Hackthbox Trickster Linux - Medium
by selukas - Wednesday September 18, 2024 at 06:22 PM
#21
Were you able to crack adams hash?
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#22
(09-21-2024, 10:17 PM)nomx1337 Wrote: Were you able to crack adams hash?

Yep, but I was running hashcat for at least 20 min before it turned up over halfway through my wordlist...
Reply
#23
for POC
there is a couple of things to change:
in zip you have a.php - need a change to yours ip to get shell - but this file must be in zip
in exploit.py - change name of shell.php to /themes/next/a.php
in exploit html:
all admin-dev to admin634ewutrx1jgitlooaj
and in import_theme to yours_ip
Reply
#24
(09-21-2024, 10:17 PM)nomx1337 Wrote: Were you able to crack adams hash?

I cracked james' hash from the database

(09-21-2024, 10:32 PM)jsvensson Wrote: for POC
there is a couple of things to change:
in zip you have a.php - need a change to yours ip to get shell - but this file must be in zip
in exploit.py - change name of shell.php to /themes/next/a.php
in exploit html:
all admin-dev to admin634ewutrx1jgitlooaj
and in import_theme to yours_ip

I had to change the call to reverse_shell.php in exploit.html to a.php as well
(or you can add the modified reverse_shell.php to the zip)
Reply
#25
james@trickster.htb

pass: alwaysandforever
Reply
#26
(09-21-2024, 11:13 PM)Leonzola Wrote: james@trickster.htb

pass: alwaysandforever

how can I fand this password ?
Reply
#27
(09-21-2024, 11:13 PM)Leonzola Wrote: james@trickster.htb

pass: alwaysandforever

where u found DB creds
Ban reason:
Asking for rep is not allowed (Permanent)
Reply
#28
You can find db creds underĀ /var/www/prestashop/app/config/parameters.php
connect to mysql
use prestashop
select * from ps_employee;
crack james hash => password:alwaysandforever

Anyone has path for root?
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#29
(09-21-2024, 11:26 PM)wtfduw Wrote: You can find db creds underĀ /var/www/prestashop/app/config/parameters.php
connect to mysql
use prestashop
select * from ps_customer;
crack james hash => password:alwaysandforever

Anyone has path for root?

thx budd ................
Ban reason:
Asking for rep is not allowed (Permanent)
Reply
#30
There is no james, just adam in my db (tried to crack the pw for 30min and it's not the same as james)
Are there different box setups?
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  HTB - ARTIFICIAL.HTB - EASY LINUX chain 0 21 02-10-2026, 02:12 PM
Last Post: chain
  HTB - VOLEUR.HTB - MEDIUM WINDOWS chain 1 120 02-09-2026, 07:07 PM
Last Post: 403Forbidden
  HTB - CONVERSOR.HTB - EASY LINUX chain 0 117 02-09-2026, 04:36 PM
Last Post: chain
  HTB - FACTS.HTB - EASY LINUX chain 2 163 02-09-2026, 11:02 AM
Last Post: chain
  Cobblestone Hack the Box Season 8 (Linux Insane) RedBlock 0 438 08-09-2025, 12:20 PM
Last Post: RedBlock



 Users browsing this thread: 1 Guest(s)