#PwnBox strikes back in #scriptkiddie from #HTB! Pulling out all the tricks to escape a webpage, we use an MSF CVE to get user. A little script analysis & root is not far away. Start #BridgingTheGap today!
#OSCP #cybersecurity
00:00 Intro
01:53 NMap
03:29 Enumeration: http [5000]
04:42 Attempt webform Command Injection
09:42 CVE-2020-7384: msfvenom apk injection
https://www.exploit-db.com/exploits/4...
10:44 Blind RCE: Using ping & tcpdump
PWNBOX Quirk [sudo apt-get install openjdk-8-jdk]
17:49 Blind RCE: test nc connection [9999]
20:12 Blind RCE: send files over nc [/etc/passwd]
21:51 Blind RCE: save command output to file & send over nc [ls]
25:24 SSH authorized_keys injection
28:13 wget authorized_keys to overwrite [user:kid]
PWNBOX Quirk [ssh-keygen]
31:44 ~~U1/kid/USER.TXT~~
32:41 Understand the Code : web app script
36:16 DEMO: /log/hackers in action
37:28 Enumeration: /home/pwn
38:01 Understand the Code : scanlosers.sh
40:54 Log Injection to exploit scanlosers.sh [/logs/hackers]
46:16 ~~U2/pwn~~
48:00 Enumeration: sudo -l [msfconsole]
49:34 ~~ROOT/ROOT.TXT~~
50:17 Summary
Auf dieser Seite können Sie das Online-Video HackTheBox ~ ScriptKiddie Walkthrough (Blind RCE & Code breakdowns) mit der Dauer stunde minuten sekunde in guter Qualität ansehen, das der Benutzer Parity InfoSec 05 Juni 2021 hochgeladen hat, den Link mit Freunden und Bekannten teilen, dieses Video wurde auf Youtube bereits 318 Mal angesehen und es wurde von 7 den Zuschauern gefallen. Viel Spaß beim Betrachtenden Zuschauern gefallen!