Checker Hack the Box Season 7 (Linux Hard)
by RedBlock - Saturday February 22, 2025 at 02:24 PM
#31
I guess the vector attack is LFR (Local FIle Read) via ssrf https://fluidattacks.com/blog/lfr-via-bl...ook-stack/, but I edited the exploit and it didn't work as expected, I still believe that the intended way
Reply
#32
(02-22-2025, 09:19 PM)0xdaniii Wrote:
(02-22-2025, 08:11 PM)HRS4156453 Wrote: I have got bookstack creds:
bob:mYSeCr3T_w1kI_P4sSw0rD

how did you got this ?

Its in Teampass
Reply
#33
yes exploit works, modify the script to send payloads with request format, and it'll read file, it's kinda slow, but that's the exploit
Reply
#34
New subdomain Unlocked:
vault.checker.htb

XD
Reply
#35
(02-22-2025, 09:29 PM)v3701 Wrote: yes exploit works, modify the script to send payloads with request format, and it'll read file, it's kinda slow, but that's the exploit

Can u show me ur changes?
Reply
#36
(02-22-2025, 09:29 PM)v3701 Wrote: yes exploit works, modify the script to send payloads with request format, and it'll read file, it's kinda slow, but that's the exploit

Can you explain a little more?
Reply
#37
https://github.com/synacktiv/php_filter_...le_exploit
Reply
#38
did anyone manage to get the otp?
Reply
#39
anyone got the correct way in? im stuck...
Reply
#40
does any one have any way to get foothold is it ssrf?????
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 350 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ARTIFICIAL.HTB - EASY LINUX chain 0 21 02-10-2026, 02:12 PM
Last Post: chain
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 21 2,029 02-10-2026, 12:28 PM
Last Post: mohammadAktham
  HTB - CERTIFICATE.HTB - HARD WINDOWS chain 0 113 02-09-2026, 04:49 PM
Last Post: chain
  HTB - CONVERSOR.HTB - EASY LINUX chain 0 117 02-09-2026, 04:36 PM
Last Post: chain



 Users browsing this thread: 1 Guest(s)