Demonstrating XSS,RCE and PostgreSQL Exploitation | CTF Walkthrough

Опубликовано: 10 Октябрь 2024
на канале: Motasem Hamdan | Cyber Security & Tech
1,338
33

RedCross From HackTheBox was like a maze, with several different paths to achieve shell and root. We'll start by listing a website and demonstrating two distinct techniques, SQL injection and XSS, for obtaining a cookie that may be used to access the admin panel. Then, using either an exploit in the Haraka SMTP server or an injection into a webpage and manipulation of the PostgreSQL database that manages the users in the ssh jail, We'll gain access to the box as Penelope. Finally, We'll demonstrate three different ways to escalate to root, as well as two additional approaches that involve the database among them.
*******
Receive Cyber Security Field Notes, Certification Notes and Special Training Videos
   / @motasemhamdan  
********
HackTheBox Red Cross
https://www.hackthebox.com/machines/r...
Writeup
https://motasem-notes.net/demonstrati...
*******
Patreon
https://www.patreon.com/motasemhamdan...
Instagram
  / dev.stuxnet  
Twitter
  / manmotasem  
Facebook
  / motasemhamdantty  
LinkedIn
[1]:   / motasem-hamdan-7673289b  
[2]:   / motasem-eldad-ha-bb42481b2  
Website
https://www.motasem-notes.net
Backup channel
   / @themastermindclips  
My Movie channel:
   / @themastermindbooks  
******