HTB catch discussion
by - Thursday, January 1, 1970 at 12:00 AM
access let'chat api with credentials at /res/values/strings.xml after that you can see john's password in the room and then use this credential access to cachet system
Reply
(March 26, 2022, 07:23 AM)percyjacking Wrote: access let'chat api with credentials at /res/values/strings.xml after that you can see john's password in the room and then use this credential access to cachet system


got that. after that i need help. working with the exploit.
Reply
(March 25, 2022, 09:56 AM)percyjacking Wrote: https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection

Got User:John's Password and test change env config file according to this website it doesn't work, can you recommend anything?


Version: 2.4.0.-dev
yea, drop the ${} querires in the Mail from address.. e.g. ${DB_Username}

refresh, and it populates the field.

else you can intercept the mail set request and change the mail_driver to the value you want ${DB_USERNAME}, run a test on the  page and then check the logs - you'll see the value in there too.

## Cachet ENV Variables
https://docs.cachethq.io/docs/installing-cachet

Then SSH as will
Reply
(March 27, 2022, 07:44 AM)skyweasel Wrote:
(March 25, 2022, 09:56 AM)percyjacking Wrote: https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection

Got User:John's Password and test change env config file according to this website it doesn't work, can you recommend anything?


Version: 2.4.0.-dev
yea, drop the ${} querires in the Mail from address.. e.g. ${DB_Username}

refresh, and it populates the field.

else you can intercept the mail set request and change the mail_driver to the value you want ${DB_USERNAME}, run a test on the  page and then check the logs - you'll see the value in there too.


## Cachet ENV Variables
https://docs.cachethq.io/docs/installing-cachet

Then SSH as will


Thanks bro.
Reply
anyone please share the root part.
Reply
Any one having the root hash?


https://fdlucifer.github.io/2022/03/23/catch/
Reply
well done. Thanks for your efforts.
Reply
how to get root on the machine?
Reply
can someone help me run the exploit on catchet? 
the instructions not working properly
Reply
(April 8, 2022, 10:18 AM)koil Wrote: can someone help me run the exploit on catchet? 
the instructions not working properly


which instruction , explain further
Reply


 Users viewing this thread: HTB catch discussion: No users currently viewing.