Open in app
Home
Notifications
Lists
Stories

Write
Tellico Lungrevink
Tellico Lungrevink

Home

Apr 18

Hack the Box: ScriptKiddie

ScriptKiddie — ScriptKiddie ScriptKiddie was an easy Hack the Box machine. Main theme of the challenge was hacking an inexperienced hacker with their won tools (hence ScriptKiddie). I’ll exploit a vulnerability in the MSF Venom to gain a local shell. Then, I’ll escalate privileges to another user by exploiting local script’s vulnerability. …

Hacking

3 min read

Hack the Box: ScriptKiddie
Hack the Box: ScriptKiddie

May 24, 2021

Hack the Box: Delivery:

Delivery was an easy difficulty machine on Hack the Box. — Delivery was an easy difficulty machine on Hack the Box. TL;DR I’ll identify a helpdesk virtual subdomain which will allow me to create a ticket with a temporary email address. Using that address I’ll create an account on Mattermost instance on port 8065 where I’ll find credentials to SSH. Using…

Hacking

3 min read

Hack the Box: Delivery:
Hack the Box: Delivery:

Apr 26, 2021

Hack the Box: Laboratory

Laboratory was an easy machine on Hack the Box. — Laboratory was an easy machine on Hack the Box. TL;DR: I’ll find a virtual domain with a vulnerable instance of Gitlab. It can be exploited to gain a shell on Docker instance. I’ll use this access to change Dexter’s password and gain access to his private repository. The repository contains…

Hacking

3 min read

Hack the Box: Laboratory
Hack the Box: Laboratory

Mar 2, 2021

Hack the Box: Academy

Academy was an easy machine on Hack the Box. — Academy was an easy machine on Hack the Box. I’ll exploit a simple pivilege escalation in registration form gain access to administrator panel. Admin panel will reveal a virtual subdomain where I’ll exploit a RCE in Laravel framework. Using that access I’ll find a database password that’s been reused by…

Hacking

4 min read

Hack the Box: Academy
Hack the Box: Academy

Jan 28, 2021

Hack the Box: Cache

Cache was medium diffculty machine on Hack the Box. Here’s my take on solving the challenge. — Cache was medium diffculty machine on Hack the Box. Here’s my take on solving the challenge. TL;DR: There’s a virtual host on webserver with an instance of a vulnerable version of OpenEMR. It’s vulnerabilities can be chained up, first to gain patient access, then use it to exploit authenticated sql…

Htb

5 min read

Hack the Box: Cache
Hack the Box: Cache

Jan 6, 2021

Hack the Box: Travel

Travel was a hard difficulty mahcine of Hack the Box. Here’s my take on solving the challenge. — Travel was a hard difficulty mahcine of Hack the Box. Here’s my take on solving the challenge. TL;DR: Travel was really great box with some advanced web exploitation. I’ll find a virtual subodmain in SSL certificate that contains a stray .git folder. It’ll allow me to reconstruct php files, where…

Security

8 min read

Hack the Box: Travel
Hack the Box: Travel

Nov 23, 2020

Hack the Box: Buff

Buff was an easy machine on Hack the Box. Here’s my take on solving the challenge — Buff was an easy machine on Hack the Box. Here’s my take on solving the challenge TL;DR: There’s a Gym Management Software running on HTTP port 8080. It’s vulnerable to a unauthenticated PHP file upload and therefore RCE. …

Security

3 min read

Hack the Box: Buff
Hack the Box: Buff

Oct 17, 2020

Hack the Box: Blunder

Blunder was an easy machine on Hack the Box. Here’s my take on solving the challenge — Blunder was an easy machine on Hack the Box. Here’s my take on solving the challenge User According to nmap, the webserver should be the only attack surface: There seems to be some kind of blog on the site

Hackthebox

3 min read

Hack the Box: Blunder
Hack the Box: Blunder

Sep 28, 2020

Hack the Box: Admirer

Admirer was an easy difficulty machine on Hack the Box. Here’s my take on solving the challenge. — Admirer was an easy difficulty machine on Hack the Box. Here’s my take on solving the challenge. User Nmap reveals three running services:

Hacking

3 min read

Hack the Box: Admirer
Hack the Box: Admirer

Sep 8, 2020

Hack the Box: Cascade

Cascade was a medium difficulty machine on Hack the box. Here’s my take on solving the machine — Cascade was a medium difficulty machine on Hack the box. Here’s my take on solving the machine TL;DR: There’s a public LDAP database endpoint available. One of users has a custom field that reveals it’s password. Using this access it’s possible to access a SMB share that contains a VNC…

Hacking

5 min read

Hack the Box: Cascade
Hack the Box: Cascade
Tellico Lungrevink

Tellico Lungrevink

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Knowable