Awkward - HTB [Discussion]
by - Thursday, January 1, 1970 at 12:00 AM
Good luck to everyone.

Reply
store.hat-valley.htb
Reply
tryin to bruteforce the store basic auth with workers name.
Reply
(October 22, 2022, 07:39 PM)dumpsterX0 Wrote: tryin to bruteforce the store basic auth with workers name.


Does it work for you?
Reply
Cookie: token=guest
Maybe somesort of cookie injection or just fuzzing it
Reply
(October 22, 2022, 07:44 PM)u53r Wrote: Cookie: token=guest
Maybe somesort of cookie injection or just fuzzing it


token is base64 of the imput username:password
Reply
(October 22, 2022, 07:43 PM)crash2overload Wrote:
(October 22, 2022, 07:39 PM)dumpsterX0 Wrote: tryin to bruteforce the store basic auth with workers name.


Does it work for you?


still tryin


(October 22, 2022, 07:44 PM)u53r Wrote: Cookie: token=guest
Maybe somesort of cookie injection or just fuzzing it


i saw that too btw uhhhh.
Reply
(October 22, 2022, 07:49 PM)Hacker2222 Wrote: hat-valley.htb also has /api/ and /hr/


True that. Quiet bad readable http://hat-valley.htb/js/app.js
Reply
(October 22, 2022, 07:49 PM)Hacker2222 Wrote: hat-valley.htb also has /api/ and /hr/

intresting.....
Reply
/hr cookie 'guest' can be changed to anything to get access to dashboard
Reply


 Users viewing this thread: Awkward - HTB [Discussion]: No users currently viewing.