HackTheBox - Pikaboo

  Рет қаралды 21,134

IppSec

IppSec

Күн бұрын

00:00 - Intro
01:05 - Start of nmap
03:00 - Discovering the webserver is apache, despite nmap saying it is nginx
06:30 - Every request with /admin gets a 401, indication that nginx location may not end with /
07:30 - Doing the nginx lfi to grab apache server-stats and leak the /admin_staging/ directory
08:30 - Running gobuster in /admin_staging/ to discover more php scripts
09:20 - Testing index.php for lfi with a php filter
12:00 - Looking at the source and seeing it is using include() which allows for RCE if we can get it pointed at php code
13:50 - Playing with the LFI, eventually finding info.php which tells us open_basedir is set to /var/ which prevents the LFI from going out of that directory
16:35 - Using wfuzz with an LFI wordlist to search for files we can chain with this LFI, discovering ftp logs
19:00 - Poisoning the FTP log with a php reverse shell then using the LFI to trigger it
24:15 - Looking at the /opt/pokeapi directory to find a LDAP credentials
25:45 - Using ldapsearch to dump information out of the linux ldap server to get pwnmeow's credentials
28:25 - Using ftp with pwnmeow's credentials, then running linpeas
32:35 - Examining the CSVUpdate cron and finding a code injection vulnerability in the perl script
35:20 - Going over why perl will execute a variable starting or ending with | with an open() command
37:30 - Creating a revers shell file that begins with |
41:30 - Uploading our malicious file via FTP and getting root

Пікірлер: 22
@anvithlobo
@anvithlobo 2 күн бұрын
41:38 is designed that way If the first character of the file name is ‘|’, the remainder of the argument is interpreted as a shell command. tnftp then forks a shell, using popen(3) with the argument supplied, and reads (writes) from the stdout (stdin). If the shell command includes spaces, the argument must be quoted; e.g. ‘"| ls -lt"’. A particularly useful example of this mechanism is: ‘dir "" |more’.
@XiSparks
@XiSparks 2 жыл бұрын
This one was so awesome. Loved all the different tricks.
@AvinashKumar-fe8xb
@AvinashKumar-fe8xb 2 жыл бұрын
sheer brilliancy, loved it :)
@pswalia2u
@pswalia2u 2 жыл бұрын
Amazing as always :)
@48pluto
@48pluto 2 жыл бұрын
You forgot to talk about incrontab at the end of the video. Thanks for the video !
@harshparekh9841
@harshparekh9841 2 жыл бұрын
Awesome box and awesome walkthrough
@Rienck
@Rienck 2 жыл бұрын
An good amount of trickery in this one! Thanks for the entertainment!
@GiniLoh
@GiniLoh 2 жыл бұрын
Nice one, thanks you bruh
@Ms.Robot.
@Ms.Robot. 2 жыл бұрын
This is very informative. 👍
@gabrielsantos19
@gabrielsantos19 2 жыл бұрын
Thank you, IppSec 👍
@markgentry8675
@markgentry8675 2 жыл бұрын
you were going to talk about that file that was like crontab. I cant remember what it was called, but you found it in the linpeas output.
@chiragartani
@chiragartani 2 жыл бұрын
1st. Will watch the video later 🙏😀
@amieemaya9472
@amieemaya9472 2 жыл бұрын
its a talk about incrotab anyways nice vid again thank u
@deadeye821
@deadeye821 2 жыл бұрын
Nice video ippsec
@sefterm-zade9744
@sefterm-zade9744 2 жыл бұрын
thanks for everything. I see you as my master. I want to ask do you update oscp playlist?
@olufelajunior
@olufelajunior 2 жыл бұрын
Amazing video, how and where did you learn all these things ? I find it hard to go on hack the box, scares the hell out of me..lol
@angelk316
@angelk316 2 жыл бұрын
Please do videos of pentesting other systems like mainframes and cloud environments
@lawaace1056
@lawaace1056 2 жыл бұрын
Hey man a stupid question lol , how old are u if u don’t mind asking
@benplayz5347
@benplayz5347 2 жыл бұрын
please do fingerprint box next. ive been stuck from when it has been released
@benplayz5347
@benplayz5347 2 жыл бұрын
please try fingerprint box next. i've been stuck from when it has been released
@sand3epyadav
@sand3epyadav 2 жыл бұрын
I have download this video watch in night
HackTheBox - Secret
49:26
IppSec
Рет қаралды 23 М.
HackTheBox - Forge
48:39
IppSec
Рет қаралды 24 М.
МАМА И STANDOFF 2 😳 !FAKE GUN! #shorts
00:34
INNA SERG
Рет қаралды 4,8 МЛН
버블티로 체감되는 요즘 물가
00:16
진영민yeongmin
Рет қаралды 112 МЛН
HackTheBox - Backdoor
38:24
IppSec
Рет қаралды 75 М.
HackTheBox   RegistryTwo
2:06:46
IppSec
Рет қаралды 11 М.
HackTheBox - AdmirerToo
58:09
IppSec
Рет қаралды 15 М.
HackThebox - Dynstr
51:29
IppSec
Рет қаралды 20 М.
UHC - Spooktrol
1:02:31
IppSec
Рет қаралды 11 М.
HackTheBox - Toby
2:06:08
IppSec
Рет қаралды 23 М.
HackTheBox - Intelligence
49:16
IppSec
Рет қаралды 32 М.
Homelab Setup Guide - Proxmox / TrueNAS / Docker Services
2:44:39
Matthias Benaets
Рет қаралды 132 М.
Network Security - Deep Dive Replay
3:08:19
Kevin Wallace Training, LLC
Рет қаралды 136 М.
МАМА И STANDOFF 2 😳 !FAKE GUN! #shorts
00:34
INNA SERG
Рет қаралды 4,8 МЛН