Перейти к содержимому

HackTheBox - Node | Beginner Friendly | Road to OSCP #49

mutatedknutz

0:00 / 0:00

HackTheBox - Node | Beginner Friendly | Road to OSCP #49

499 просмотров · 6 лет назад
mutatedknutz
1,58 тыс. подписчиков
499 просмотров · 6 лет назад
This is a Beginner friendly pentesting video where we will be gaining system access on HackTheBox - Node machine. We will manually enumerate the web application to obtain credentials. We will insert cmd data in mongodb for RCE and exploit buffer overflow binary to get root. 00:00 Intro 00:18 Enumeration using AutoRecon 01:50 Enumerating port 3000 web application 05:45 Obtaining hashes and passwords 11:14 Using found credentials to download the backup file 12:00 Analyzing and obtaining zip file password 15:51 Analyzing zip file contents and obtaining mark user credentials 17:37 Successful SSH login as user mark and manual enumeration 19:37 Executing and analyzing LinEnum.sh 25:20 Analyzing scheduler app.js file 28:55 Mongo scheduler database login and enumerating 32:05 Inserting cmd data in collections to gain reverse shell as tom 40:25 Analyzing the backup binary file 49:16 Confirming buffer overflow in backup file 54:31 Transferring backup and keys file to target machine 58:30 Analyzing backup file using gdb and locating EIP 1:04:38 Performing return to LIBC attack and gaining root 1:19:53 Bypassing blacklisted characters in backup file 1:25:44 Command line injection to get root shell 1:30:00 Box summary #hackthebox #node