Hacking a BIKE website | sea htb walkthrough

Опубликовано: 10 Май 2026
на канале: Chris Alupului
3,349
120

I dive into the Sea machine on HackTheBox, starting with the exploitation of WonderCMS. I demonstrate a manual approach to a proof-of-concept (POC) exploit, showcasing each step to help you learn alongside me.

🔐 WonderCMS stores data in files, and I uncover a password hash hidden within, crack it, and use it to escalate to the next user. That same password grants access to an internal website, where I uncover a command injection vulnerability to achieve root access!

📽️ Don’t forget to like, comment, and subscribe for more HackTheBox walkthroughs, tips, and tricks!

   • unPixelate passwords like a PRO  | greenho...  
   • Hacking Education App from Hackthebox | HT...  
   • usage HTB walkthrough | SQLmap tutorial fo...  

------------------------------
Chris Alupulu's Socials:
Instagram:   / chrisalupului  
X: https://x.com/chrisalupului
TikTok: https://tiktok.com/chrisalupului
BlueSky: https://bsky.app/profile/chrisalupulu...
Visit my website: https://alupului.com

My Recording Gear Used:
https://www.amazon.com/shop/chrisalup...

Sponsors:
Interested in sponsoring my videos? Reach out to me at: [email protected]
------------------------------

💡 TIMESTAMPS:
00:00 Intro
00:40 Adding IP to the hosts file
01:40 Recon nmap
04:30 Subdomain enumeration ffuf scan
05:55 Launching burp suite and viewing web app
08:15 Contact Form
13:59 Fingerprint the CMS
19:25 Uncover login page
22:35 Discover CVE-2023-41425
25:45 Stealing admin cookie via XSS
27:20 Admin panel access
29:00 Crafting rev shell
36:50 Foothold established
39:10 Cracking hashes
40:55 SSH in and priv escalation
51:40 Outro

Subscribe for more hacking tutorials, tools, and tips

#htb #ethicalhacking #pentesting #cybersecurity #ethicalhacker #tryhackme #redteam #infosec #kalilinux #hackthebox #offensivesecurity

DISCLAIMER: This video is intended for educational purposes only. All activities demonstrated in this video were conducted on legally authorized systems such as HackTheBox & TryHackMe. Unauthorized hacking, including attempts to gain unauthorized access to computers, servers, or other digital assets, is illegal and unethical. Always obtain proper permission before conducting any form of penetration testing or security research. The techniques shown here should only be used in ethical hacking environments, and I am not responsible for any misuse of the information provided.