HackTheBox ~ Cache Walkthrough

Veröffentlicht am: 10 Oktober 2020
auf dem Kanal: Parity InfoSec
231
7

Cache was an enumeration box from start to finish (OSCP like?) with a great example of chained unauthenticated to authenticated exploits to achieve RCE. Pushing the boundaries on a lesser known memcache enumeration skill, we get the final user and escape the Docker container for root. Join me for a great run on #HackTheBox.

#HTB #BridgingTheGap

00:00 Intro
03:17 NMap
04:07 Enumeration: http (cache.htb)
07:16 Enumeration: login page (Username/Password Enumeration)
08:30 Enumeration: JavaScript function (Client-Side authentication & exposed credentials)
11:19 Enumeration: http (hms.htb / OpenEMR)
12:23 OpenEMR vulnerabilities
https://www.open-emr.org/wiki/images/...

13:26 add_edit_event_user.php authentication bypass
14:26 gobuster (hms.htb)
17:20 admin.php (OpenEMR version leak / database name disclosure)
19:55 Manual SQLi via add_edit_event_user.php
21:13 sqlmap enumeration / dump
24:47 Gather openemr_admin hash / crack password
26:18 Authenticated RCE
https://www.exploit-db.com/exploits/4...

28:44 Obtained shell (www-data) & priv esc to user
31:19 ~~USER.TXT~~
32:13 Enumeration: linpeas (user:ash)
39:41 HTB specific -- change ssh port from 22 (no longer permitted traffic into hacker domain (10.10.14.x))
42:11 Remote port forwarding (11211/memcached)
43:48 Python memcache tools (memcstat, memcdump, memccat)
46:03 ssh (user:luffy)
46:53 Enumeration: linpeas (user:luffy)
47:14 GTFOBins priv esc (docker)
49:48 ~~ROOT.TXT~~
49:59 Summary


Auf dieser Seite können Sie das Online-Video HackTheBox ~ Cache Walkthrough mit der Dauer stunde minuten sekunde in guter Qualität ansehen, das der Benutzer Parity InfoSec 10 Oktober 2020 hochgeladen hat, den Link mit Freunden und Bekannten teilen, dieses Video wurde auf Youtube bereits 231 Mal angesehen und es wurde von 7 den Zuschauern gefallen. Viel Spaß beim Betrachtenden Zuschauern gefallen!