HackTheBox - Facts

IppSec Video 1 months ago

Description

00:00 - Introduction
00:55 - Start of nmap
02:30 - Discovering it is Camaleon CMS based upon the theme url
04:00 - Looking at the cookie to see it is likely a RAILS App
06:00 - Discovering /admin, enumerating valid usernames by how long a login takes
09:40 - Playing with Mass Assignment spots in the application, failing the first few
13:10 - Exploiting mass assignment from the password reset and setting role to admin
16:30 - Discovering AWS Information in the admin panel, setting upthe AWS CLI to use this endpoint then download a ssh key from S3
21:30 - Cracking SSHNG$6 with John because Hashcat doesn't have this yet
25:15 - Our user can run facter with sudo, looking at the GTFOBin and getting code execution
29:20 - Beyond Root: Exploiting CVE-2024-46987, which is a File Disclosure