Premium Only Content

pollution | hack the box | HTB | Malayalam | XXE
Pollution is a hard linux box starts off burp history attached to a forum. Using token from the request we will be escalating to admin, and then to an endpoint vulnerable to XML external entity (XXE) injection. With that, we’ll read files, including the source code for the site to get access to redis, where we’ll modify the access at the database level. That site has a PHP local file include (LFI) that we can exploit with filter injection to get code execution. Then we will move to next user by exploiting PHP’s FastCGI Process Manager (PHP-FPM). Using prototpye pollution vulnerability we will exploit to gain root.
0:00 nmap
1:26 accessing website
1:56 discovering hostname
2:48 enumerating Vhost
4:02 Discovering Burp history
6:49 cyber chef
7:33 accessing set role admin
10:59 accessing admin page
12:57 Blind XXE
13:52 Attacking XXE
15:57 Leaking site files using XXE
20:09 cracking using john
20:55 Developers
21:38 source code for login.php
23:04 accessing redis using redis-cli
24:38 changing session access
27:00 LFI to RCE
31:40 as www-data
32:45 Rlwarp
35:45 FPM exploiting
39:23 Shell as Victor
43:04 Root
55:09 prototype pollution
Support my channel by subscribing to hack the box:
https://affiliate.hackthebox.com/29icft3zq24o
Disclaimer :
All video’s and tutorials are for informational and educational purposes only. The tutorials and videos provided there is only for those who are interested to learn about Cyber security, Penetration Testing and malware analysis. Hacking tutorials is against misuse of the information and we strongly suggest against it.
All tutorials and videos have been made using our own routers, servers, websites and other resources, they do not contain any illegal activity. We do not promote, encourage, support or excite any illegal activity or hacking without written permission in general. We want to raise security awareness and inform our readers on how to prevent themselves from being a victim of hackers. If you plan to use the information for illegal purposes, please leave this website now. We cannot be held responsible for any misuse of the given information.
1. Information provided on this Channel are for educational purposes only. This channel is no way responsible for any misuse of the information.
2. This Channel is all about ethical hacking.
3. This Channel is totally meant for providing information on “Computer Security”, “Computer Programming” and other related computer tricks and tweaks topics and is no way related towards the terms “CRACKING” or “HACKING” (Unethical).
4. I’ll include few blogs which may contain the information related to ‘Hacking Password’ or ‘Hacking email accounts’ or similar terms. You shall not misuse the information the information to gain unauthorised access. Also be aware, performing hack attempts without permission on computers that you do not own is illegal.
5. I’ll not be responsible for any direct or indirect damage caused due to the usage of the information provided on this site.
6. I reserve the right to modify the Disclaimer at any time without notice.
#parrotos
#kalilinux
#cybersecurity
#ethicalhackingmalayalam
#cybersecuritymalayalam
#xml
#XXE
-
2:18:15
Side Scrollers Podcast
20 hours agoBlizzard BANS Player for Saying “n00b” + Cracker Barrel Ends PRIDE Funding + MORE | Side Scrollers
53.3K27 -
19:54
GritsGG
16 hours agoMAX SR Win on Warzone! Ranked Tips for Loadout & Landing Spot!
15.7K -
LIVE
Lofi Girl
2 years agoSynthwave Radio 🌌 - beats to chill/game to
308 watching -
44:41
Inverted World Live
15 hours agoPolitical Violence in Minnesota w/ AK Kamara
168K19 -
6:29:40
SpartakusLIVE
14 hours ago#1 Massive MEAT-HEAD can't stop WINNING, can't stop FLEXING
89.1K -
5:09:25
Drew Hernandez
15 hours agoGIDEON AI THREAT DETECTION SOFTWARE PUSH & NEW EPSTEIN EMAIL LEAK?
61.2K27 -
2:03:51
TimcastIRL
11 hours agoTrans Minneapolis Shooter BLAMED Massacre On Mom & Gender Transition | Timcast IRL
200K379 -
47:29
Man in America
18 hours agoIT DOESN'T ADD UP: The Trans Shooter's Story Is FULL of Holes
67.6K85 -
3:59:36
StevieTLIVE
11 hours agoFriday Night Warzone HYPE
50.5K1 -
3:47:10
SynthTrax & DJ Cheezus Livestreams
1 day agoFriday Night Synthwave 80s 90s Electronica and more DJ MIX Livestream Michael Jackson / AI Art Compilation Edition
56K2