HTB University CTF 2024
by VladTrun98 - Friday December 13, 2024 at 05:33 PM
#1
discussion, i start with freedom

echo "e.tylar" > a.txt && GetNPUsers.py -request -format hashcat -outputfile asrep.roast -dc-ip '<ip>' -usersfile 'a.txt' 'freedom.htb/'
Reply
#2
An1 any hint on baking bad ?

DM me on disc (malw_guy) if u wanna talk

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#3
(Dec 13, 2024, 05:33 PM)VladTrun98 Wrote: discussion, i start with freedom

echo "e.tylar" > a.txt && GetNPUsers.py -request -format hashcat -outputfile asrep.roast -dc-ip '<ip>' -usersfile 'a.txt' 'freedom.htb/'

Hey how you can ge e.tylar from that ?

(Dec 13, 2024, 05:33 PM)VladTrun98 Wrote: discussion, i start with freedom

echo "e.tylar" > a.txt && GetNPUsers.py -request -format hashcat -outputfile asrep.roast -dc-ip '<ip>' -usersfile 'a.txt' 'freedom.htb/'

And also how you can get SQL injection from /admin/ ?
Reply
#4
Any hint on Wanted Alive challenge in Forensic category??
Reply
#5
I'm stuck on web_breaking_bad.
Basically, I need to somehow get access to the account financial-controller@frontier-board[.]htb, but nothing is working. I also can't forge JWT signatures... I even wrote a script for OTP to transfer money, but still no success.
Reply
#6
(Dec 14, 2024, 01:57 PM)Surfacing2325 Wrote: I'm stuck on web_breaking_bad.
Basically, I need to somehow get access to the account financial-controller@frontier-board[.]htb, but nothing is working. I also can't forge JWT signatures... I even wrote a script for OTP to transfer money, but still no success.

I am stuck on this too. There is a py script that they provided that you need to complete and it gets the flag instantly but there are many things you need to complete
Reply
#7
for breaking bank, look for JWKS Spoofing

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#8
(Dec 14, 2024, 02:41 PM)malwguy Wrote: for breaking bank, look for JWKS Spoofing

Add me on Discord pls

(Dec 14, 2024, 02:41 PM)malwguy Wrote: for breaking bank, look for JWKS Spoofing

I had an idea to do it like this:
"jku": "http://127.0.0.1:1337/api/analytics/redirect?url=.well-known/jwks.json&ref=test"

(Dec 14, 2024, 02:42 PM)Surfacing2325 Wrote:
(Dec 14, 2024, 02:41 PM)malwguy Wrote: for breaking bank, look for JWKS Spoofing

Add me on Discord pls

(Dec 14, 2024, 02:41 PM)malwguy Wrote: for breaking bank, look for JWKS Spoofing

I had an idea to do it like this:
"jku": "http://127.0.0.1:1337/api/analytics/redirect?url=.well-known/jwks.json&ref=test"
I already tested the above to see if it would work, and as a result, I got the following request:
but i got
HTTP/1.1 401 Unauthorized
Server: nginx
Date: Sat, 14 Dec 2024 14:52:12 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 29
Connection: keep-alive

{"error":"Invalid Signature"}
Reply
#9
(Dec 13, 2024, 05:33 PM)VladTrun98 Wrote: discussion, i start with freedom

echo "e.tylar" > a.txt && GetNPUsers.py -request -format hashcat -outputfile asrep.roast -dc-ip '<ip>' -usersfile 'a.txt' 'freedom.htb/'

Can't crack the hash with rockyou.txt. Got any other method?. I tried with hashcat
Reply
#10
(Dec 13, 2024, 05:33 PM)VladTrun98 Wrote: discussion, i start with freedom

echo "e.tylar" > a.txt && GetNPUsers.py -request -format hashcat -outputfile asrep.roast -dc-ip '<ip>' -usersfile 'a.txt' 'freedom.htb/'

How did you get to this point, i mean i got the sql injection but the passwords are litteraly uncrackble, same goes for the hash you've sent(kerb)?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  SVCHOST Injector 2026 opsecmaster67 0 42 3 hours ago
Last Post: opsecmaster67
  Cold Seal 5.6 cracked Sensitive information can be exposed or stolen opsecmaster67 0 44 3 hours ago
Last Post: opsecmaster67
  EagleRAT v2.5 Create backdoor access points opsecmaster67 0 41 3 hours ago
Last Post: opsecmaster67
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 43 3,466 4 hours ago
Last Post: qwertyuiop0987654321
  CBBH Write Ups hiddenhacker 27 6,733 4 hours ago
Last Post: qwertyuiop0987654321

Forum Jump:


 Users browsing this forum: 1 Guest(s)