HackTheBox - Node | Beginner Friendly | Road to OSCP #49
mutatedknutz
0:00 / 0:00
HackTheBox - Node | Beginner Friendly | Road to OSCP #49
499 просмотров · 6 лет назад
mutatedknutz
1,58 тыс. подписчиков
499 просмотров · 6 лет назад
This is a Beginner friendly pentesting video where we will be gaining system access on HackTheBox - Node machine. We will manually enumerate the web application to obtain credentials. We will insert cmd data in mongodb for RCE and exploit buffer overflow binary to get root.
00:00 Intro
00:18 Enumeration using AutoRecon
01:50 Enumerating port 3000 web application
05:45 Obtaining hashes and passwords
11:14 Using found credentials to download the backup file
12:00 Analyzing and obtaining zip file password
15:51 Analyzing zip file contents and obtaining mark user credentials
17:37 Successful SSH login as user mark and manual enumeration
19:37 Executing and analyzing LinEnum.sh
25:20 Analyzing scheduler app.js file
28:55 Mongo scheduler database login and enumerating
32:05 Inserting cmd data in collections to gain reverse shell as tom
40:25 Analyzing the backup binary file
49:16 Confirming buffer overflow in backup file
54:31 Transferring backup and keys file to target machine
58:30 Analyzing backup file using gdb and locating EIP
1:04:38 Performing return to LIBC attack and gaining root
1:19:53 Bypassing blacklisted characters in backup file
1:25:44 Command line injection to get root shell
1:30:00 Box summary
#hackthebox #node