HTB University CTF 2024
by VladTrun98 - Friday December 13, 2024 at 05:33 PM
#1
discussion, i start with freedom

echo "e.tylar" > a.txt && GetNPUsers.py -request -format hashcat -outputfile asrep.roast -dc-ip '<ip>' -usersfile 'a.txt' 'freedom.htb/'
Reply
#2
An1 any hint on baking bad ?

DM me on disc (malw_guy) if u wanna talk

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#3
(Dec 13, 2024, 05:33 PM)VladTrun98 Wrote: discussion, i start with freedom

echo "e.tylar" > a.txt && GetNPUsers.py -request -format hashcat -outputfile asrep.roast -dc-ip '<ip>' -usersfile 'a.txt' 'freedom.htb/'

Hey how you can ge e.tylar from that ?

(Dec 13, 2024, 05:33 PM)VladTrun98 Wrote: discussion, i start with freedom

echo "e.tylar" > a.txt && GetNPUsers.py -request -format hashcat -outputfile asrep.roast -dc-ip '<ip>' -usersfile 'a.txt' 'freedom.htb/'

And also how you can get SQL injection from /admin/ ?
Reply
#4
Any hint on Wanted Alive challenge in Forensic category??
Reply
#5
I'm stuck on web_breaking_bad.
Basically, I need to somehow get access to the account financial-controller@frontier-board[.]htb, but nothing is working. I also can't forge JWT signatures... I even wrote a script for OTP to transfer money, but still no success.
Reply
#6
(Dec 14, 2024, 01:57 PM)Surfacing2325 Wrote: I'm stuck on web_breaking_bad.
Basically, I need to somehow get access to the account financial-controller@frontier-board[.]htb, but nothing is working. I also can't forge JWT signatures... I even wrote a script for OTP to transfer money, but still no success.

I am stuck on this too. There is a py script that they provided that you need to complete and it gets the flag instantly but there are many things you need to complete
Reply
#7
for breaking bank, look for JWKS Spoofing

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#8
(Dec 14, 2024, 02:41 PM)malwguy Wrote: for breaking bank, look for JWKS Spoofing

Add me on Discord pls

(Dec 14, 2024, 02:41 PM)malwguy Wrote: for breaking bank, look for JWKS Spoofing

I had an idea to do it like this:
"jku": "http://127.0.0.1:1337/api/analytics/redirect?url=.well-known/jwks.json&ref=test"

(Dec 14, 2024, 02:42 PM)Surfacing2325 Wrote:
(Dec 14, 2024, 02:41 PM)malwguy Wrote: for breaking bank, look for JWKS Spoofing

Add me on Discord pls

(Dec 14, 2024, 02:41 PM)malwguy Wrote: for breaking bank, look for JWKS Spoofing

I had an idea to do it like this:
"jku": "http://127.0.0.1:1337/api/analytics/redirect?url=.well-known/jwks.json&ref=test"
I already tested the above to see if it would work, and as a result, I got the following request:
but i got
HTTP/1.1 401 Unauthorized
Server: nginx
Date: Sat, 14 Dec 2024 14:52:12 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 29
Connection: keep-alive

{"error":"Invalid Signature"}
Reply
#9
(Dec 13, 2024, 05:33 PM)VladTrun98 Wrote: discussion, i start with freedom

echo "e.tylar" > a.txt && GetNPUsers.py -request -format hashcat -outputfile asrep.roast -dc-ip '<ip>' -usersfile 'a.txt' 'freedom.htb/'

Can't crack the hash with rockyou.txt. Got any other method?. I tried with hashcat
Reply
#10
(Dec 13, 2024, 05:33 PM)VladTrun98 Wrote: discussion, i start with freedom

echo "e.tylar" > a.txt && GetNPUsers.py -request -format hashcat -outputfile asrep.roast -dc-ip '<ip>' -usersfile 'a.txt' 'freedom.htb/'

How did you get to this point, i mean i got the sql injection but the passwords are litteraly uncrackble, same goes for the hash you've sent(kerb)?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 71 2,158 22 minutes ago
Last Post: codexUltron
  [FREE] HackTheBox Academy - CAPE Path Study Techtom 43 4,213 40 minutes ago
Last Post: codexUltron
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 24 2,739 43 minutes ago
Last Post: codexUltron
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 603 92,361 7 hours ago
Last Post: 0xnany
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 374 93,325 7 hours ago
Last Post: 0xnany

Forum Jump:


 Users browsing this forum: 1 Guest(s)