Solar/FullHouse Pro Lab
by RaidenZX - Saturday December 28, 2024 at 11:19 AM
#1
Would anyone like to give a clue about the manor...? and fullhouse I lost the script to make the footprint and I don't remember how to do it again hahaha

Remembering that anyone who doesn't want to help, please don't get in the way... <3 I was stuck in the solar footprint, I don't understand why I can't find anything listing the host folders
Reply
#2
(Dec 28, 2024, 11:19 AM)RaidenZX Wrote: Would anyone like to give a clue about the manor...? and fullhouse I lost the script to make the footprint and I don't remember how to do it again hahaha

Remembering that anyone who doesn't want to help, please don't get in the way... <3 I was stuck in the solar footprint, I don't understand why I can't find anything listing the host folders
am also stucked there there is hidden directory related to .zfs file system like a snapshot or backup that will not be showing with ls -all

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching.
Reply
#3
this is nice, thanks
Reply
#4
(Feb 09, 2025, 02:30 PM)0xb043 Wrote: this is nice, thanks

what the fuck are you talking about, there's nothing here?
what exactly is nice?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Scraping | https://breachforums.ai/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#5
(Feb 10, 2025, 07:04 PM)onetxguy Wrote:
(Feb 09, 2025, 02:30 PM)0xb043 Wrote: this is nice, thanks

what the fuck are you talking about, there's nothing here?
what exactly is nice?

With "zfs list", you can see the backups mount point, the with "zfs list -t snapshot" you can see the snapshot for each backup.
The one that teorically is useful is /backups/neptune/usr/local/fileserver/, inside that folder there is the snapshot that isn't visible with "ls -al".
Just cd into it and go to /backups/neptune/usr/local/fileserver/.zfs, in that directory there is the snapshot/ and inside, the binary fileserver.
Teorically you must RE that file and do some stuff but idk what beacouse i'm stuck on that Tongue
Reply
#6
(Feb 13, 2025, 03:03 PM)Pierluigi2497 Wrote:
(Feb 10, 2025, 07:04 PM)onetxguy Wrote:
(Feb 09, 2025, 02:30 PM)0xb043 Wrote: this is nice, thanks

what the fuck are you talking about, there's nothing here?
what exactly is nice?

With "zfs list", you can see the backups mount point, the with "zfs list -t snapshot" you can see the snapshot for each backup.
The one that teorically is useful is /backups/neptune/usr/local/fileserver/, inside that folder there is the snapshot that isn't visible with "ls -al".
Just cd into it and go to /backups/neptune/usr/local/fileserver/.zfs, in that directory there is the snapshot/ and inside, the binary fileserver.
Teorically you must RE that file and do some stuff but idk what beacouse i'm stuck on that Tongue
Yup am back to it i will ping you guys if i found something

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching.
Reply
#7
Hey guys, you need to overflow the password field into the port number. From there you can interact with the local web server, but I'm stuck here.
Reply
#8
(Mar 06, 2025, 10:55 PM)choucco Wrote: Hey guys, you need to overflow the password field into the port number. From there you can interact with the local web server, but I'm stuck here.

yeah exactly and we can like over flow the host from the password field with _*512 and _ get striped out cause the _ is not a valid char in the host see that sanitaze host function but am still trying to make it able to request 8080 cause there is a local server runing there and remamber we can upload pdf on www.solrsystem.htb we can play with magic bytes to upload php fiile but i didn't manage to escape .pdf ext and also i don't know where the file is stored 
```struct url {
    char scheme[16];
    char user[256];
    char pwd[256];
    char host[256];
    int port;
    char* doc;
    int netrcfd;
};```

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching.
Reply
#9
also we can't use null bytes to keep port eq 80 and write on host -> doc to request like a file from the server

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching.
Reply
#10
Oh, how did you manage to upload pdf?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 66 1,790 6 hours ago
Last Post: vlka
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 370 92,595 11 hours ago
Last Post: lifolifo007
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,218 Yesterday, 02:10 PM
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,527 Apr 29, 2026, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 416 Apr 29, 2026, 10:36 PM
Last Post: op334

Forum Jump:


 Users browsing this forum: 1 Guest(s)