[HTB] Sea - Machine
by RedTeamer - Friday August 9, 2024 at 08:04 PM
#11
(08-10-2024, 07:54 PM)AdenBilal Wrote: there is ssrf on the website parameter in contact.php. start python server in your machine and enter that IP in the website with idnf
http://10.10.16.51:1235/idnf

why idnf?////////////
Ban reason:
Asking for rep is not allowed (Permanent)
Reply
#12
(08-10-2024, 07:58 PM)osamy7593 Wrote:
(08-10-2024, 07:54 PM)AdenBilal Wrote: there is ssrf on the website parameter in contact.php. start python server in your machine and enter that IP in the website with idnf
http://10.10.16.51:1235/idnf

why idnf?////////////

That's just the file they're calling
Reply
#13
(08-10-2024, 08:01 PM)vainyyyyyy Wrote:
(08-10-2024, 07:58 PM)osamy7593 Wrote:
(08-10-2024, 07:54 PM)AdenBilal Wrote: there is ssrf on the website parameter in contact.php. start python server in your machine and enter that IP in the website with idnf
http://10.10.16.51:1235/idnf

why idnf?////////////

That's just the file they're calling


sorry for the delay idnf is just an identifier.
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#14
At this point we all know the website parameter in the post request is the way forward
Reply
#15
i am receiving hits back to my server multiple times which either means the website URL I enter is getting fetched multiple times or it is getting stored anywhere and it is auto-execute for that.
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#16
(08-10-2024, 08:21 PM)gihimlek Wrote:
(08-10-2024, 08:19 PM)AdenBilal Wrote: i am receiving hits back to my server multiple times which either means the website URL I enter is getting fetched multiple times or it is getting stored anywhere and it is auto-execute for that.

Is getting stored

Trying brute forcing ssh with velik71 user, but without any expectation

how you found velik71 user
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#17
(08-10-2024, 08:23 PM)AdenBilal Wrote:
(08-10-2024, 08:21 PM)gihimlek Wrote:
(08-10-2024, 08:19 PM)AdenBilal Wrote: i am receiving hits back to my server multiple times which either means the website URL I enter is getting fetched multiple times or it is getting stored anywhere and it is auto-execute for that.

Is getting stored

Trying brute forcing ssh with velik71 user, but without any expectation

how you found velik71 user

Home page
Reply
#18
(08-10-2024, 08:25 PM)kewlcat002 Wrote:
(08-10-2024, 08:23 PM)AdenBilal Wrote:
(08-10-2024, 08:21 PM)gihimlek Wrote:
(08-10-2024, 08:19 PM)AdenBilal Wrote: i am receiving hits back to my server multiple times which either means the website URL I enter is getting fetched multiple times or it is getting stored anywhere and it is auto-execute for that.

Is getting stored

Trying brute forcing ssh with velik71 user, but without any expectation

how you found velik71 user

Home page

yeah but ig that may or may not be ssh user.
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#19
(08-10-2024, 08:23 PM)AdenBilal Wrote:
(08-10-2024, 08:21 PM)gihimlek Wrote:
(08-10-2024, 08:19 PM)AdenBilal Wrote: i am receiving hits back to my server multiple times which either means the website URL I enter is getting fetched multiple times or it is getting stored anywhere and it is auto-execute for that.

Is getting stored

Trying brute forcing ssh with velik71 user, but without any expectation

how you found velik71 user

Dude it's in the banner of the webpage.
Reply
#20
apache server is apache/2.4.41
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 360 88,710 03-28-2026, 09:28 AM
Last Post: catsweet
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,348 03-28-2026, 03:30 AM
Last Post: lulaladrow
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,490 03-27-2026, 07:22 PM
Last Post: stn
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 350 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 646 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)