Posts

Admirer Write-up | HackTheBox | By Valerie23

Image
ENUMERATION  As always let start with basic port scan. Lets visit port 80. And take a look at its source code. There is nothing worthy of our attention here. GOBUSTER Running gobuster against the target with hope of finding some hidden directories. gobuster dir -u http://admirer.htb/ -w /usr/share/wordlists/dirb/common.txt -t 50 Taking a look at robots.txt: So now we have found a username "waldo" and a hidden directory /admin-dir that contains interesting files. We are going to access this directory now The directory is forbidden. But we shouldn't lose hope this soon. Lets try to access the possible folders inside it (as mentioned in /robots.txt). http://10.10.10.187/admin-dir/contacts.txt http://10.10.10.187/admin-dir/credentials.txt FTP Using the ftp credentials try connecting to  port 21. The user and password was valid and we were able to successfully login to ftp even find some files worth looking at so we transfered it into our systems. Dump.sql doesn't contain ...

Blunder Writeup | HackTheBox | By Valerie23

Image
Gathering information Let’s start with a  nmap scan to establish the open ports in the host. Website Analysis Now we should start enumerating port 80. So lets check out the source code of the homepage and see if we are able to find any additional clues. We found this /about directory  There doesn't seem to be anything useful in this directory. Lets fireup a GoBuster scan gobuster dir -u http://10.10.10.191 -w /usr/share/ wordlists/dirb/common.txt -t 50 The /admin directory looks like: Just a little bit of google search about "BLUDIT" reveals that it is a CMS. Now we have a login panel, all we need is a username and a password. GoBuster extension Its always good to perform some further enumeration of the webapp using custom file extensions to find out any hidden backup files or some notes :) $ gobuster dir -u http://10.10.10.191 -w /usr/share/wordlists/dirb/common.txt -x txt,zip -t 50 Using the -x flag to look for some specific extensions such as txt,zip we get a /todo.txt...

Remote writeup | HackTheBox | by DarkRider88

Image
This is an easy level windows machine. So, let's start.. Enumeration First we will do the nmap scan to enumerate all the services We got our ports and we will start by enumerating the port 80. Just a simple lookup to the source code of the website gave us that the website is based upon Umbraco CMS and we can reach its login page using http://10.10.10.180/umbraco.  But wait, we don't have any credentials yet, I tried some defaul logins but no success. So, for now lets enumerate other services. FTP got nothing in it and the SMB serivce does not allow anonymous login. So, whats more? remember that Port 111 RPCbind. RPCbind: From the nmap scan's RPCinfo we can say that there are some Network File System(NFS) shares. Now we are going to enumerate further and try to list the NFS shares, if any. So here it is.. Little Explanation  First I used Showmount tool to extract all the publicly available shares from the box's IP. Then I mounted that share to my local /mnt directory usi...

Exploiting PHP preg_replace( ) function

Image
  Introduction: The preg_replace() function returns a string or array of strings where all matches of a pattern or list of patterns found in the input are replaced with substrings.  Usage:  preg_replace( patterns, replacements, input, limit, count ) This is a userful function but when handled incorrectly could cause severe damage as great as RCE. Exploitation: For example see this:  this will output: world world No problem, right? But the problem arises if we use this /e  modifier in the PHP preg_funtions which allows the PHP code to be executed. So now lets add the /e modifier and read the contents of index.php Output et Voila!  This was just an example but in real life same thing could be used but with some more complex payloads. Have nice day.                                                  -DarkRider88

Carpe-Diem | Tryhackme | Writeup

Image
Room:  Carpe - diem  Big shout out to the creator of this room:  4ndr34z Overview:   In this room we have retrieve the key which is used to encrypt a database file stored at /downloads/database.carpe. For me this room was too challenging and hence this writeup for all the coming folks. I have tried to explain everything so that the beginners could understand it easily. Enumeration: 1. A s usual we will start with NMAP scan From port scan we found there is nothing unique or interesting running except the port 80. So we should open the website and do some enumeration. 2. This website is asking us to send proof of our bitcoin address..and only after that you can retrieve the key..(I think thats what the theme of this room .. a perfect ransomware attack) 3. After that we review the source code of the webpage and always read those javascripts. Explanation:  first this code is checking that you don't copy the same address and send to proof and if you do that it pop up...