#PwnBox strikes back in #scriptkiddie from #HTB! Pulling out all the tricks to escape a webpage, we use an MSF CVE to get user. A little script analysis & root is not far away. Start #BridgingTheGap today!
#OSCP #cybersecurity
00:00 Intro
01:53 NMap
03:29 Enumeration: http [5000]
04:42 Attempt webform Command Injection
09:42 CVE-2020-7384: msfvenom apk injection
https://www.exploit-db.com/exploits/4...
10:44 Blind RCE: Using ping & tcpdump
PWNBOX Quirk [sudo apt-get install openjdk-8-jdk]
17:49 Blind RCE: test nc connection [9999]
20:12 Blind RCE: send files over nc [/etc/passwd]
21:51 Blind RCE: save command output to file & send over nc [ls]
25:24 SSH authorized_keys injection
28:13 wget authorized_keys to overwrite [user:kid]
PWNBOX Quirk [ssh-keygen]
31:44 ~~U1/kid/USER.TXT~~
32:41 Understand the Code : web app script
36:16 DEMO: /log/hackers in action
37:28 Enumeration: /home/pwn
38:01 Understand the Code : scanlosers.sh
40:54 Log Injection to exploit scanlosers.sh [/logs/hackers]
46:16 ~~U2/pwn~~
48:00 Enumeration: sudo -l [msfconsole]
49:34 ~~ROOT/ROOT.TXT~~
50:17 Summary
On this page of the site you can watch the video online HackTheBox ~ ScriptKiddie Walkthrough (Blind RCE & Code breakdowns) with a duration of hours minute second in good quality, which was uploaded by the user Parity InfoSec 05 June 2021, share the link with friends and acquaintances, this video has already been watched 318 times on youtube and it was liked by 7 viewers. Enjoy your viewing!