Noter - HTB [Discussion]
by - Thursday, January 1, 1970 at 12:00 AM
Anyone help me with user
Reply
(May 8, 2022, 06:37 PM)Exa Wrote: So I think I got code execution. My test.md file contains:

a'; sleep 10; echo 'a


Nice one :idea:


(May 8, 2022, 07:05 PM)LaLisa Wrote: Anyone help me with user


Where are you stuck?
Reply
Got XSS and secret i can't get in as blue
Reply
(May 8, 2022, 07:42 PM)LaLisa Wrote: Got XSS and secret i can't get in as blue


flask-unsign --sign --cookie "{'logged_in': True, 'username': 'blue'}" --secret 'secret123' --legacy


https://github.com/Paradoxis/Flask-Unsign
Reply
But how did you guys get blue as user ..??
Reply
this could be interesting for user shell 
'md-to-pdf exploit'

https://security.snyk.io/vuln/SNYK-JS-MDTOPDF-1657880
Reply
(May 8, 2022, 07:50 PM)LaLisa Wrote: But how did you guys get blue as user ..??


There's a different error message between 'users that don't exist' and 'users that exist and you got the password wrong'

So I enumerated the users, using https://github.com/danielmiessler/SecLists/blob/master/Usernames/Names/names.txt as a source.
Reply
(May 8, 2022, 07:52 PM)Truss46 Wrote: this could be interesting for user shell 
'md-to-pdf exploit'

https://security.snyk.io/vuln/SNYK-JS-MDTOPDF-1657880


I mentioned this earlier
Reply
what is the next step for root?
Reply
(May 8, 2022, 07:56 PM)Truss46 Wrote: what is the next step for root?


There was a hint that this was a mysql. Exploring this moment now

Reply


 Users viewing this thread: Noter - HTB [Discussion]: No users currently viewing.