HackTheBox ~ Cache Walkthrough

Pubblicato il: 10 ottobre 2020
sul canale di: Parity InfoSec
231
7

Cache was an enumeration box from start to finish (OSCP like?) with a great example of chained unauthenticated to authenticated exploits to achieve RCE. Pushing the boundaries on a lesser known memcache enumeration skill, we get the final user and escape the Docker container for root. Join me for a great run on #HackTheBox.

#HTB #BridgingTheGap

00:00 Intro
03:17 NMap
04:07 Enumeration: http (cache.htb)
07:16 Enumeration: login page (Username/Password Enumeration)
08:30 Enumeration: JavaScript function (Client-Side authentication & exposed credentials)
11:19 Enumeration: http (hms.htb / OpenEMR)
12:23 OpenEMR vulnerabilities
https://www.open-emr.org/wiki/images/...

13:26 add_edit_event_user.php authentication bypass
14:26 gobuster (hms.htb)
17:20 admin.php (OpenEMR version leak / database name disclosure)
19:55 Manual SQLi via add_edit_event_user.php
21:13 sqlmap enumeration / dump
24:47 Gather openemr_admin hash / crack password
26:18 Authenticated RCE
https://www.exploit-db.com/exploits/4...

28:44 Obtained shell (www-data) & priv esc to user
31:19 ~~USER.TXT~~
32:13 Enumeration: linpeas (user:ash)
39:41 HTB specific -- change ssh port from 22 (no longer permitted traffic into hacker domain (10.10.14.x))
42:11 Remote port forwarding (11211/memcached)
43:48 Python memcache tools (memcstat, memcdump, memccat)
46:03 ssh (user:luffy)
46:53 Enumeration: linpeas (user:luffy)
47:14 GTFOBins priv esc (docker)
49:48 ~~ROOT.TXT~~
49:59 Summary


In questa pagina del sito puoi guardare il video online HackTheBox ~ Cache Walkthrough della durata di ore minuti seconda in buona qualità , che l'utente ha caricato Parity InfoSec 10 ottobre 2020, condividi il link con amici e conoscenti, su youtube questo video è già stato visto 231 volte e gli è piaciuto 7 spettatori. Buona visione!