HackTheBox(HTB) | Spider 🕸️ (Linux | Hard)

Опубликовано: 22 Май 2026
на канале: SecAura
924
22

Today we root "Spider" 🕸️, a "Hard" Linux machine from HackTheBox(htb)! - Like and Subscribe :)

⏱️Timestamps:
➡️ 00:00 - Intro
➡️ 00:20 - Routing terminal requests via http_proxy
➡️ 00:40 - Web application content discovery
➡️ 01:20 - Web application analysis/enumeration
➡️ 02:00 - Reviewing cookies
➡️ 03:45 - Python automation of user information flow
➡️ 05:15 - Extracting request flow via burp to python demo
➡️ 08:35 - Using regex to extract UUID
➡️ 20:00 - Using a wordlist with automated flow to fuzz application
➡️ 21:55 - Observe SSTI(Server Side Template Injection) payload executed
➡️ 22:30 - Python assisted manual analysis of Server Side Template Injection
➡️ 24:50 - Review of Flask/Jinja global variables
➡️ 26:00 - Dump flask global vars, leaking "secret" signing key
➡️ 28:30 - Investigation into flask SECRET_KEY usage
➡️ 31:00 - Using Flask-unsign to automate signing of forged Cookie
⭐️Link to Flask cookie SQLmap alternate method: 31:50 :
🔗 https://book.hacktricks.xyz/pentestin...
➡️ 42:00 - Python automation of cookie fuzzing
➡️ 47:00 - Detection of SQL injection based on content length
➡️ 47:30 - Python assisted manual analysis of SQL injection
➡️ 50:00 - Demo of SQL injection authentication bypass
➡️ 59:30 - Python automation of SQL injection
➡️ 1:08:00 - Chiv account dumping via SQL injection
➡️ 1:09:00 - Logging into web app as chiv follwing SQL injection
➡️ 1:10:00 - Enumeration of Support functionality in web application
➡️ 1:15:00 - Exploitation of Server Side Template Injection
➡️ 1:18:00 - Reverse shell via Server Side Template Injection
➡️ 1:20:00 - Enumeration of file system, leading to RSA private key
➡️ 1:21:00 - Enumeration of ports running, SSH tunnel created to analyse port 8080
➡️ 1:22:55 - Investigation of internal web app running on 8080
➡️ 1:23:40 - Analysis of cookie using flask-unsign
➡️ 1:25:10 - XML Entity Injection(XXE exploitation)
➡️ 1:32:25 - XML Entity Injection dumping /etc/passwd
➡️ 1:33:00 - XML Entity Injection dumping /root/.ssh/id_rsa
➡️ 1:33:35 - Logging as root!
➡️ 1:33:36 - Outtro / me mumbling contemplating life

⭐️Link to box:
🔗 https://app.hackthebox.eu/machines/350
⭐️Link to SSTI support:
🔗 https://pequalsnp-team.github.io/chea...
🔗 https://book.hacktricks.xyz/pentestin...
⭐️Link to SQL injection wordlist:
🔗 https://raw.githubusercontent.com/pay...

⭐️Link to Scripts Used:
🔗 https://github.com/SecAuraYT/HackTheB...

For more Cyber security/hacking based content, check out the rest of my channel - covering SQL injection, server side template injection, remote code execution/injection(rce), linux/windows privilege escalation, wireshark, CVE's, hackthebox, scripting - web application security testing automation etc. :)