Skip to content

Latest commit

 

History

History
66 lines (33 loc) · 2 KB

lazy.md

File metadata and controls

66 lines (33 loc) · 2 KB

LAZY HACTHEBOX

NMAP

image

In images directory i found this image:

image

I don't find ANYTHING...

But at one point I decide to see cookies, I see a cookie saved with the name auth, I'm going to try to change the cookie with the Burpsuite repeater and I get this error "Invalid Padding"...

Looks like a Padding Oracle Attack i try with Padbuster

PADBUSTER

https://github.com/AonCyberLabs/PadBuster

image

It seems that this is it!

image

DONE :)

It's the moment to create the cookie for admin user:

image

I have the cookie!

image

I put in request and...

image

I'm in Admin account i have SSH id_rsa:

image

I try to connect with SSH:

image

I can execute script named backup with root permisions

I see string from this script and i see cat /etc/shadow

This is Path Hijacking...

cd /tmp

nano cat

image

image

I execute and i have root shell.

THANKS.