University CTF 2023
by terminaluzer - Friday December 8, 2023 at 01:40 PM
#21
DouglDoul dateline='[url=tel:1702049957' Wrote: 1702049957[/url]']
terminaluzer dateline='[url=tel:1702045421' Wrote: 1702045421[/url]']
ghostess256 dateline='[url=tel:1702044509' Wrote: 1702044509[/url]']
terminaluzer dateline='[url=tel:1702043513' Wrote: 1702043513[/url]']
ghostess256
dateline='[url=tel:1702043208' Wrote:
1702043208[/url]']

yes I am am also in the CTF

managed to get anything??

working on a machine apethanto but not finding anything yet

i found metabase.apethanto.htb on the source code tried rce 
https://github.com/m3m0o/metabase-pre-auth-rce-poc

but this doesnt seem to work

User this instead : hhhttps://github.com/shamo0/CVE-2023-38646-PoC

I tried it but it didn’t work for me. Is apethanto db exploitation is Pre-Auth RCE in metabase (CVE-2023-38646) or something else ?
Reply
#22
Anyone here
Reply
#23
(Dec 09, 2023, 09:00 AM)Jonwi Wrote:
DouglDoul dateline='[url=tel:1702049957' Wrote: 1702049957[/url]']
terminaluzer dateline='[url=tel:1702045421' Wrote: 1702045421[/url]']
ghostess256 dateline='[url=tel:1702044509' Wrote: 1702044509[/url]']
terminaluzer dateline='[url=tel:1702043513' Wrote: 1702043513[/url]']

managed to get anything??

working on a machine apethanto but not finding anything yet

i found metabase.apethanto.htb on the source code tried rce 
https://github.com/m3m0o/metabase-pre-auth-rce-poc

but this doesnt seem to work

User this instead : hhhttps://github.com/shamo0/CVE-2023-38646-PoC

I tried it but it didn’t work for me. Is apethanto db exploitation is Pre-Auth RCE in metabase (CVE-2023-38646) or something else ?

same, no response
Reply
#24
anyone can help me with BioBundle?
Reply
#25
What is this

Try this comment
Reply
#26
(Dec 09, 2023, 01:37 AM)ashur Wrote: Need a hint for Apethanto root plz !

is it kernel exploit? everything else doesn't seems to work
Reply
#27
Can anyone give me a hint to great old talisman (pwn easy challenge) ?
Reply
#28
(Dec 08, 2023, 03:20 PM)ghostess256 Wrote: check your dms

Id also like to know please
Reply
#29
(Dec 09, 2023, 01:37 AM)ashur Wrote: Need a hint for Apethanto root plz !

I tryed dirtypipe exploit, but it gave me nothing.
Reply
#30
(Dec 09, 2023, 01:06 PM)st123 Wrote:
(Dec 08, 2023, 03:20 PM)ghostess256 Wrote: check your dms

Id also like to know please

me too, please. 

i tried both of 'em and HTB_Analytics_poc, too. 

but i'm getting "Malformed JSON in request body" in my burp with first two and db not found with htb py script: 

{"message":"Database cannot be found.","errors":{"db":"check your connection string"}}

any suggestions?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 10 597 1 hour ago
Last Post: chufoni
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 28 2,824 1 hour ago
Last Post: chufoni
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 375 93,498 1 hour ago
Last Post: Johe
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 604 92,606 1 hour ago
Last Post: Johe
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,994 3 hours ago
Last Post: char0n1507

Forum Jump:


 Users browsing this forum: 1 Guest(s)