#PwnBox strikes back in #scriptkiddie from #HTB! Pulling out all the tricks to escape a webpage, we use an MSF CVE to get user. A little script analysis & root is not far away. Start #BridgingTheGap today!
#OSCP #cybersecurity
00:00 Intro
01:53 NMap
03:29 Enumeration: http [5000]
04:42 Attempt webform Command Injection
09:42 CVE-2020-7384: msfvenom apk injection
https://www.exploit-db.com/exploits/4...
10:44 Blind RCE: Using ping & tcpdump
PWNBOX Quirk [sudo apt-get install openjdk-8-jdk]
17:49 Blind RCE: test nc connection [9999]
20:12 Blind RCE: send files over nc [/etc/passwd]
21:51 Blind RCE: save command output to file & send over nc [ls]
25:24 SSH authorized_keys injection
28:13 wget authorized_keys to overwrite [user:kid]
PWNBOX Quirk [ssh-keygen]
31:44 ~~U1/kid/USER.TXT~~
32:41 Understand the Code : web app script
36:16 DEMO: /log/hackers in action
37:28 Enumeration: /home/pwn
38:01 Understand the Code : scanlosers.sh
40:54 Log Injection to exploit scanlosers.sh [/logs/hackers]
46:16 ~~U2/pwn~~
48:00 Enumeration: sudo -l [msfconsole]
49:34 ~~ROOT/ROOT.TXT~~
50:17 Summary
In questa pagina del sito puoi guardare il video online HackTheBox ~ ScriptKiddie Walkthrough (Blind RCE & Code breakdowns) della durata di ore minuti seconda in buona qualità , che l'utente ha caricato Parity InfoSec 05 giugno 2021, condividi il link con amici e conoscenti, su youtube questo video è già stato visto 318 volte e gli è piaciuto 7 spettatori. Buona visione!