HackTheBox - Vault
01:08 - Begin of Recon
03:08 - Begin of GoBustering
07:15 - Discovery of an image upload script
08:39 - Attempting to bypass the upload filter
12:46 - Reverse Shell to ubuntu Returned. Examining Web Source
15:28 - ALTERNATIVE: Checking out the host name pollution, setting host header to localhost
19:27 - Resume of poking around the host, discover passwords and other hosts in /home
23:14 - Uploading a static-compiled nmap to the box (static-binaries is a github repo)
24:57 - SSH Local Port Forward and Dynamic, to let our Kali box communicate with the next hop.
27:27 - Discovery of a page that …
Watch on YouTube ↗
(saves to browser)
Chapters (28)
1:08
Begin of Recon
3:08
Begin of GoBustering
7:15
Discovery of an image upload script
8:39
Attempting to bypass the upload filter
12:46
Reverse Shell to ubuntu Returned. Examining Web Source
15:28
ALTERNATIVE: Checking out the host name pollution, setting host header to loca
19:27
Resume of poking around the host, discover passwords and other hosts in /home
23:14
Uploading a static-compiled nmap to the box (static-binaries is a github repo)
24:57
SSH Local Port Forward and Dynamic, to let our Kali box communicate with the n
27:27
Discovery of a page that lets us create ovpn (openvpn) configs and test the VP
28:45
Think i broke the box here, sent unicode to the box.... It stops responding on
32:55
Machine reverted, getting back to where I started.
34:50
Trying this again, and get a shell on ubuntu -- Lets do a Reverse Port Forward
36:12
Shell returned to Kali Box, explaining how to use socat if SSH Forward cannot
38:58
Exploring the DNS Server box.
39:26
Finding a password in /home/dave/ssh
40:15
Discovering Vault's IP Address in /etc/hosts
41:20
Perfoming a NMAP on the vault box, discover two ports closed
41:50
Doing a NMAP with the source port of one of the above ports to test for a lazy
43:20
ALTERNATIVE: Bypassing the firewall by using IPv6
49:47
How to set the source port with SSH via ncat
50:45
Discovering root.txt.gpg on Vault, it is encrypted with RSA Key D1EB1F03
51:35
Dave has the above RSA Key, use SCP to send the file back to Ubuntu
54:45
The file has been copied, using gpg to decrypt the file.
55:39
MAJOR UNINTENDED WAY: Discovering SPICE ports are listening on localhost:5900-
57:05
Using Remote-Viewer to connect to the SPICE Port and getting physical access t
57:42
Rebooting Vault by sending the Ctrl+Alt+delete key
58:00
Editing grub to get a root shel
Playlist
Uploads from IppSec · IppSec · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
HHC2016 - Dungeon
IppSec
HHC2016 - Terminal Speedrun
IppSec
HHC2016 - Ads
IppSec
HHC2016 - Debug
IppSec
HHC2016 - Exception
IppSec
HHC2016 - Analytics
IppSec
HHC2016 - Getting Coins
IppSec
HackTheBox - Popcorn
IppSec
HackTheBox - October
IppSec
HackTheBox - Arctic
IppSec
HackTheBox - Tenten
IppSec
HackTheBox - CronOS
IppSec
HackTheBox - Brainfuck
IppSec
HackTheBox - Beep
IppSec
HackTheBox - Bastard
IppSec
HackTheBox - Bank
IppSec
HackTheBox - Joker
IppSec
HackTheBox - Haircut
IppSec
HackTheBox - Lazy
IppSec
Camp CTF 2015 - Bitterman
IppSec
HackTheBox - Devel
IppSec
Reversing Malicious Office Document (Macro) Emotet(?)
IppSec
HackTheBox - Granny and Grandpa
IppSec
HackTheBox - Pivoting Update: Granny and Grandpa
IppSec
HackTheBox - Optimum
IppSec
HackTheBox - Charon
IppSec
HackTheBox - Sneaky
IppSec
HackTheBox - Holiday
IppSec
HackTheBox - Apocalyst
IppSec
HackTheBox - Europa
IppSec
Introduction to tmux
IppSec
HackTheBox - Blocky
IppSec
HackTheBox - Nineveh
IppSec
HackTheBox - Jail
IppSec
HackTheBox - Blue
IppSec
HackTheBox - Calamity
IppSec
HackTheBox - SolidState
IppSec
HackTheBox - Shrek
IppSec
HackTheBox - Mirai
IppSec
HackTheBox - Shocker
IppSec
HackTheBox - Mantis
IppSec
HackTheBox - Node
IppSec
HackTheBox - Kotarak
IppSec
HackTheBox - Enterprise
IppSec
HackTheBox - Sense
IppSec
HackTheBox - Minion
IppSec
VulnHub - Sokar
IppSec
VulnHub - Pinkys Palace v2
IppSec
HackTheBox - Inception
IppSec
Vulnhub - Trollcave 1.2
IppSec
HackTheBox - Ariekei
IppSec
HackTheBox - Bashed
IppSec
HackTheBox - Flux Capacitor
IppSec
HackTheBox - Jeeves
IppSec
HackTheBox - Tally
IppSec
HackTheBox - CrimeStoppers
IppSec
HackTheBox - Fulcrum
IppSec
HackTheBox - Chatterbox
IppSec
HackTheBox - Falafel
IppSec
HackTheBox - Nibbles
IppSec
DeepCamp AI