[HTB] Lantern
by RedTeamer - Saturday August 17, 2024 at 10:14 AM
#71
Guys anyone read cronjobs ? To know where to add that dll
Ban reason:
Asking for rep is not allowed (Permanent)
Reply
#72
(08-18-2024, 01:33 AM)ir0nman4l1f3 Wrote:
(08-18-2024, 01:27 AM)drunkp Wrote: Have you guys managed to build a dll with rev shell?

Used multiple tools to dissassemble and try to build but nothing worked.

What tools have you used?

(08-18-2024, 01:24 AM)ir0nman4l1f3 Wrote: Has anyone tried to upload a pdf using msf and exploit/windows/fileformat/adobe_pdf_embedded_exe?

If tomas has login to the port on 3000, then it is likely that HTB has an automated "click" action for uploaded resumes?

It is not windows thoug

just an example - you can also update the payload to use a linux version as well for that one.

How can you set payload for linux in adobe_pdf_embedded_exe ? tried to 'set payload' for meterpreter and tcp but says incompatible. Also used the non js option same result.
Reply
#73
(08-18-2024, 01:37 AM)osamy7593 Wrote: Guys anyone read cronjobs ? To know where to add that dll

u already can upload dll?
seems we need upload to /opt/components
and execute from lantern.htb:3000
Reply
#74
(08-18-2024, 02:19 AM)olkn00b Wrote:
(08-18-2024, 01:33 AM)ir0nman4l1f3 Wrote:
(08-18-2024, 01:27 AM)drunkp Wrote: Have you guys managed to build a dll with rev shell?

Used multiple tools to dissassemble and try to build but nothing worked.

What tools have you used?

(08-18-2024, 01:24 AM)ir0nman4l1f3 Wrote: Has anyone tried to upload a pdf using msf and exploit/windows/fileformat/adobe_pdf_embedded_exe?

If tomas has login to the port on 3000, then it is likely that HTB has an automated "click" action for uploaded resumes?

It is not windows thoug

just an example - you can also update the payload to use a linux version as well for that one.

How can you set payload for linux in adobe_pdf_embedded_exe ? tried to 'set payload' for meterpreter and tcp but says incompatible. Also used the non js option same result.

Yea I looked into this further afterwards and linux isn't suppored... based on the rapid7 post, it made it seem like other platforms were supported...
Reply
#75
GET /PrivacyAndPolicy?lang=../../../../../../&ext=./var/mail/tomas HTTP/1.1
Host: lantern.htb
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: http://lantern.htb/
DNT: 1
Connection: close
Upgrade-Insecure-Requests: 1
Sec-GPC: 1

From hr@lantern.htb Mon Jan 1 12:00:00 2023
Subject: Welcome to Lantern!

Hi Tomas,

Congratulations on joining the Lantern team as a Linux Engineer! We're thrilled to have you on board.

While we're setting up your new account, feel free to use the access and toolset of our previous team member. Soon, you'll have all the access you need.

Our admin is currently automating processes on the server. Before global testing, could you check out his work in /root/automation.sh? Your insights will be valuable.

Exciting times ahead!

Best.
Reply
#76
were are we puttting this dill file
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#77
(08-18-2024, 04:05 AM)hackemall Wrote: were are we puttting this dill file

I believe we are uploading it inside the admin panel but how can we get it to execute at /var/www/sites/lantern.htb/static/images ? Must be an LFI mentioned earlier but I haven't found it.
Reply
#78
i have done that but is stuck there
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#79
(08-18-2024, 04:44 AM)hackemall Wrote: i have done that but is stuck there

Did you got the shell ?
Reply
#80
i tried to load test.dll generated from msfvenom to /opt/components it worked but as i try to run it i get Bad IL Format
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 360 88,710 03-28-2026, 09:28 AM
Last Post: catsweet
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,348 03-28-2026, 03:30 AM
Last Post: lulaladrow
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,490 03-27-2026, 07:22 PM
Last Post: stn
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 350 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 646 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)