0xdf.gitlab.io/2019/08/31/htb-onetwoseven.html

Preview meta tags from the 0xdf.gitlab.io website.

Linked Hostnames

15

Search Engine Appearance

Google

https://0xdf.gitlab.io/2019/08/31/htb-onetwoseven.html

HTB: OneTwoSeven

OneTwoSeven was a very cleverly designed box. There were lots of steps, some enumeration, all of which was do-able and fun. I’ll start by finding a hosting provider that gives me SFTP access to their system. I’ll use that to tunnel into the box, and gain access to the admin panel. I’ll find creds for that using symlinks over SFTP. From there, I’ll exploit a logic error in the plugin upload to install a webshell. To get root, I’ll take advantage of my user’s ability to run apt update and apt upgrade as root, and man-in-the-middle the connection to install a backdoored package.



Bing

HTB: OneTwoSeven

https://0xdf.gitlab.io/2019/08/31/htb-onetwoseven.html

OneTwoSeven was a very cleverly designed box. There were lots of steps, some enumeration, all of which was do-able and fun. I’ll start by finding a hosting provider that gives me SFTP access to their system. I’ll use that to tunnel into the box, and gain access to the admin panel. I’ll find creds for that using symlinks over SFTP. From there, I’ll exploit a logic error in the plugin upload to install a webshell. To get root, I’ll take advantage of my user’s ability to run apt update and apt upgrade as root, and man-in-the-middle the connection to install a backdoored package.



DuckDuckGo

https://0xdf.gitlab.io/2019/08/31/htb-onetwoseven.html

HTB: OneTwoSeven

OneTwoSeven was a very cleverly designed box. There were lots of steps, some enumeration, all of which was do-able and fun. I’ll start by finding a hosting provider that gives me SFTP access to their system. I’ll use that to tunnel into the box, and gain access to the admin panel. I’ll find creds for that using symlinks over SFTP. From there, I’ll exploit a logic error in the plugin upload to install a webshell. To get root, I’ll take advantage of my user’s ability to run apt update and apt upgrade as root, and man-in-the-middle the connection to install a backdoored package.

  • General Meta Tags

    9
    • title
      HTB: OneTwoSeven | 0xdf hacks stuff
    • name
      HTB: OneTwoSeven
    • charset
      utf-8
    • X-UA-Compatible
      IE=edge
    • viewport
      width=device-width, initial-scale=1
  • Open Graph Meta Tags

    6
    • og:title
      HTB: OneTwoSeven
    • US country flagog:locale
      en_US
    • og:description
      OneTwoSeven was a very cleverly designed box. There were lots of steps, some enumeration, all of which was do-able and fun. I’ll start by finding a hosting provider that gives me SFTP access to their system. I’ll use that to tunnel into the box, and gain access to the admin panel. I’ll find creds for that using symlinks over SFTP. From there, I’ll exploit a logic error in the plugin upload to install a webshell. To get root, I’ll take advantage of my user’s ability to run apt update and apt upgrade as root, and man-in-the-middle the connection to install a backdoored package.
    • og:url
      https://0xdf.gitlab.io/2019/08/31/htb-onetwoseven.html
    • og:site_name
      0xdf hacks stuff
  • Twitter Meta Tags

    2
    • twitter:card
      summary
    • twitter:site
      @0xdf_
  • Link Tags

    11
    • alternate
      https://0xdf.gitlab.io/feed.xml
    • canonical
      https://0xdf.gitlab.io/2019/08/31/htb-onetwoseven.html
    • icon
      /assets/icons/favicon-32x32.png
    • icon
      /assets/icons/favicon-16x16.png
    • stylesheet
      /assets/css/bootstrap-toc.min.css

Emails

1

Links

38