HTB Caption - Linux - Hard
by mhsoraa - Saturday September 14, 2024 at 06:31 PM
#81
How did you guys figured out the root
Reply
#82
(09-15-2024, 07:42 PM)upl04d3r Wrote:
(09-15-2024, 05:52 PM)terk12 Wrote: why am i getting an error
 ssh -i id_rsa margo@10.10.11.33
Load key "id_rsa": error in libcrypto
margo@10.10.11.33's password:

I had the same problem, fortunately chatGTP fixed it and formatted the key.

dos2unix id_rsa
vim --clean id_rsa

in vim:
:wq
Reply
#83
i cant login with root:root in http://caption.htb:8080/signin 
2 days ago i could login with root:root successfully but now i cant 
i tried to change vpn and reset the machine but nothing help
Reply
#84
(09-27-2024, 01:12 PM)khairy24 Wrote: i cant login with root:root in http://caption.htb:8080/signin 
2 days ago i could login with root:root successfully but now i cant 
i tried to change vpn and reset the machine but nothing help

They patched this machine. That was unintended solutions.
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#85
Hello, could you please advise how to access http://10.10.11.33:8080/ after the patch? (root
no longer works)
Reply
#86
Who can help with the user part?
Reply
#87
This will help with getting a foothold as margo the intended way: https://github.com/BishopFox/h2csmuggler
Reply
#88
(10-27-2024, 04:32 AM)miserey Wrote: This will help with getting a foothold as margo the intended way: https://github.com/BishopFox/h2csmuggler

hhhmmm... i'm chasing after intended solution for the moment & still failing to make it right. They seemingly patched everything.
Even previous ACL HAproxy bypass with `//` doesn't work anymore.

I've found XSS via Varsnish cache poisoning to steal admin's cookie & get inside (although, there's no difference between user or admin in the interface. Kind off lazy copy-pasta shitty machine).

Tried different fuzzing & methods to bypass HAproxy, or poison Varnish cache or HTTP/2 req smuggling via manual & automated approach... still nothing.
Used different tools (including the one you've mentioned).
https://github.com/intrudir/BypassFuzzer
https://github.com/BishopFox/h2csmuggler
https://github.com/defparam/smuggler.git

Varnish is also vulnerable to different HTTP/2 req smuggling attacks (lookup some CVEs).. however..
There's a tricky part here... HTTP/2 is a binary proto & it only works via TLS/SSL connection..
i also tried to modify some of these tools .... and i got nothing yet. Any tricks here ?
Reply
#89
(09-14-2024, 06:31 PM)mhsoraa Wrote: https://www.hackthebox.com/machines/caption
https://app.hackthebox.com/machines/625

Have fun and good luck everyone!

[Image: GXR-8C8WcAIbnPF?format=jpg]

It got patched, someone has the complete writeup?
Ban reason: Leeching. (Permanent)
Reply
#90
(10-27-2024, 04:43 PM)mazafaka555 Wrote:
(10-27-2024, 04:32 AM)miserey Wrote: This will help with getting a foothold as margo the intended way: https://github.com/BishopFox/h2csmuggler

hhhmmm... i'm chasing after intended solution for the moment & still failing to make it right. They seemingly patched everything.
Even previous ACL HAproxy bypass with `//` doesn't work anymore.

I've found XSS via Varsnish cache poisoning to steal admin's cookie & get inside (although, there's no difference between user or admin in the interface. Kind off lazy copy-pasta shitty machine).

Tried different fuzzing & methods to bypass HAproxy, or poison Varnish cache or HTTP/2 req smuggling via manual & automated approach... still nothing.
Used different tools (including the one you've mentioned).
https://github.com/intrudir/BypassFuzzer
https://github.com/BishopFox/h2csmuggler
https://github.com/defparam/smuggler.git

Varnish is also vulnerable to different HTTP/2 req smuggling attacks (lookup some CVEs).. however..
There's a tricky part here... HTTP/2 is a binary proto & it only works via TLS/SSL connection..
i also tried to modify some of these tools .... and i got nothing yet. Any tricks here ?

Same here, bro. I tried to XSS on the firewall page, but even the admin can't get past this proxy. Do you have any ideas?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 360 88,710 03-28-2026, 09:28 AM
Last Post: catsweet
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,348 03-28-2026, 03:30 AM
Last Post: lulaladrow
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,490 03-27-2026, 07:22 PM
Last Post: stn
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 350 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 646 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)