Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Horizontall HackTheBox Walkthrough
IntroductionHorizontall is an “easy” rated CTF Linux box on Hack The Box platform. The box covers initial compromise by exploiting Strapi RCE vulnerability and escalating privileges by tunneling an internal application (Laravel) to local machine and running a PoC exploit on Laravel v 7.4.18Table of Content· nmapEnumeration· Subdomain enumeration using wfuzzExploitation· Exploiting strapi CVE-2019-18818 to gain a reverse shellPrivilege Escalation· Tunneling internal website to our systemNetwork ScanningFirst, we will run an nmap scan on the victim machine nmap -sV -sC -Pn 10.129.149.92https://blogger.googleusercontent.com/img/a/AVvXsEgpA-ERDt2IsmWu1onaA-eMoZwP8bM2uw9PiJTKSVhKoFR54wVRzWG5wS5slegvKNv96-piH_BX9d2EJ-JBGaOxii2snN8fZzMBYisTeSiDuFnZrphFY1QlfDB-xsujwKCaqC32lNPf9rvtTSaeahA3fCA0SdRdcQgGqnBHE8N0dIf74HfEzZcEmpP21w=s16000 EnumerationSince, there was a website running on port 80, we added the address in our hosts file for resolution.wfuzz -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -H "Host: FUZZ.horizontall.htb" --sc 200 10.129.149.92This returned back an interesting subdomain called api-prodecho "10.129.149.92 api-prod.horizontall.htb" >> /etc/hostshttps://blogger.googleusercontent.com/img/a/AVvXsEhpkAZ1FQs1vINrFT3yNzeAQkUBox1nTSnNah3GeSiEV2eTGyIPZ4cpdN_mH_lfagNRDvjotfYtJ836KXZX5RU_KFMmhJx3cItwy6f1yu515CYVjdbfSMR8LlZ9ynhLajeA7mrczF2tcplH1_NKjMKjlHF7-pFqrQGLiJ5ISMGKIt2SG_DJ0gKKyGx0_g=s16000 It seemed like a plain website with no vectors again and thus, we tried directory enumeration. We found a directory /admin. Upon checking the components that made this website, we found the title to be strapi.whatweb http://api-prod.horizontall.htb/admin/https://blogger.googleusercontent.com/img/a/AVvXsEimfroWYSUi1l_gg2u2KOWFlyXtQy0UO7pcFA_13LhNTK6-GU9OWI8g6P9dODQk8rTY7nSMAQ8kU-546CCQGx-XgQGXMNitJpK5N6MW1g50oQTdBQ5-PkpEHEtweHKNxBNt6GMKmDAVRcTbw_8Imz88hk1DWXvJCIP2G-r-JDqv3nPL6FCrGr9dPoBhhA=s16000 We observed the response in burp and noticed strapi version to be 3.0.0-beta 17.4https://blogger.googleusercontent.com/img/a/AVvXsEiCJ8FgYHLpzxFTOdtwRwzcnHXhtUbc2NH_ehA9tppXwpZUVlKdpIJWRz5XgsL9HCbz7x2_L96MfIcWW4um32hlBV8Ev-kaKCwF2LH6afj-GKoyTn8OFA3Xu6MIripA_Y12Sg0mGnZAlnPvt1zXMqwuhWLgLgddxw6sQcDesQWrxvUuDs7tImeGVplX5Q=s16000 ExploitationSearchsploit result showed us an exploit for the given version was available. This version was afflicted with CVE-2019-18818. This vulnerability allows an attacker to reset the admin password witho[...]
