Premium Only Content
![pollution | hack the box | HTB | Malayalam | XXE](https://1a-1791.com/video/s8/1/a/6/D/z/a6Dzl.qR4e-small-pollution-hack-the-box-HTB-.jpg)
pollution | hack the box | HTB | Malayalam | XXE
Pollution is a hard linux box starts off burp history attached to a forum. Using token from the request we will be escalating to admin, and then to an endpoint vulnerable to XML external entity (XXE) injection. With that, we’ll read files, including the source code for the site to get access to redis, where we’ll modify the access at the database level. That site has a PHP local file include (LFI) that we can exploit with filter injection to get code execution. Then we will move to next user by exploiting PHP’s FastCGI Process Manager (PHP-FPM). Using prototpye pollution vulnerability we will exploit to gain root.
0:00 nmap
1:26 accessing website
1:56 discovering hostname
2:48 enumerating Vhost
4:02 Discovering Burp history
6:49 cyber chef
7:33 accessing set role admin
10:59 accessing admin page
12:57 Blind XXE
13:52 Attacking XXE
15:57 Leaking site files using XXE
20:09 cracking using john
20:55 Developers
21:38 source code for login.php
23:04 accessing redis using redis-cli
24:38 changing session access
27:00 LFI to RCE
31:40 as www-data
32:45 Rlwarp
35:45 FPM exploiting
39:23 Shell as Victor
43:04 Root
55:09 prototype pollution
Support my channel by subscribing to hack the box:
https://affiliate.hackthebox.com/29icft3zq24o
Disclaimer :
All video’s and tutorials are for informational and educational purposes only. The tutorials and videos provided there is only for those who are interested to learn about Cyber security, Penetration Testing and malware analysis. Hacking tutorials is against misuse of the information and we strongly suggest against it.
All tutorials and videos have been made using our own routers, servers, websites and other resources, they do not contain any illegal activity. We do not promote, encourage, support or excite any illegal activity or hacking without written permission in general. We want to raise security awareness and inform our readers on how to prevent themselves from being a victim of hackers. If you plan to use the information for illegal purposes, please leave this website now. We cannot be held responsible for any misuse of the given information.
1. Information provided on this Channel are for educational purposes only. This channel is no way responsible for any misuse of the information.
2. This Channel is all about ethical hacking.
3. This Channel is totally meant for providing information on “Computer Security”, “Computer Programming” and other related computer tricks and tweaks topics and is no way related towards the terms “CRACKING” or “HACKING” (Unethical).
4. I’ll include few blogs which may contain the information related to ‘Hacking Password’ or ‘Hacking email accounts’ or similar terms. You shall not misuse the information the information to gain unauthorised access. Also be aware, performing hack attempts without permission on computers that you do not own is illegal.
5. I’ll not be responsible for any direct or indirect damage caused due to the usage of the information provided on this site.
6. I reserve the right to modify the Disclaimer at any time without notice.
#parrotos
#kalilinux
#cybersecurity
#ethicalhackingmalayalam
#cybersecuritymalayalam
#xml
#XXE
-
8:34
Mike Rowe
6 days agoWhat You Didn't Hear At Pete's Confirmation Hearing | The Way I Heard It with Mike Rowe
33.1K18 -
7:13:44
TonYGaMinG
8 hours ago🟢LATEST! KINGDOM COME DELIVERANCE 2 / NEW EMOTES / BLERPS #RumbleGaming
56.7K3 -
40:17
SLS - Street League Skateboarding
4 days agoEVERY 9 CLUB IN FLORIDA! Looking back at SLS Jacksonville 2021 & 2022 - Yuto, Jagger, Sora & more...
101K1 -
2:00:47
PaddysParlorGames
17 hours agoSunday Parlor Chill: GOBSTEIN
56.1K3 -
LIVE
Major League Fishing
5 days agoLIVE! - Bass Pro Tour: Stage 2 - Day 4
167 watching -
56:24
Russell Brand
1 day agoEddie Gallagher: War, Betrayal & Fighting the System
117K13 -
11:21
TimcastIRL
9 hours agoGOP Rep Says TWO SHOOTERS In JFK Assassination As FBI Uncovers TROVE Of Secret Documents
157K197 -
1:04:55
Bare Knuckle Fighting Championship
4 days agoBKFC ITALY PRESS CONFERENCE | LIVE!
94.7K7 -
10:04
Space Ice
7 hours agoThe Movie Silent Hill Is Like Resident Evil Without The Good Parts - Worst Movie Ever
57.1K12 -
5:49
Hannah Barron
1 day agoRedneck Euro Mount
45.8K23