0xdf.gitlab.io/2023/08/26/htb-onlyforyou.html

Preview meta tags from the 0xdf.gitlab.io website.

Linked Hostnames

21

Thumbnail

Search Engine Appearance

Google

https://0xdf.gitlab.io/2023/08/26/htb-onlyforyou.html

HTB: OnlyForYou

OnlyForYou is about exploiting Python and Neo4J. I’ll start by exploiting a Flask website file disclosure vulnerability due to a misunderstanding of the os.path.join function to get the source for another site. In that source, I’ll identify a command injection vulnerability, and figure out how bypass the filtering with a misunderstanding of the re.match function. Exploiting this returns a shell. I’ll pivot to the next user by abusing a Cypher Injection in Neo4J, and then escalate to root by exploiting an unsafe sudo rule with pip.



Bing

HTB: OnlyForYou

https://0xdf.gitlab.io/2023/08/26/htb-onlyforyou.html

OnlyForYou is about exploiting Python and Neo4J. I’ll start by exploiting a Flask website file disclosure vulnerability due to a misunderstanding of the os.path.join function to get the source for another site. In that source, I’ll identify a command injection vulnerability, and figure out how bypass the filtering with a misunderstanding of the re.match function. Exploiting this returns a shell. I’ll pivot to the next user by abusing a Cypher Injection in Neo4J, and then escalate to root by exploiting an unsafe sudo rule with pip.



DuckDuckGo

https://0xdf.gitlab.io/2023/08/26/htb-onlyforyou.html

HTB: OnlyForYou

OnlyForYou is about exploiting Python and Neo4J. I’ll start by exploiting a Flask website file disclosure vulnerability due to a misunderstanding of the os.path.join function to get the source for another site. In that source, I’ll identify a command injection vulnerability, and figure out how bypass the filtering with a misunderstanding of the re.match function. Exploiting this returns a shell. I’ll pivot to the next user by abusing a Cypher Injection in Neo4J, and then escalate to root by exploiting an unsafe sudo rule with pip.

  • General Meta Tags

    10
    • title
      HTB: OnlyForYou | 0xdf hacks stuff
    • name
      HTB: OnlyForYou
    • charset
      utf-8
    • X-UA-Compatible
      IE=edge
    • viewport
      width=device-width, initial-scale=1
  • Open Graph Meta Tags

    7
    • og:title
      HTB: OnlyForYou
    • US country flagog:locale
      en_US
    • og:description
      OnlyForYou is about exploiting Python and Neo4J. I’ll start by exploiting a Flask website file disclosure vulnerability due to a misunderstanding of the os.path.join function to get the source for another site. In that source, I’ll identify a command injection vulnerability, and figure out how bypass the filtering with a misunderstanding of the re.match function. Exploiting this returns a shell. I’ll pivot to the next user by abusing a Cypher Injection in Neo4J, and then escalate to root by exploiting an unsafe sudo rule with pip.
    • og:url
      https://0xdf.gitlab.io/2023/08/26/htb-onlyforyou.html
    • og:site_name
      0xdf hacks stuff
  • Twitter Meta Tags

    2
    • twitter:card
      summary
    • twitter:site
      @0xdf_
  • Link Tags

    11
    • alternate
      https://0xdf.gitlab.io/feed.xml
    • canonical
      https://0xdf.gitlab.io/2023/08/26/htb-onlyforyou.html
    • icon
      /assets/icons/favicon-32x32.png
    • icon
      /assets/icons/favicon-16x16.png
    • stylesheet
      /assets/css/bootstrap-toc.min.css

Emails

1

Links

63