___________________________
@hacking_Attack
@Hacking_Video
Horizontall HackTheBox Walkthrough
IntroductionHorizontall is an “easy” rated CTF Linux box on Hack The Box platform. The box covers initial compromise by exploiting Strapi RCE vulnerability and escalating privileges by tunneling an internal application (Laravel) to local machine and running a PoC exploit on Laravel v 7.4.18Table of Content· nmapEnumeration· Subdomain enumeration using wfuzzExploitation· Exploiting strapi CVE-2019-18818 to gain a reverse shellPrivilege Escalation· Tunneling internal website to our systemNetwork ScanningFirst, we will run an nmap scan on the victim machine nmap -sV -sC -Pn 10.129.149.92https://blogger.googleusercontent.com/img/a/AVvXsEgpA-ERDt2IsmWu1onaA-eMoZwP8bM2uw9PiJTKSVhKoFR54wVRzWG5wS5slegvKNv96-piH_BX9d2EJ-JBGaOxii2snN8fZzMBYisTeSiDuFnZrphFY1QlfDB-xsujwKCaqC32lNPf9rvtTSaeahA3fCA0SdRdcQgGqnBHE8N0dIf74HfEzZcEmpP21w=s16000 EnumerationSince, there was a website running on port 80, we added the address in our hosts file for resolution.wfuzz -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -H "Host: FUZZ.horizontall.htb" --sc 200 10.129.149.92This returned back an interesting subdomain called api-prodecho "10.129.149.92 api-prod.horizontall.htb" >> /etc/hostshttps://blogger.googleusercontent.com/img/a/AVvXsEhpkAZ1FQs1vINrFT3yNzeAQkUBox1nTSnNah3GeSiEV2eTGyIPZ4cpdN_mH_lfagNRDvjotfYtJ836KXZX5RU_KFMmhJx3cItwy6f1yu515CYVjdbfSMR8LlZ9ynhLajeA7mrczF2tcplH1_NKjMKjlHF7-pFqrQGLiJ5ISMGKIt2SG_DJ0gKKyGx0_g=s16000 It seemed like a plain website with no vectors again and thus, we tried directory enumeration. We found a directory /admin. Upon checking the components that made this website, we found the title to be strapi.whatweb http://api-prod.horizontall.htb/admin/https://blogger.googleusercontent.com/img/a/AVvXsEimfroWYSUi1l_gg2u2KOWFlyXtQy0UO7pcFA_13LhNTK6-GU9OWI8g6P9dODQk8rTY7nSMAQ8kU-546CCQGx-XgQGXMNitJpK5N6MW1g50oQTdBQ5-PkpEHEtweHKNxBNt6GMKmDAVRcTbw_8Imz88hk1DWXvJCIP2G-r-JDqv3nPL6FCrGr9dPoBhhA=s16000 We observed the response in burp and noticed strapi version to be 3.0.0-beta 17.4https://blogger.googleusercontent.com/img/a/AVvXsEiCJ8FgYHLpzxFTOdtwRwzcnHXhtUbc2NH_ehA9tppXwpZUVlKdpIJWRz5XgsL9HCbz7x2_L96MfIcWW4um32hlBV8Ev-kaKCwF2LH6afj-GKoyTn8OFA3Xu6MIripA_Y12Sg0mGnZAlnPvt1zXMqwuhWLgLgddxw6sQcDesQWrxvUuDs7tImeGVplX5Q=s16000 ExploitationSearchsploit result showed us an exploit for the given version was available. This version was afflicted with CVE-2019-18818. This vulnerability allows an attacker to reset the admin password witho[...]
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Horizontall HackTheBox Walkthrough
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles|Raj Chandel's Blog
Horizontall HackTheBox Walkthrough
___________________________
@hacking_Attack
@Hacking_Video
Horizontall HackTheBox Walkthrough
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Horizontall HackTheBox Walkthrough
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CompTIA ISAO and IT-ISAC Urge Technology Companies to Elevate Cybersecurity Monitoring, Readiness in Response to Rising Geopolitical Tensions
The CompTIA ISAO and IT-ISAC teams will continue to provide updated reporting and share new threat information as it becomes available.
___________________________
@hacking_Attack
@Hacking_Video
CompTIA ISAO and IT-ISAC Urge Technology Companies to Elevate Cybersecurity Monitoring, Readiness in Response to Rising Geopolitical Tensions
The CompTIA ISAO and IT-ISAC teams will continue to provide updated reporting and share new threat information as it becomes available.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
CompTIA ISAO and IT-ISAC Urge Technology Companies to Elevate Cybersecurity Monitoring, Readiness in Response to Rising Geopolitical…
The CompTIA ISAO and IT-ISAC teams will continue to provide updated reporting and share new threat information as it becomes available.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Bugcrowd Announces Real-Time Customer Visibility and Improved Crowd-matching For Penetration Testing as a Service Solution
New features include a rich dashboard with customer visibility into the progress of methodology-based pen tests.
