HackTheBox - Tabby

00:00 - Intro
00:55 - Start of Nmap
01:25 - Taking a look at the web page
02:40 - Discovering Megahosting.HTB and adding it to /etc/hosts
04:04 - Playing with news.php and explaining the logic of LFI
08:40 - Discovering it is a file_get_contents(), which means we can skip all our "RCE Tests" as it won't execute PHP Code
11:20 - Poking at Tomcat and hunting for its tomcat-users.xml file to use with our LFI on apache2
17:30 - Uploading a JSP Webshell to tomcat with credentials found in tomcat-users.xml
20:20 - Using Curl to upload the JSP webshell.
23:10 - Whoops was uploading to the wrong port and then forgot to convert the JSP to a WAR File
25:38 - Reverse shells having trouble running due to bad characters.
27:55 - Downloading the shell to disk, then executing it in order to avoid special characters
31:15 - Reverse shell returned and TTY fixed. Discovering an encrypted zip file that we crack with John
35:00 - Exploring the Zip file to find there's nothing really interesting
39:00 - Trying the zip password as users on the box and getting a shell as Ash, dropping an SSH key and logging in with ash
42:00 - Running linpeas
43:00 - Discovering user is a member of LXD Group
44:42 - Building an alpine container, then uploading it to the target machine
47:45 - Uploading the alpine container and using lxc to privesc

Пікірлер: 45

  • @abisrug4898
    @abisrug48983 жыл бұрын

    "If i can type or if i can talk it will surely help me" -ippsec 2020

  • @yuno3364
    @yuno33643 жыл бұрын

    i got a good laugh watching you look for tomcat user file when the path was in the text of the default tomcat page on 8080😂

  • @dxsp1d3r
    @dxsp1d3r3 жыл бұрын

    Am now using port 9001, to respect the legend ippsec

  • @HMUP7
    @HMUP73 жыл бұрын

    " file is pulling some type of file " ippsec - 2020

  • @azelbane87
    @azelbane873 жыл бұрын

    Simply AWSOME. Thanks 4 all the time U putting 4 these videos!

  • @veritatas678
    @veritatas6783 жыл бұрын

    Really cool to see you struggle the same as me sometimes. I didn't know that cd without arguments goes to HOME as well :D

  • @saketsrv9068
    @saketsrv90683 жыл бұрын

    Respect for this man...What a dedication towards serving the community. my biggest inspiration ..

  • @pramodkhandelwal9321
    @pramodkhandelwal93213 жыл бұрын

    As always awesome man keep it up

  • @teachd.marshal1066
    @teachd.marshal10663 жыл бұрын

    We love u man coz ur awesome

  • @amitkumarprajapati5210
    @amitkumarprajapati52103 жыл бұрын

    Excellent

  • @cybersecurity3523
    @cybersecurity35233 жыл бұрын

    My brother you are the best

  • @alessandrodegregori4525
    @alessandrodegregori45253 жыл бұрын

    tomcat-users.xml was in /etc/tomcat9 folder, see 11:36 minute at the bottom of the tomcat default page

  • @HMUP7
    @HMUP73 жыл бұрын

    i love u dude

  • @kret63
    @kret633 жыл бұрын

    Awesome!

  • @harrytvu
    @harrytvu3 жыл бұрын

    Thank you!

  • @brettnieman3453
    @brettnieman34533 жыл бұрын

    Thanks for showing this without Metasploit!

  • @AhmedAbdullah-pp2mp
    @AhmedAbdullah-pp2mp3 жыл бұрын

    love u

  • @Ms.Robot.
    @Ms.Robot.3 жыл бұрын

    This was good! I loved it sweetheart! 💋💝

  • @ghost3364
    @ghost33643 жыл бұрын

    U awesome dude

  • @razaabbas5668
    @razaabbas56683 жыл бұрын

    Haven't watched it yet but I do know that the next 52m will be a really exciting one ;)

  • @tanishbhandwalkar-scarlet-8524

    @tanishbhandwalkar-scarlet-8524

    3 жыл бұрын

    Yeahh It's fun watching him doing it

  • @saidzihmmou6426
    @saidzihmmou64263 жыл бұрын

    Thank you

  • @nero2k619
    @nero2k6193 жыл бұрын

    hashcat can crack zips. They added support for cracking zip files.

  • @acestrike40
    @acestrike403 жыл бұрын

    "See you all next time" was hoping for a possible ropetwo retire next week lel

  • @P3droo96
    @P3droo963 жыл бұрын

    I would like to know wich Keyboard are you using. I love the sound! xD

  • @ippsec

    @ippsec

    3 жыл бұрын

    Ducky Zero

  • @P3droo96

    @P3droo96

    3 жыл бұрын

    @@ippsec thank you so much

  • @d4rckh122
    @d4rckh1223 жыл бұрын

    awesome :D

  • @lofdfrjhmjvjivlukjhgfghj4716
    @lofdfrjhmjvjivlukjhgfghj47163 жыл бұрын

    05:26 dev: "user input is like uh clicking buttons" user: (browse via burp repeater)

  • @vonniehudson
    @vonniehudson3 жыл бұрын

    @49:47 “sooo man options! -- sure.” You sound like me @ippsec !

  • @mitchodonnell3976
    @mitchodonnell39763 жыл бұрын

    3:50 you go over an issue with dns resolving after modifying the /etc/hosts file. I noticed when I type in a spoofed domain from .htb, I get dropped into a google/duckduckgo search. To get around this, I just add to the beginning of the .htb spoofed domain. Works without clearing cache.

  • @vhsonacomeback
    @vhsonacomeback3 жыл бұрын

    34:05 is the reason that we shouldn't crack things in a VM because it is slow (due to lack of GPU)? Or, is there another reason?

  • @jotunheim1491
    @jotunheim14913 жыл бұрын

    Hello. All works fine until the end. lxc gives me an error of "

  • @florian2119
    @florian21193 жыл бұрын

    Why you have not uploaded a PHP reverseshell

  • @nowonder9466
    @nowonder94663 жыл бұрын

    Around 25:00 your shell wasn't working so you URL encoded it but it didn't look encoded.

  • @enesozdemir9973
    @enesozdemir99733 жыл бұрын

    46:54 it's doing something hahahahahhahaha

  • @JuanBotes
    @JuanBotes3 жыл бұрын

    thanks for making these videos, i said before maybe my age but i often play your videos and 3/4 speed. too fast for me.

  • @eseseis7251
    @eseseis72513 жыл бұрын

    is Firefox, i think it some kind of protection against dns filters like pi-hole. thats why personaly i hate FF, cuz is the best browser but has things like this.

  • @michaelod8841
    @michaelod88413 жыл бұрын

    why shouldn't you crack passwords in a VM?

  • @thepinkestmoon

    @thepinkestmoon

    3 жыл бұрын

    its just slow

  • @enesozdemir9973
    @enesozdemir99733 жыл бұрын

    There is a tool "fcrackzip" to crack zip files. I think it can save you some time.

  • @devbidesmega1662
    @devbidesmega16623 жыл бұрын

    You said you will make a video to clone pwnbox themes into local parrot and never made it Whyyyyyyyyyyyyyyyyyyyyyyyyy

  • @ippsec

    @ippsec

    3 жыл бұрын

    Because videos isn’t my job. I just haven’t found the time to do that.

  • @ursr78122

    @ursr78122

    3 жыл бұрын

    @@ippsec What is your main job include? Interesting to hear :D