Today we root Developer 👨💻 (Linux | Hard) machine from HackTheBox! - Like and Subscribe :)
⏱️Timestamps/Steps:
➡️ 00:00 - Intro
➡️ 00:20 - Web app review
➡️ 02:40 - Phishing email ctf
➡️ 04:20 - Find Extra web functionality after completing ctf
➡️ 04:55 - Tab nabbing discussion
➡️ 07:00 - Tab naming setup
➡️ 10:00 - Tab naming exploitation
➡️ 11:00 - Login into web admin
➡️ 12:00 - Login into web sentry subdomain
➡️ 13:10 - Find vuln version of Sentry
➡️ 13:50 - Exploiting sentry 8.0.0 / 8.0.2
➡️ 18:10 - Explaining base64 shellcode bypass
➡️ 22:50 - Getting a reverse shell
➡️ 23:00 - Linux privesc
➡️ 24:30 - Finding SQL creds/accessing DB
➡️ 28:40 - Looking for sentry credentials
➡️ 29:40 - Logging into sentry DB, getting hash for Karl
➡️ 31:00 - Hash cracking karl hash
➡️ 32:00 - SSH as Karl
➡️ 32:30 - Finding Sudo Binary
➡️ 32:40 - Binary analysis
➡️ 33:08 - Using ghidra to analyse Binary
➡️ 35:00 - Analysing binary flow with Ghidra
➡️ 37:00 - Locating AES function and parameters
➡️ 38:00 - Reviewing the binary logic
➡️ 41:20 - Using GDB
➡️ 42:40 - Using GDB to breakpoint on user password comparison
➡️ 46:00 - Intercepting password data with GDB on R15 register
➡️ 46:40 - Extracting AES encrypted password with GDB
➡️ 48:00 - Decryptig the AES password in cyber chef
➡️ 49:30 - Getting password
➡️ 51:00 - Root
⭐️Link to box:
🔗 https://app.hackthebox.com/machines/372
For more Cyber security/hacking/pentesting beginner based content, check out the rest of my channel covering:
⭐️Web application security:
🔗Web Fundamentals for Cyber Security Series https://youtube.com/playlist?list=PLw...
🔗HackTheBox | Web/OSWE • HackTheBox | Web/OSWE
🔗OSWE "Build and Break it" Guide (Offensive Security Web Expert) • OSWE "Build and Break it" Guide (Offensive...
SQL injection, Server Side template Injection, XSS, remote code execution/Injection(RCE) XXE(XML Enternal Entity Injection) etc.
⭐️Linux Hacking + Priv esc - • HackTheBox | Linux
⭐️Windows Hacking + Priv esc- • HackTheBox | Windows
⭐️Active Directory Hacking - • HackTheBox | ActiveDirectory