HTB: Postman

Posted on 15 Mar 2020 in security • Tagged with security, boot2root, HTB, redis, webmin, linux • 6 min read

Postman Card

This is a writeup about a retired HacktheBox machine: Postman publish on Novemer the second 2019 by TheCyberGeek. This box is rated as easy box. It implies a redis server, a id_rsa.bak, john the ripper and webmin 1.910.


Continue reading

Vault

Posted on 08 Feb 2020 in security • Tagged with security, devops, vault • 4 min read

"Secure, store and tightly control access to tokens, passwords, certificates, encryption keys for protecting secrets and other sensitive data using a UI, CLI, or HTTP API."


Continue reading

HTB: Bitlab

Posted on 11 Jan 2020 in security • Tagged with security, boot2root, HTB, gitlab, x64dbg, postgresql, linux • 5 min read

Bitlab Card

This is a writeup about a retired HacktheBox machine: Bitlab. This box is rated as a medium box. It implies a gitlab, a user, some enumeration, a PostgreSQL database, some pain with a b64 password and some basic reverse engineering on a Windows binary.

If you just want to play with the binary: it is available in the "RemoteConnection.exe" part.


Continue reading

HTB: Craft

Posted on 05 Jan 2020 in security • Tagged with security, boot2root, HTB, git, gogs, api, vault, linux • 6 min read

Craft card

This is a writeup about a retired HacktheBox machine: Craft This box is classified as a medium machine. The user part is quit long and involve to find "secrets" in a git repository, access an API to get a reverse shell and manipulate a MySQL database in a jailed environment. The root part is quit easier and involve to interact with a vault instance.


Continue reading

HTB: Wall

Posted on 07 Dec 2019 in security • Tagged with security, boot2root, HTB, bruteforce, centreon, WAF, bypass, SUID, screen, linux • 5 min read

Wall Card

This is a writeup about a retired HacktheBox machine: Wall. This box is rated as a medium box. It implies a lot of frustration, some bruteforce, an centreon exploit with a WAF bypass and the exploitation of a SUID screen.


Continue reading

HTB: Heist

Posted on 01 Dec 2019 in security • Tagged with security, boot2root, HTB, Cisco, winrm, procdump, meterpreter, windows • 7 min read

Heist card

This is a writeup about a retired HacktheBox machine: Heist This box is classified as an easy machine. It implies some CISCO router configuration, a MS Windows server with a WinRM service, a meterpreter, a tentative of Lazagne and procdump.


Continue reading

HTB: Jarvis

Posted on 10 Nov 2019 in security • Tagged with security, boot2root, HTB, SQLi, linux • 7 min read

Jarvis Card

This is a writeup about a retired HacktheBox machine: Jarvis. This box is rated as a medium box. It implies a dead end, some SQL injection, a homemade script and a SUID binary.


Continue reading

HTB: Ellingson

Posted on 21 Oct 2019 in security • Tagged with security, boot2root, HTB, buffer overflow, ROP, ret2libc, linux • 10 min read

Ellingson card

This is a writeup about a retired HacktheBox machine: Ellingson This box is classified as a hard machine. The user is not too hard to get as it require to know python and password's cracking. The root part is really hard as this require the exploitation of a ROP buffer overflow.

Note: if you just want to play with the buffer overflow, the binary is available on this site, just go to the "Analysing the Buffer Overflow" section.


Continue reading

HTB: Writeup

Posted on 12 Oct 2019 in security • Tagged with security, boot2root, HTB, exploit, linux • 4 min read

Writeup Card

This article is a writeup about a retired HacktheBox machine: Writeup. (Yes the machine name is writeup, searching a writeup for writeup will be a funny thing.). The machine is classed as an easy one. It involves vulnerability in a known CMS as well as "PATH vulnerability" for the privilege escalation.


Continue reading

HTB: Swagshop

Posted on 29 Sep 2019 in security • Tagged with security, boot2root, HTB, linux, mangento • 6 min read

Swagshop Card

This article is a writeup about a retired HacktheBox machine: Swagshop This box was suppose to be an easy one. Turns out it wasn't. I struggle a lot in wrong direction and finally found a path to root this magento box.

This article presents the different methods which failed on the box as well as the solution to root it.


Continue reading