RedCross From HackTheBox was like a maze, with several different paths to achieve shell and root. We'll start by listing a website and demonstrating two distinct techniques, SQL injection and XSS, for obtaining a cookie that may be used to access the admin panel. Then, using either an exploit in the Haraka SMTP server or an injection into a webpage and manipulation of the PostgreSQL database that manages the users in the ssh jail, We'll gain access to the box as Penelope. Finally, We'll demonstrate three different ways to escalate to root, as well as two additional approaches that involve the database among them.
*******
Receive Cyber Security Field Notes, Certification Notes and Special Training Videos
/ @motasemhamdan
********
HackTheBox Red Cross
https://www.hackthebox.com/machines/r...
Writeup
https://motasem-notes.net/demonstrati...
*******
Patreon
https://www.patreon.com/motasemhamdan...
Instagram
/ dev.stuxnet
Twitter
/ manmotasem
Facebook
/ motasemhamdantty
LinkedIn
[1]: / motasem-hamdan-7673289b
[2]: / motasem-eldad-ha-bb42481b2
Website
https://www.motasem-notes.net
Backup channel
/ @themastermindclips
My Movie channel:
/ @themastermindbooks
******