[Hack The Boo] Day 2 Challenges
by - Thursday, January 1, 1970 at 12:00 AM
typing something stupid to see
Reply
(October 23, 2022, 03:21 PM)Hacker2222 Wrote: web challenge:
ssti in mako templates

Thanksss
Reply
Could someone elaborate on the web challenge? ssti in mako templates doesnt say enough for me unfortunately.
Reply
(October 23, 2022, 03:21 PM)Hacker2222 Wrote: forensics challenge:
dns exfil


rename gives corrupted unrecoverable file :(
Reply
(October 23, 2022, 04:12 PM)NotEvenME Wrote: Could someone elaborate on the web challenge? ssti in mako templates doesnt say enough for me unfortunately.


its server side template injection...
payload is already there
copy and paste it in search
enjoy!!!!!


(October 23, 2022, 03:37 PM)Meep Wrote: A hint for Pwn: p.send(b'\xc9\x07\xcc\x00\x00\x00\x00\x00' + b'
')


pls be more specific
Reply
(October 23, 2022, 04:13 PM)ludovschneck Wrote:
(October 23, 2022, 03:21 PM)Hacker2222 Wrote: forensics challenge:
dns exfil


rename gives corrupted unrecoverable file :(


Don't use excel . Use his site or similar : https://products.aspose.app/cells/viewer/xlsx
Reply
(October 23, 2022, 04:13 PM)ludovschneck Wrote:
(October 23, 2022, 03:21 PM)Hacker2222 Wrote: forensics challenge:
dns exfil


rename gives corrupted unrecoverable file :(


dont forget about last "00" and remove new lines
Reply
ooooops, i was struglling with web
Reply
(October 23, 2022, 03:21 PM)Hacker2222 Wrote: web challenge:
ssti in mako templates


thanks
Reply
thanks
Reply


 Users viewing this thread: [Hack The Boo] Day 2 Challenges: No users currently viewing.