HackTheBox - Compiled @ippsec
HackTheBox - Compiled  @ippsec
Uploaded December 2024 | Updated September 2026, 2 weeks ago
00:00 - Introduction
01:00 - Start of nmap
03:20 - Entering our IP Address into the website and viewing the request within NC to see the useragent (git/2.45.0.windows.1)
06:50 - Going over CVE-2024-32002 which is a RCE within Git on case insensitive file systems
12:00 - Creating the malicious git project
21:15 - Our exploit didn't work, editing the post hook to be a base64 encoded powershell reverse shell
27:15 - Reverse shell returned downloading the Gitea database
31:00 - Looking at how gitea formats the PBKDF2 hash, converting it to a hashcat format
37:00 - Creating a python script to dump hashes from a gitea database in hashcat format
47:25 - Shell as Emily, discovering Visual Studio version
51:00 - Going over CVE-2024-20656 which is a privesc within Visual Studio
58:00 - Going over the code, editing it to send us a reverse shell
1:06:25 - Exploit didn't work, going back over the code and discovering it has the wrong path for visual studio
HackTheBox - CompiledHackTheBox - PilgrimageHackTheBox - OutboundAnalyzing auth.log and Playing with Grok Filters - HTB Sherlocks - BrutusHackTheBox - AxlleHackTheBox - UsageHackTheBox - SignedHackTheBox - MonitorsTwoHackTheBox - PollutionHackTheBox - BackfireHackTheBox - BrowsedHackTheBox - Trickster
IppSec |

HackTheBox - Compiled

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER