Talkative machine discussion
by - Thursday, January 1, 1970 at 12:00 AM
let's open discussion about this new hard machine 
just found these ports are open 

PORT    STATE SERVICE
80/tcp  open  http
8080/tcp open  http-proxy
8082/tcp open  blackice-alerts
Reply
PORT STATE SERVICE VERSION
80/tcp open http?
3000/tcp open ppp?
8080/tcp open http Tornado httpd 5.0
8081/tcp open http Tornado httpd 5.0
8082/tcp open http Tornado httpd 5.0

http://talkative.htb [200 OK] Apache[2.4.52], Country[RESERVED][ZZ], Email[[email protected]], Frame, HTML5, HTTPServer[Debian Linux][Apache/2.4.52 (Debian)], MetaGenerator[Bolt], PHP[7.4.28,], Script, Title[Talkative.htb | Talkative], UncommonHeaders[permissions-policy,link], X-Powered-By[PHP/7.4.28, Bolt], X-UA-Compatible[ie=edge]

[email protected]
[email protected]
[email protected]

8080 - Jamovi RCE XSS? https://github.com/theart42/cves/blob/master/CVE-2021-28079/CVE-2021-28079.md

3000 - Rocket Chat - User Registration - tried blind but nothing https://github.com/CsEnox/CVE-2021-22911
Reply
on the jamovi use r plugin ,run rce system cmd
Reply
I'm still working on it : )
Reply
So we can xss on jamovi but can't trigger js script, any hint?
Reply
(April 10, 2022, 08:12 PM)Internetdreams Wrote: Rooted what a hard box


you are always the rock
Reply
Allways use ro ck y list of words with jhohn?
Reply
Hi everybody. PLS share root's hash
Reply
(April 11, 2022, 03:44 PM)Internetdreams Wrote: easy rce on rjeditor -> try(system("bash -c 'id'", intern = TRUE))
on the container go on /root/ unzip the .omv containing passwords for /bolt/ on :80.
Login as [email protected]:<PASSWORD>
TWIG SSTI to RCE on theme editing ; you got a shell as www-data you can ssh as saul from here with previous creds.


sadly, i cannot run the rce on rjeditor...some help please..
Reply
(April 11, 2022, 03:44 PM)Internetdreams Wrote: easy rce on rjeditor -> try(system("bash -c 'id'", intern = TRUE))
on the container go on /root/ unzip the .omv containing passwords for /bolt/ on :80.
Login as [email protected]:<PASSWORD>
TWIG SSTI to RCE on theme editing ; you got a shell as www-data you can ssh as saul from here with previous creds.


how to unzip .omv file in machine? or how to transfer that file to my machine?
Reply


 Users viewing this thread: Talkative machine discussion: No users currently viewing.