Hack The Box - Heal
by rebelhex2 - Saturday December 14, 2024 at 07:19 PM
#1
Happy Hacking! 
Let's discuss this new Medium Linux box!
**HTB Heal**
Good Luck !!!!
Reply
#2
subs

api.heal.htb
take-survey.heal.htb

"Please contact Administrator ( ralph@heal.htb ) for further assistance."
Reply
#3
LFI at the export pdf function.
GET /download?filename=/../../
ruby 3.3.5 + Rails 7.1.4
Reply
#4
GET /download?filename=../../config/database.yml
GET /download?filename=../../storage/development.sqlite3

Crackable hash for ralph. Only works for heal.htb though and not for limesurvey or ssh.
Reply
#5
How long did you crack? mode is 28400 right?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#6
(Dec 14, 2024, 08:20 PM)nomx1337 Wrote: How long did you crack? mode is 28400 right?

3200

hashcat --identify
Reply
#7
Once logged in, use the LimeSurvey RCE malicious plugin, grab RCE, look further, dig more, find the postgresql connection string which contains a password, use that for user.
Reply
#8
The sql database shows

ralph | 147258369

http://heal.htb/profile shows he is the Administrator

============

He can log into here also:

http://take-survey.heal.htb/index.php/admin/index
Reply
#9
Yes, that's where you upload the malicious plugin to get RCE. Once there, look further and user is just a step away.

Privesc is not too shabby, quite easy after all, just look what else is running. What service. Access it then exploit it to gain shell thru it.
Reply
#10
(Dec 14, 2024, 09:10 PM)peRd1 Wrote: Yes, that's where you upload the malicious plugin to get RCE. Once there, look further and user is just a step away.

Privesc is not too shabby, quite easy after all, just look what else is running. What service. Access it then exploit it to gain shell thru it.

Thanks for the hints.
Stupidly only tried admin at first on limesurvey, doh.

For root have a look at port 8500. Quite straight-forward.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,182 2 hours ago
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,495 Yesterday, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 398 Yesterday, 10:36 PM
Last Post: op334
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 369 92,013 Yesterday, 04:10 PM
Last Post: sabbyahmed
  CBBH Write Ups hiddenhacker 22 6,229 Yesterday, 06:39 AM
Last Post: Usercomplex

Forum Jump:


 Users browsing this forum: 1 Guest(s)