Nocturnal Hack the Box Season 7 (Linux Easy)
by RedBlock - Saturday April 12, 2025 at 06:18 PM
#1
Creator Boxes:



Sea

Chemistry

Alert

Cat

Dog

Code


Overall, the boxes were interesting and offered something new in each one.

http://nocturnal.htb/view.php?username=admin&file=FUZZ?
Hack the Box Season 8

https://t.me/+u1sCX38Xneo3OGM1
Reply
#2
We can use this syntax to check our uploads:

nocturnal.htb/view.php?username=amanda&file=privacy.odt

but i doesnt make my revshell work idk why, any suggest?
Reply
#3
It doesn't work because of "Content-Disposition: attachment;"
We can see the admin's session by changing the username, but it has no files. If you try another user it says the username is not found, but with admin it works. Can be a clue
Reply
#4
(Apr 12, 2025, 07:35 PM)kkkgrukckhko Wrote: We can use this syntax to check our uploads:

nocturnal.htb/view.php?username=amanda&file=privacy.odt

but i doesnt make my revshell work idk why, any suggest?

log into site as Amanda

Download backup

Dump the DB

ssh as that user

check local ports for interesting things
Reply
#5
Anyone knows what to do, to get root, after logged in through ssh as tobias?
Reply
#6
(Apr 12, 2025, 08:46 PM)samuelballsiu1 Wrote: Anyone knows what to do, to get root, after logged in through ssh as tobias?

Check ports there might be a CVE....

https://github.com/bipbopbup/CVE-2023-46...on-exploit
Reply
#7
(Apr 12, 2025, 08:47 PM)maggi Wrote:
(Apr 12, 2025, 08:46 PM)samuelballsiu1 Wrote: Anyone knows what to do, to get root, after logged in through ssh as tobias?

Check ports there might be a CVE....

https://github.com/bipbopbup/CVE-2023-46...on-exploit

Oh yeah, we need valid credentials for that
Reply
#8
(Apr 12, 2025, 08:10 PM)maggi Wrote:
(Apr 12, 2025, 07:35 PM)kkkgrukckhko Wrote: We can use this syntax to check our uploads:

nocturnal.htb/view.php?username=amanda&file=privacy.odt

but i doesnt make my revshell work idk why, any suggest?

log into site as Amanda

Download backup

Dump the DB

ssh as that user

check local ports for interesting things

how to download the sql dump I'm geting a 403.
Reply
#9
(Apr 12, 2025, 08:53 PM)hujson Wrote:
(Apr 12, 2025, 08:10 PM)maggi Wrote:
(Apr 12, 2025, 07:35 PM)kkkgrukckhko Wrote: We can use this syntax to check our uploads:

nocturnal.htb/view.php?username=amanda&file=privacy.odt

but i doesnt make my revshell work idk why, any suggest?

log into site as Amanda

Download backup

Dump the DB

ssh as that user

check local ports for interesting things

how to download the sql dump I'm geting a 403.

Login as amanda:arHkG7HAI68X8s1J

Create backup with the password arHkG7HAI68X8s1J

and unzip with the same password arHkG7HAI68X8s1J
Reply
#10
(Apr 12, 2025, 08:59 PM)samuelballsiu1 Wrote:
(Apr 12, 2025, 08:53 PM)hujson Wrote:
(Apr 12, 2025, 08:10 PM)maggi Wrote:
(Apr 12, 2025, 07:35 PM)kkkgrukckhko Wrote: We can use this syntax to check our uploads:

nocturnal.htb/view.php?username=amanda&file=privacy.odt

but i doesnt make my revshell work idk why, any suggest?

log into site as Amanda

Download backup

Dump the DB

ssh as that user

check local ports for interesting things

how to download the sql dump I'm geting a 403.

Login as amanda:arHkG7HAI68X8s1J

Create backup with the password arHkG7HAI68X8s1J

and unzip with the same password arHkG7HAI68X8s1J

Thanks it worked. But how did you find the creds for that account?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,486 Yesterday, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 394 Yesterday, 10:36 PM
Last Post: op334
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 369 91,957 Yesterday, 04:10 PM
Last Post: sabbyahmed
  CBBH Write Ups hiddenhacker 22 6,223 Yesterday, 06:39 AM
Last Post: Usercomplex
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 86 7,808 Apr 28, 2026, 11:39 PM
Last Post: my4ri0d0

Forum Jump:


 Users browsing this forum: 1 Guest(s)