Posts

Showing posts with the label Love

Explore HTB - Walkthrough

Image
Hey peeps Styx here, This is a quick write-up on the Explore box. The box is rated as easy. But this is also the first android challange!   ____________________________________________________________________________________  # RECON # OS = Android  version =  4.9.214-android-x86_64-g04f9324  ____________________________________________________________________________________  ## PORTS ##  3 ports open  2222 tcp SSH-2.0-SSH Server - Banana Studio  44491 tcp  42135/tcp open http ES File Explorer Name Response httpd  59777 http Bukkit JSONAPI httpd for Minecraft game server 3.6.0 or older  ____________________________________________________________________________________  #EXPLOITATION# The ES File Explorer service seems to have and arbitrary file read vulnerability. Link can be found  -- > here    run python3 exploit.py listPics 10.10.10.247  We can see a couple of pics in that di...

Love HTB Walkthrough

Image
    Hey guys Styx here. Back again with another HTB walkthrough. This time we go through the Love box which is rated as easy. ## RECON ##   as usual add love.htb to the /etc/hosts file. Let's kick off off a quick rust scan.  We quickly see that there are 19 ports open. Let's look at further results. Looking at the scan results we see staging.love.htb. Let's add this to our host file. Ok let's move on to content discovery.  When enumerating the target we see that we got a hit on /admin let's browse to this location.  In this pic  here we can see that we found an admin panel. No further results were found that we can use to dig deeper in the application. So let's look back at the nmap results. Let's take a look at staging.love.htb. And on staging.love.htb we found the file scanner. Let's see if we can scan some of the local ports using this file scanner. after trying a few ports that also used HTTP (as shown in the nmap results). Eventually,by scanning 1...

Popular posts from this blog

Explore HTB - Walkthrough

Schooled HTB -Writeup

Seal HTB Walkthrough