RedPanda - HTB [Discussion]
by - Thursday, January 1, 1970 at 12:00 AM
New box, gl hf

PORT     STATE SERVICE
22/tcp   open  ssh
8080/tcp open  http-proxy
Reply
trying sql injection in param name :(

Panda name:
Greg
Panda bio:
Greg is a hacker. Watch out for his injection attacks!
Reply
search is vulnerable to SSTI

@(50*50)


ASP.NET Razor - Basic injection

@{
// C# code
}
Reply
(July 9, 2022, 07:18 PM)mimikatz Wrote: search is vulnerable to SSTI

@(50*50)


ASP.NET Razor - Basic injection

@{
  // C# code
}

Do you know of a c# one liner rev shell ?
Reply
(July 9, 2022, 07:25 PM)Erik Wrote:
(July 9, 2022, 07:18 PM)mimikatz Wrote: search is vulnerable to SSTI

@(50*50)


ASP.NET Razor - Basic injection

@{
  // C# code
}

Do you know of a c# one liner rev shell ?


I am working on it in burpsuite


https://www.schtech.co.uk/razor-pages-ssti-rce/

Good write up on exploit razor
Reply
(July 9, 2022, 07:25 PM)mimikatz Wrote:
(July 9, 2022, 07:25 PM)Erik Wrote:
(July 9, 2022, 07:18 PM)mimikatz Wrote: search is vulnerable to SSTI

@(50*50)


ASP.NET Razor - Basic injection

@{
  // C# code
}

Do you know of a c# one liner rev shell ?


I am working on it in burpsuite


https://www.schtech.co.uk/razor-pages-ssti-rce/

Good write up on exploit razor


Did you make it work ?
Reply
(July 9, 2022, 07:42 PM)Erik Wrote:
(July 9, 2022, 07:25 PM)mimikatz Wrote:
(July 9, 2022, 07:25 PM)Erik Wrote:
(July 9, 2022, 07:18 PM)mimikatz Wrote: search is vulnerable to SSTI

@(50*50)


ASP.NET Razor - Basic injection

@{
  // C# code
}

Do you know of a c# one liner rev shell ?


I am working on it in burpsuite


https://www.schtech.co.uk/razor-pages-ssti-rce/

Good write up on exploit razor


Did you make it work ?


Instead of waiting for a solution from me and leeching can you put in some effort?
Reply
(July 9, 2022, 07:45 PM)mimikatz Wrote:
(July 9, 2022, 07:42 PM)Erik Wrote:
(July 9, 2022, 07:25 PM)mimikatz Wrote:
(July 9, 2022, 07:25 PM)Erik Wrote:
(July 9, 2022, 07:18 PM)mimikatz Wrote: search is vulnerable to SSTI

@(50*50)


ASP.NET Razor - Basic injection

@{
  // C# code
}

Do you know of a c# one liner rev shell ?


I am working on it in burpsuite


https://www.schtech.co.uk/razor-pages-ssti-rce/

Good write up on exploit razor


Did you make it work ?


Instead of waiting for a solution from me and leeching can you put in some effort?


I'm literally asking you if you succeeded cause I've already tried it and it didn't for me, didn't ask you to tell me how you did it
Reply
Its simple java ssti. Red Panda Search | Made with Spring Boot - spring framework
https://javamana.com/2021/11/20211121071046977B.html 
try to use use *{} instead of ${} It's OK, too
Reply
(July 9, 2022, 08:05 PM)noone9001 Wrote: ssh
woodenk:RedPandazRule


How did you get this?
Reply


 Users viewing this thread: RedPanda - HTB [Discussion]: No users currently viewing.