DEDSEC-MAX / website-comments

store website comments
0 stars 0 forks source link

https://0xdedinfosec.vercel.app/posts/hackthebox-timing-writeup #7

Open utterances-bot opened 2 years ago

utterances-bot commented 2 years ago

HTB Timing Writeup | 0xDedinfosec Blog

Hackthebox release new machine called timing, in this machine we need to first find LFI with some fuzzing through LFI we need to dump the sorce code of file and get useful information and get the admin panel through admin panel we will upload imges abusing that function to get RFI and dump the git directory to find old password and get ssh session after that abuse the netutils to overwrite the authorized_keys.

https://0xdedinfosec.vercel.app/posts/hackthebox-timing-writeup

tXambe commented 2 years ago

Hi,

I follow your steps for priv esc but always what I connect by ssh with root always asks me the password of root, some track that may be wrong ?.

A greeting and thanks