Nocturnal Hack the Box Season 7 (Linux Easy)
by RedBlock - Saturday April 12, 2025 at 06:18 PM
#1
Creator Boxes:



Sea

Chemistry

Alert

Cat

Dog

Code


Overall, the boxes were interesting and offered something new in each one.

http://nocturnal.htb/view.php?username=admin&file=FUZZ?
Hack the Box Season 8

https://t.me/+u1sCX38Xneo3OGM1
Reply
#2
We can use this syntax to check our uploads:

nocturnal.htb/view.php?username=amanda&file=privacy.odt

but i doesnt make my revshell work idk why, any suggest?
Reply
#3
It doesn't work because of "Content-Disposition: attachment;"
We can see the admin's session by changing the username, but it has no files. If you try another user it says the username is not found, but with admin it works. Can be a clue
Reply
#4
(Apr 12, 2025, 07:35 PM)kkkgrukckhko Wrote: We can use this syntax to check our uploads:

nocturnal.htb/view.php?username=amanda&file=privacy.odt

but i doesnt make my revshell work idk why, any suggest?

log into site as Amanda

Download backup

Dump the DB

ssh as that user

check local ports for interesting things
Reply
#5
Anyone knows what to do, to get root, after logged in through ssh as tobias?
Reply
#6
(Apr 12, 2025, 08:46 PM)samuelballsiu1 Wrote: Anyone knows what to do, to get root, after logged in through ssh as tobias?

Check ports there might be a CVE....

https://github.com/bipbopbup/CVE-2023-46...on-exploit
Reply
#7
(Apr 12, 2025, 08:47 PM)maggi Wrote:
(Apr 12, 2025, 08:46 PM)samuelballsiu1 Wrote: Anyone knows what to do, to get root, after logged in through ssh as tobias?

Check ports there might be a CVE....

https://github.com/bipbopbup/CVE-2023-46...on-exploit

Oh yeah, we need valid credentials for that
Reply
#8
(Apr 12, 2025, 08:10 PM)maggi Wrote:
(Apr 12, 2025, 07:35 PM)kkkgrukckhko Wrote: We can use this syntax to check our uploads:

nocturnal.htb/view.php?username=amanda&file=privacy.odt

but i doesnt make my revshell work idk why, any suggest?

log into site as Amanda

Download backup

Dump the DB

ssh as that user

check local ports for interesting things

how to download the sql dump I'm geting a 403.
Reply
#9
(Apr 12, 2025, 08:53 PM)hujson Wrote:
(Apr 12, 2025, 08:10 PM)maggi Wrote:
(Apr 12, 2025, 07:35 PM)kkkgrukckhko Wrote: We can use this syntax to check our uploads:

nocturnal.htb/view.php?username=amanda&file=privacy.odt

but i doesnt make my revshell work idk why, any suggest?

log into site as Amanda

Download backup

Dump the DB

ssh as that user

check local ports for interesting things

how to download the sql dump I'm geting a 403.

Login as amanda:arHkG7HAI68X8s1J

Create backup with the password arHkG7HAI68X8s1J

and unzip with the same password arHkG7HAI68X8s1J
Reply
#10
(Apr 12, 2025, 08:59 PM)samuelballsiu1 Wrote:
(Apr 12, 2025, 08:53 PM)hujson Wrote:
(Apr 12, 2025, 08:10 PM)maggi Wrote:
(Apr 12, 2025, 07:35 PM)kkkgrukckhko Wrote: We can use this syntax to check our uploads:

nocturnal.htb/view.php?username=amanda&file=privacy.odt

but i doesnt make my revshell work idk why, any suggest?

log into site as Amanda

Download backup

Dump the DB

ssh as that user

check local ports for interesting things

how to download the sql dump I'm geting a 403.

Login as amanda:arHkG7HAI68X8s1J

Create backup with the password arHkG7HAI68X8s1J

and unzip with the same password arHkG7HAI68X8s1J

Thanks it worked. But how did you find the creds for that account?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  CBBH Write Ups hiddenhacker 26 6,607 10 minutes ago
Last Post: d39ug
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 35 3,145 12 minutes ago
Last Post: d39ug
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 606 94,030 20 minutes ago
Last Post: Gotoschool
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 384 95,274 23 minutes ago
Last Post: Gotoschool
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 93 8,537 5 hours ago
Last Post: shx

Forum Jump:


 Users browsing this forum: 1 Guest(s)