HackTheBox - CozyHosting @ippsec
HackTheBox - CozyHosting  @ippsec
Uploaded March 2024 | Updated September 2026, 2 weeks ago
00:00 - Introduction
01:00 - Start of nmap
03:10 - Identify JSESSIONID with nginx, but nginx appears to be configured correctly
06:00 - Googling the error message to identify the page uses SpringBoot, using a SpringBoot wordlist to find actuators!
10:30 - Using the Sessions Actuator and seeing a session for kanderson, logging in to get to the admin interface
14:15 - Finding RCE in the ExecSSH Page
23:20 - Shell on CozyHosting, looking at running services
26:00 - Examining the CozyHosting Jar to identify PostGres credentials then dumping the users table and cracking hashes
33:00 - Josh can run SSH with sudo, using proxy command to get root
34:10 - Explaining what ProxyCommand is
HackTheBox - CozyHostingHackTheBox - AnalyticsGolang for Hackers - LDAP Injector - Episode 04 - Functional Options PatternHackTheBox - UniversityHackTheBox - KoboldConfiguring Iptables/UFW and Auditd with AnsibleHackTheBox - AbsoluteHackTheBox   RegistryTwoHackTheBox - CraftyHackTheBox - OnlyForYouHackTheBox - BagelHackTheBox - Nocturnal
IppSec |

HackTheBox - CozyHosting

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER