krutoenviro.blogg.se

Shellshock live hack
Shellshock live hack









shellshock live hack

This box is a part of TJnull’s list of boxes. I can get privilege with python so that I searched python privilege command at internet. php page presents an interesting BI/Analytics page, shown below: Poking around a bit, there seemed to be a number of potential attack paths, such as attempting commmand injection via an imported js or csv file with the import local file function, or potentially trying SQL or NoSQL injection (thinking the host might have a mongoDB backend) in the main index.

shellshock live hack shellshock live hack

Hackthebox Heist Walkthrough-Further Reading.











Shellshock live hack