University CTF 2023
by terminaluzer - Friday December 8, 2023 at 01:40 PM
#41
desperately need a hint on apethanto root...
Reply
#42
Has anyone got any advice for GateCrash?

I suspect that the User-Agent header is involved through a bit of messing around with it, but I'm not sure what approach to actually take with it.
Reply
#43
is there a way to solve apethantos without collaborator? or is there another tool for burpsuite collaborator?
Reply
#44
(Dec 09, 2023, 07:59 PM)yoshihtb2 Wrote: Has anyone got any advice for GateCrash?

I suspect that the User-Agent header is involved through a bit of messing around with it, but I'm not sure what approach to actually take with it.

Haven't got it but found this: CR-LF injection in Nim
Let me know if you get somewhere with this
Reply
#45
If I could get some help with Web GateCrash I'd really appreciate it.  I'm confident the vulnerability is CRLF as discussed, but all my payloads are yielding "Unexpected EOF".  Happy to reciprocate.  Not really competing but would like to solve at least one web challenge.  Thanks!
Reply
#46
Anyone wants to assist me with pwn easy (great old talisman) ? I can help you with web easy (gatecrash)
Reply
#47
(Dec 10, 2023, 01:03 AM)crazyaf Wrote: Anyone wants to assist me with pwn easy (great old talisman) ? I can help you with web easy (gatecrash)

Check you PMs
Reply
#48
(Dec 10, 2023, 01:32 AM)malwguy Wrote: Anyone currently doing the last web chall ?

check your pm

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Attempted Scamming | https://breachforums.rs/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#49
Hello, Can someone guide me to WindowsOfOpportunity please? I'm new to CTFs and want to complete at least 1 challenge
Reply
#50
(Dec 08, 2023, 03:39 PM)DouglDoul Wrote:
(Dec 08, 2023, 02:23 PM)terminaluzer Wrote:
(Dec 08, 2023, 02:08 PM)ghostess256 Wrote:
(Dec 08, 2023, 01:51 PM)terminaluzer Wrote:
(Dec 08, 2023, 01:46 PM)ghostess256 Wrote: yes I am am also in the CTF

managed to get anything??

working on a machine apethanto but not finding anything yet

i found metabase.apethanto.htb on the source code tried rce 
https://github.com/m3m0o/metabase-pre-auth-rce-poc

but this doesnt seem to work

User this instead : hhhttps://github.com/shamo0/CVE-2023-38646-PoC

I used it but I'm getting nothing on my collaborator
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 88 8,029 1 hour ago
Last Post: ElCAESAR_97
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 10 605 3 hours ago
Last Post: chufoni
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 28 2,831 3 hours ago
Last Post: chufoni
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 375 93,512 3 hours ago
Last Post: Johe
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 604 92,620 3 hours ago
Last Post: Johe

Forum Jump:


 Users browsing this forum: 1 Guest(s)