Today we root Forge 🔨(Linux | Medium) machine from HackTheBox! - Like and Subscribe :)
⏱️Timestamps/Steps:
➡️ 00:00 - Intro
➡️ 00:20 - Web app review
➡️ 05:00 - SSRF review
➡️ 06:00 - SSRF Python Scripting
➡️ 12:10 - FTP reveal via SSRF
➡️ 13:30 - RSA key via SSRF
➡️ 14:50 - Sudo -l to vuln python script
➡️ 15:30 - Python script review
➡️ 17:00 - SSH tunnel to internal port
➡️ 19:00 - Escaping PDB(Python debugger) interpreter to root (GTFObins)
➡️ 20:25 - Root
⭐️Link to box:
🔗 https://app.hackthebox.com/machines/376
For more Cyber security/hacking/pentesting beginner based content, check out the rest of my channel covering:
⭐️Web application security:
🔗Web Fundamentals for Cyber Security Series https://youtube.com/playlist?list=PLw...
🔗HackTheBox | Web/OSWE • HackTheBox | Web/OSWE
🔗OSWE "Build and Break it" Guide (Offensive Security Web Expert) • OSWE "Build and Break it" Guide (Offensive...
SQL injection, Server Side template Injection, XSS, remote code execution/Injection(RCE) XXE(XML Enternal Entity Injection) etc.
⭐️Linux Hacking + Priv esc - • HackTheBox | Linux
⭐️Windows Hacking + Priv esc- • HackTheBox | Windows
⭐️Active Directory Hacking - • HackTheBox | ActiveDirectory