HTB - Editorial
by paven - Saturday June 15, 2024 at 05:48 PM
#1
Editorial - Linux - Easy

Good luck everyone! Let's tackle this together!
https://app.hackthebox.com/machines/Editorial
Reply
#2
will be solving it today only
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#3
any hints/findings for user?
Reply
#4
/upload has pingback on the URL field when hitting preview.
Reply
#5
anyother updates whatever i uploaded its uploading as txt file
Reply
#6
preview gives the url path but file ext is changed even i upload double ext it remove all ext
Reply
#7
The image is unchanged (so no imagemagick on the server) and the preview URL is valid for one request as far as I can see now
Reply
#8
(06-15-2024, 07:52 PM)newbi31 Wrote: preview gives the url path but file ext is changed even i upload double ext it remove all ext

Same, I'm trying to inject command on the field, but no luck
Reply
#9
Think the focus is on the cover URL - it grabs your input URL and attempts to display it as an image. Supplying an actual image and re-downloading it through the application doesn't yield any metadata about software in use
Reply
#10
http://editorial.htb/static/uploads/e6d3...18a612d27f
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 360 88,710 03-28-2026, 09:28 AM
Last Post: catsweet
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,348 03-28-2026, 03:30 AM
Last Post: lulaladrow
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,490 03-27-2026, 07:22 PM
Last Post: stn
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 350 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 646 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)