HackTheBox - CrimeStoppers
Skills:
Security Basics80%
Key Takeaways
Exploits a PHP application vulnerability by setting an admin cookie and testing the $op parameter
Original Description
01:18 - Begin of Recon: Getting ubuntu version
04:00 - Navigating to the CrimeStoppers Page
05:15 - First Hint - Read The Source!
05:50 - 2nd Hint - No SQL Databases and playing with the upload form
07:55 - 3rd Hint - Setting Admin cookie to 1 to see whiterose.txt
09:00 - Explanation of PHP App and why I went down testing $op parameter
10:45 - Testing $op parameter, another hint what year is it?
12:20 - Finding out $op appends .php
13:05 - Using php b64 filter to view php files ("Read the source luke")
22:50 - Looking into PHP Wrappers to try to gain code execution
24:50 - Placing our PHP Script in a zip so we can reference it with zip://, also improperly upload it to the server
26:20 - Attempting to use the zip:// wrapper to execute our php script, then troubleshooting the bad upload.
30:30 - Easy way to copy binary data into BurpSuite (Base64)
34:10 - Getting a shell
37:18 - Downloading ThunderBird Directory and reading email + getting dom's password
46:20 - Begin of looking into Apache Rootkit (mod_rootme)
48:04 - Begin of using r2 (Radare) to analyze rootkit, basic intro
50:55 - Analyzing DarkArmy Function
55:30 - Grabbing the strings and using python to XOR them to get secret that allows root
58:35 - Get Root
##### BOX DONE
59:10 - Potential rabbit hole in the binary /var/www/html/whiterose.txt in the binary
01:04:20 - Second way to get root, looking around at file modification times to find FunSociety in logs
AI explanation not available for this lesson yet
This lesson is still being prepared for the AI tutor. In the meantime, explore lessons that are ready.
Browse explainer-ready lessons →
Playlist
Uploads from IppSec · IppSec · 41 of 60
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
▶
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
HHC2016 - Analytics
IppSec
HackTheBox - October
IppSec
HackTheBox - Arctic
IppSec
HackTheBox - Brainfuck
IppSec
HackTheBox - Bank
IppSec
HackTheBox - Joker
IppSec
HackTheBox - Lazy
IppSec
Camp CTF 2015 - Bitterman
IppSec
HackTheBox - Devel
IppSec
Reversing Malicious Office Document (Macro) Emotet(?)
IppSec
HackTheBox - Granny and Grandpa
IppSec
HackTheBox - Pivoting Update: Granny and Grandpa
IppSec
HackTheBox - Optimum
IppSec
HackTheBox - Charon
IppSec
HackTheBox - Sneaky
IppSec
HackTheBox - Holiday
IppSec
HackTheBox - Europa
IppSec
Introduction to tmux
IppSec
HackTheBox - Blocky
IppSec
HackTheBox - Nineveh
IppSec
HackTheBox - Jail
IppSec
HackTheBox - Blue
IppSec
HackTheBox - Calamity
IppSec
HackTheBox - Shrek
IppSec
HackTheBox - Mirai
IppSec
HackTheBox - Shocker
IppSec
HackTheBox - Mantis
IppSec
HackTheBox - Node
IppSec
HackTheBox - Kotarak
IppSec
HackTheBox - Enterprise
IppSec
HackTheBox - Sense
IppSec
HackTheBox - Minion
IppSec
VulnHub - Sokar
IppSec
VulnHub - Pinkys Palace v2
IppSec
HackTheBox - Inception
IppSec
Vulnhub - Trollcave 1.2
IppSec
HackTheBox - Ariekei
IppSec
HackTheBox - Flux Capacitor
IppSec
HackTheBox - Jeeves
IppSec
HackTheBox - Tally
IppSec
HackTheBox - CrimeStoppers
IppSec
HackTheBox - Fulcrum
IppSec
HackTheBox - Chatterbox
IppSec
HackTheBox - Falafel
IppSec
How To Create Empire Modules
IppSec
HackTheBox - Nightmare
IppSec
HackTheBox - Nightmarev2 - Speed Run/Unintended Solutions
IppSec
HackTheBox - Bart
IppSec
HackTheBox - Aragog
IppSec
HackTheBox - Valentine
IppSec
HackTheBox - Silo
IppSec
HackTheBox - Rabbit
IppSec
HackTheBox - Celestial
IppSec
HackTheBox - Stratosphere
IppSec
HackTheBox - Poison
IppSec
HackTheBox - Canape
IppSec
HackTheBox - Olympus
IppSec
HackTheBox - Sunday
IppSec
HackTheBox - Fighter
IppSec
HackTheBox - Bounty
IppSec
More on: Security Basics
View skill →Related Reads
📰
📰
📰
📰
Am I over-engineering my analytics portfolio project?
Reddit r/artificial
Data Governance vs. Data Quality: The Difference Shows Up on a Monday Morning
Medium · Data Science
Data & AI Careers in the USA: A Practical Guide to Data Analyst, Data Scientist, ML & GenAI Jobs
Medium · AI
Data & AI Careers in the USA: A Practical Guide to Data Analyst, Data Scientist, ML & GenAI Jobs
Medium · Machine Learning
Chapters (22)
1:18
Begin of Recon: Getting ubuntu version
4:00
Navigating to the CrimeStoppers Page
5:15
First Hint - Read The Source!
5:50
2nd Hint - No SQL Databases and playing with the upload form
7:55
3rd Hint - Setting Admin cookie to 1 to see whiterose.txt
9:00
Explanation of PHP App and why I went down testing $op parameter
10:45
Testing $op parameter, another hint what year is it?
12:20
Finding out $op appends .php
13:05
Using php b64 filter to view php files ("Read the source luke")
22:50
Looking into PHP Wrappers to try to gain code execution
24:50
Placing our PHP Script in a zip so we can reference it with zip://, also impro
26:20
Attempting to use the zip:// wrapper to execute our php script, then troublesh
30:30
Easy way to copy binary data into BurpSuite (Base64)
34:10
Getting a shell
37:18
Downloading ThunderBird Directory and reading email + getting dom's password
46:20
Begin of looking into Apache Rootkit (mod_rootme)
48:04
Begin of using r2 (Radare) to analyze rootkit, basic intro
50:55
Analyzing DarkArmy Function
55:30
Grabbing the strings and using python to XOR them to get secret that allows ro
58:35
Get Root
59:10
Potential rabbit hole in the binary /var/www/html/whiterose.txt in the binary
1:04:20
Second way to get root, looking around at file modification times to find FunS
🎓
Tutor Explanation
DeepCamp AI