___________________________
@hacking_Attack
@Hacking_Video
Bugcrowd Announces Real-Time Customer Visibility and Improved Crowd-matching For Penetration Testing as a Service Solution
New features include a rich dashboard with customer visibility into the progress of methodology-based pen tests.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Bugcrowd Announces Real-Time Customer Visibility and Improved Crowd-matching For Penetration Testing as a Service Solution
New features include a rich dashboard with customer visibility into the progress of methodology-based pen tests.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
NYU Tandon Launches Chief Information Security Officer Program
Featuring in-depth core sessions and topical electives, the nine-month program takes a risk-based approach to cyber strategy.
___________________________
@hacking_Attack
@Hacking_Video
NYU Tandon Launches Chief Information Security Officer Program
Featuring in-depth core sessions and topical electives, the nine-month program takes a risk-based approach to cyber strategy.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
NYU Tandon Launches Chief Information Security Officer Program
Featuring in-depth core sessions and topical electives, the nine-month program takes a risk-based approach to cyber strategy.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
2022 Executive Women's Forum Annual Conference to Be In Person for 20th Anniversary Celebration
This year’s theme is “Celebrating 20 Years of Building Women Leaders.”
___________________________
@hacking_Attack
@Hacking_Video
2022 Executive Women's Forum Annual Conference to Be In Person for 20th Anniversary Celebration
This year’s theme is “Celebrating 20 Years of Building Women Leaders.”
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
2022 Executive Women's Forum Annual Conference to Be In Person for 20th Anniversary Celebration
This year’s theme is “Celebrating 20 Years of Building Women Leaders.”
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Netacea Announces $12M Series A Investment
New funding will be used to grow Netacea’s presence in US and UK bot mitigation markets.
___________________________
@hacking_Attack
@Hacking_Video
Netacea Announces $12M Series A Investment
New funding will be used to grow Netacea’s presence in US and UK bot mitigation markets.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Netacea Announces $12M Series A Investment
New funding will be used to grow Netacea’s presence in US and UK bot mitigation markets.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
The Unsettling Reason Why Your Help Desk May Be Your Greatest Security Vulnerability
A rogue help-desk employee could gain access to user accounts through unauthorized password resets. It's time to bring zero trust to the help desk.
___________________________
@hacking_Attack
@Hacking_Video
The Unsettling Reason Why Your Help Desk May Be Your Greatest Security Vulnerability
A rogue help-desk employee could gain access to user accounts through unauthorized password resets. It's time to bring zero trust to the help desk.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
The Unsettling Reason Why Your Help Desk May Be Your Greatest Security Vulnerability
A rogue help-desk employee could gain access to user accounts through unauthorized password resets. It's time to bring zero trust to the help desk.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Red Canary Launches Partner Program
Red Canary Partner Connect will unite a diverse ecosystem of incident response, risk and managed services partners.
___________________________
@hacking_Attack
@Hacking_Video
Red Canary Launches Partner Program
Red Canary Partner Connect will unite a diverse ecosystem of incident response, risk and managed services partners.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Red Canary Launches Partner Program
Red Canary Partner Connect will unite a diverse ecosystem of incident response, risk and managed services partners.
Shellcodetester - An Application To Test Windows And Linux Shellcodes
This tools test generated ShellCodes. Usage Exemple ShellCode Tester Linux Instalation git clone https://github.com/helviojunior/shellcodetester.gitcd shellcodetester/Linuxmake Usage Without break-point: shellcodetester file.asm With break-point (INT3). The break-point will be inserted before our generated shellcode: shellcodetester file.asm --break-point Download Shellcodetester
Read more...
___________________________
@hacking_Attack
@Hacking_Video
This tools test generated ShellCodes. Usage Exemple ShellCode Tester Linux Instalation git clone https://github.com/helviojunior/shellcodetester.gitcd shellcodetester/Linuxmake Usage Without break-point: shellcodetester file.asm With break-point (INT3). The break-point will be inserted before our generated shellcode: shellcodetester file.asm --break-point Download Shellcodetester
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Shellcodetester - An Application To Test Windows And Linux Shellcodes
http://www.kitploit.com/2022/02/shellcodetester-application-to-test.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/02/shellcodetester-application-to-test.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Shellcodetester - An Application To Test Windows And Linux Shellcodes
This tools test generated ShellCodes.
Usage
___________________________
@hacking_Attack
@Hacking_Video
Usage
___________________________
@hacking_Attack
@Hacking_Video