Monitored - HTB
by paven - Saturday January 13, 2024 at 12:13 PM
#21
I tried this with no luck.. what is your endpoint ?


(Jan 13, 2024, 09:25 PM)DataNinja Wrote: PING WORKS!
[Image: yeCEPsM.png]

ok got the ping also working with service icmp so we are allowed to use some cmd.cgi

curl snippet
--data-binary $'nagFormId=a30151f1&cmd_typ=3&cmd_mod=2&host=10.10.x.x&service=icmp&persistent=on&com_data=test&btnSubmit=Commit' \
$'https://nagios.monitored.htb/nagios/cgi-bin/cmd.cgi'
Reply
#22
Nagios core is running on https://nagios.monitored.htb/nagios/
And I'm able to log in with svc:XjH7VCehowpR1xZB but can't find anything useful
Reply
#23
(Jan 13, 2024, 09:32 PM)RebeLHeX Wrote: I tried this with no luck.. what is your endpoint ?


(Jan 13, 2024, 09:25 PM)DataNinja Wrote: PING WORKS!
[Image: yeCEPsM.png]

ok got the ping also working with service icmp so we are allowed to use some cmd.cgi

curl snippet
--data-binary $'nagFormId=a30151f1&cmd_typ=3&cmd_mod=2&host=10.10.x.x&service=icmp&persistent=on&com_data=test&btnSubmit=Commit' \
    $'https://nagios.monitored.htb/nagios/cgi-bin/cmd.cgi'

But how are you supposed to upload cmd.cgi to the server?
Reply
#24
Trying to get son useful in CGIs but nothing

GET /nagios/cgi-bin/cmd.cgi?cmd_typ=22&host=localhost&service=SSH HTTP/1.1

POST /nagios/cgi-bin/cmd.cgi HTTP/1.1
...

nagFormId=a9e827f8&cmd_typ=22&cmd_mod=2&host=localhost&service=SSH&btnSubmit=Commit
Reply
#25
you all got into https://nagios.monitored.htb/nagiosxi/login.php with svc:XjH7VCehowpR1xZB  ????

I get The specified user account has been disabled or does not exist.
Reply
#26
(Jan 13, 2024, 11:28 PM)zeroedbykrycek Wrote: you all got into https://nagios.monitored.htb/nagiosxi/login.php with svc:XjH7VCehowpR1xZB  ????

I get The specified user account has been disabled or does not exist.

not  https://nagios.monitored.htb/nagiosxi/login.php try https://nagios.monitored.htb/nagios/
Reply
#27
Try to find SQLi in
POST /nagiosxi/admin/banner_message-ajaxhelper.php HTTP/1.1
Host: nagios.monitored.htb
...
action=acknowledge_banner_message&id=3

No much success (maybe a rabbit hole)
Reply
#28
(Jan 14, 2024, 12:26 AM)ElBakhaw Wrote: i'll share full writeup 100% free tomorrow, i have rooted Smile

any hint on what to look into after getting the nagios panel using svc creds? Smile
Reply
#29
(Jan 14, 2024, 12:33 AM)zeroedbykrycek Wrote: any hint on what to look into after getting the nagios panel using svc creds? Smile
Try finding an sql injection vulnerability and dumb those tables Big Grin
Reply
#30
(Jan 14, 2024, 12:56 AM)peRd1 Wrote:
(Jan 14, 2024, 12:33 AM)zeroedbykrycek Wrote: any hint on what to look into after getting the nagios panel using svc creds? Smile
Try finding an sql injection vulnerability and dumb those tables Big Grin

But where should we find the SQLi, in the Nagios XI login?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  CPTS-FLAG darkcat 14 5,703 17 minutes ago
Last Post: Sukon
  [FREE] CPTS 12 FLAGS pulsebreaker 78 2,577 22 minutes ago
Last Post: hitlerssecretsidechick
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 91 8,258 24 minutes ago
Last Post: hitlerssecretsidechick
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 381 94,427 3 hours ago
Last Post: xixi75
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 14 771 4 hours ago
Last Post: phas3lock

Forum Jump:


 Users browsing this forum: 1 Guest(s)