Blog
About
Tags
Easy
Jul 6, 24
Hack the Box - Perfection
Weclome to Perfection!
Sep 16, 23
Hack the Box - wifinetic
Wifinetic is an easy difficulty Linux machine which presents an intriguing network challenge, focusing on wireless security and network monitoring. FTP service has anonymous authentication enabled which allows us to download available files. One of the file being OpenWRT backup which contains Wireless Network configuration that discloses Access Point password. Contents of shadow or passwd files discloses username on the server. With this information, a password reuse attack can be carried out on the SSH service, allowing us to gain a foothold as the netadmin user.. Using standard tools and with the provided wireless interface in monitoring mode we can bruteforce WPS PIN for the Access Point to obtain the PSK. The pass phrase can be reused on SSH service to obtain root access on the server.
Sep 2, 23
Hack the Box - monitorstwo
May 20, 23
Hack the Box - Precious
Precious is an Easy Difficulty Linux machine, that focuses on the Ruby language. It hosts a custom Ruby web application, using an outdated library, namely pdfkit, which is vulnerable to CVE-2022-25765, leading to an initial shell on the target machine. After a pivot using plaintext credentials that are found in a Gem repository config file, the box concludes with an insecure deserialization attack on a custom, outdated, Ruby script.
Apr 29, 23
Hack the Box - Topology
Apr 29, 23
Hack the Box - Sau
««
«
1
2
3
4
5
»
»»
Follow me
I hack things and tweet about things...
Search
Results
No results found
Try adjusting your search query