read /home/John/automation/administration.py for credentials
  • (Again unintended) Portforward all the larger ports, chrome debugging and check the network, if session is preserved you'll get the credentials
  • For root; reset ftp creds, login and find database.kbd, crack the password and find ssh keys
  • Or you can use php-fpm to read root.text or to get shell
Thanks @paw for the rank!!
Reply
#2
thanks mate, great help

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#3
(Sep 08, 2024, 05:56 AM)macavitysworld Wrote:
  • sqlpad template injection to rce to get access on docker
  • Crack hash for user found in shadow file
  • Get user flag
  • admin.sightless.htb running on 8080
  • Portforward to access the vhost
  • Intended (xss to get credentials)
  • (Unintended) use metasploit chrome debugger to read /home/John/automation/administration.py for credentials
  • (Again unintended) Portforward all the larger ports, chrome debugging and check the network, if session is preserved you'll get the credentials
  • For root; reset ftp creds, login and find database.kbd, crack the password and find ssh keys
  • Or you can use php-fpm to read root.text or to get shell

For the mestasploit debugger, i get an error 404 not found, even tought froxlor is accessible with broswer on port 4445; for the xss, i guess its the one who require admin browsing in a specific place, but it seem to never happens. Could you help me?
Reply
#4
(Sep 08, 2024, 05:56 AM)macavitysworld Wrote:
  • sqlpad template injection to rce to get access on docker
  • Crack hash for user found in shadow file
  • Get user flag
  • admin.sightless.htb running on 8080
  • Portforward to access the vhost
  • Intended (xss to get credentials)
  • (Unintended) use metasploit chrome debugger to read /home/John/automation/administration.py for credentials
  • (Again unintended) Portforward all the larger ports, chrome debugging and check the network, if session is preserved you'll get the credentials
  • For root; reset ftp creds, login and find database.kbd, crack the password and find ssh keys
  • Or you can use php-fpm to read root.text or to get shell

Thanks for the tips, very usefull !!
Reply
#5
Great tips. Hash was hard to format. Any examples on hashcat or john?

(Sep 09, 2024, 04:20 AM)Detector6 Wrote: Great tips. Hash was hard to format. Any examples on hashcat or john?

hashcat -m1800 -a 0 shadow /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt
Reply
#6
(Sep 08, 2024, 05:56 AM)macavitysworld Wrote:
  • sqlpad template injection to rce to get access on docker
  • Crack hash for user found in shadow file
  • Get user flag
  • admin.sightless.htb running on 8080
  • Portforward to access the vhost
  • Intended (xss to get credentials)
  • (Unintended) use metasploit chrome debugger to read /home/John/automation/administration.py for credentials
  • (Again unintended) Portforward all the larger ports, chrome debugging and check the network, if session is preserved you'll get the credentials
  • For root; reset ftp creds, login and find database.kbd, crack the password and find ssh keys
  • Or you can use php-fpm to read root.text or to get shell
hi there im new to HTB and im learning still just a quick question how do i find admin.sightless.htb that is running on 8080 i tried fuzz/gobuster etc but i seem to not find admin and how do i discover that there is something running on port 8080 if someone could be give me tips of finding them thank you.



NVM: i went ugaa bungaa i forgot what i can do with those
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,167 1 hour ago
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,491 Yesterday, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 396 Yesterday, 10:36 PM
Last Post: op334
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 369 92,002 Yesterday, 04:10 PM
Last Post: sabbyahmed
  CBBH Write Ups hiddenhacker 22 6,226 Yesterday, 06:39 AM
Last Post: Usercomplex

Forum Jump:


 Users browsing this forum: 1 Guest(s)