hackthebox magicgardens
by osamy7593 - Friday May 24, 2024 at 11:16 AM
#1
https://app.hackthebox.com/competitive/5/overview
let's pwn it guys

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply
#2
“xss-morty” >> “buffer overflow-alex “ >> “pickle deserialization-docker root” >> “escape container-root”

PWNED!
Thanks @paw for the rank!!
Reply
#3
(May 24, 2024, 12:12 PM)macavitysworld Wrote: “xss-morty” >> “buffer overflow-alex “ >> “pickle deserialization-docker root” >> “escape container-root”

PWNED!

can u give more details

(May 24, 2024, 12:12 PM)macavitysworld Wrote: “xss-morty” >> “buffer overflow-alex “ >> “pickle deserialization-docker root” >> “escape container-root”

PWNED!

what payload for xss

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply
#4
rooted............................

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply
#5
can someone find the workaround for the smtp service? it has been removed from the box
Reply
#6
(May 24, 2024, 12:12 PM)macavitysworld Wrote: “xss-morty” >> “buffer overflow-alex “ >> “pickle deserialization-docker root” >> “escape container-root”

PWNED!

Can you give more details about this
Reply
#7
(May 29, 2024, 02:45 AM)psy00ps1337 Wrote: can someone find the workaround for the smtp service? it has been removed from the box

The box was patched, now there is no unintended ways and you should exploit binary to pwn it.
Reply
#8
Has anyone any idea on how to proceed?? The machine is patched and i would like to complete it again.

Need nudge for foothold, don't know what to do with the web page...
Reply
#9
(Jun 05, 2024, 09:40 PM)octubrerojo Wrote: Has anyone any idea on how to proceed?? The machine is patched and i would like to complete it again.

Need nudge for foothold, don't know what to do with the web page...

SSRF to get subscription. Then XSS in QR code to steal stuff session. That is web site part.
Reply
#10
(Jun 06, 2024, 02:10 PM)j868K3792 Wrote:
(Jun 05, 2024, 09:40 PM)octubrerojo Wrote: Has anyone any idea on how to proceed?? The machine is patched and i would like to complete it again.

Need nudge for foothold, don't know what to do with the web page...

SSRF to get subscription. Then XSS in QR code to steal stuff session. That is web site part.

Yup!! But of no use.. morty doesn't have the user flag...
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 370 92,363 4 hours ago
Last Post: lifolifo007
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,200 7 hours ago
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,505 Yesterday, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 406 Yesterday, 10:36 PM
Last Post: op334
  CBBH Write Ups hiddenhacker 22 6,237 Yesterday, 06:39 AM
Last Post: Usercomplex

Forum Jump:


 Users browsing this forum: 1 Guest(s)