03-11-2025, 09:07 PM
Happy to help Smile
|
[FREE] CPTS • CWES • CDSA • CWEE Exam Hint
by 3midjets - Wednesday February 14, 2024 at 09:06 AM
|
|
03-11-2025, 09:07 PM
Happy to help Smile
03-11-2025, 10:16 PM
Great! Thank you so much!
03-14-2025, 07:57 AM
Tried to DM but got a 403 forbidden. Maybe this is because I'm new?
![]() I'd very much appreciate a nudge to gain initial access. Anyway, so far I have found the following: Discovered FTP, SSH, SMTP, DNS, POP3, RPCBIND, and IMAP services Identified the additional HTTP service on port 7777 Enumerated the services and brute forced FTP to identify the "ftp" user creds Found the following vhosts: dev portal remote store careers blog pr securetransfer-dev Fuzzed the vhost directories and pages, inspected the page source and walked each website in Burp. This has disclosed the following: blog is vulnerable to CVE-2023-23752. I found a PoC exploit to dump the MySQL database creds and super user login. I'm unable to find the password for this account. I've tried brute forcing using joomla-brute.py but no success. Registered an account on securetransfer-devand uploaded a few files. Uploaded files are referenced by a unique "uuid". I've tried various LFI payloads in Burp Repeater/Intruder. I suspect the "GET /download.php?file=xxx" may be the injection point but I always receive "File does not exist" when trying to retrieve /etc/passwd. trilocor.local:7777 Werkzeug "console" directory that requires PIN. I've read some research and it appears that this cannot be exploited without an initial foothold. In the real world, I would seek advice from a senior tester (hence this request!). I would very much appreciate some advice and guidance on how to progress as I'm now going around in circles!. Any pointers please? Many thanks!
03-14-2025, 05:13 PM
Answered on Discord
HTB Writeups
CPTS • CWES • CDSA • CWEE • CAPE
Discord: 3midjets_81260
Telegram: @BF3midjets
Session: 054908dd7850b28c0c39cf6c594877b6ce025bfae0e9e29b3c0e894aa4f6633a23
03-14-2025, 09:40 PM
Good resource, Appreciate it.
Thanks.
03-16-2025, 08:09 AM
A thousand thanks! Very kind and helpful Big Grin
03-17-2025, 01:48 PM
Small bump so everyone knows about this free hint.
HTB Writeups
CPTS • CWES • CDSA • CWEE • CAPE
Discord: 3midjets_81260
Telegram: @BF3midjets
Session: 054908dd7850b28c0c39cf6c594877b6ce025bfae0e9e29b3c0e894aa4f6633a23
03-18-2025, 03:21 PM
thanks i appreciate it
03-18-2025, 03:31 PM
(02-14-2024, 09:06 AM)3midjets Wrote: WoW thank you much to post this!
03-19-2025, 08:44 PM
Small bump so everyone knows about this free hint.
HTB Writeups
CPTS • CWES • CDSA • CWEE • CAPE
Discord: 3midjets_81260
Telegram: @BF3midjets
Session: 054908dd7850b28c0c39cf6c594877b6ce025bfae0e9e29b3c0e894aa4f6633a23
|
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] CPTS 12 FLAGS | 65 | 9,045 |
07-29-2026, 11:03 PM Last Post: |
||
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 361 | 98,833 |
07-28-2026, 01:37 AM Last Post: |
||
| [FREE] HTB-ProLabs APTLABS Just Flags | 24 | 9,630 |
07-12-2026, 04:10 AM Last Post: |
||
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 22 | 9,275 |
06-25-2026, 02:15 PM Last Post: |
||
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 19 | 9,448 |
06-25-2026, 12:30 PM Last Post: |
||