HackTheBox - Dog @ippsec
HackTheBox - Dog  @ippsec
Uploaded July 2025 | Updated September 2026, 3 weeks ago
00:00 - Introduction
00:57 - Start of nmap, discovering an open .git directory
04:15 - Using git-dumper to download the source code and discovering MySQL credentials
06:00 - Trying to enumerate usernames but running into bruteforce protection in the login and reset password functionality
12:45 - Looking for other ways to enumerate users, finding BackDropScan which shows another endpoint which is unprotected
17:00 - Logging into backdrop, then installing a malicious module
21:00 - Getting a shell on the box and then password re-use lets us switch to a different user
24:45 - We can run Bee with Sudo, finding out it has an eval command that lets us run commands
28:20 - Showing another way to find valid users, searching the git files for emails and getting tiffany.
HackTheBox - DogHackTheBox - ResourceHackTheBox - VisualHackTheBox - AirTouchHackTheBox - SorceryHackTheBox - CompiledHackTheBox - PilgrimageHackTheBox - OutboundAnalyzing auth.log and Playing with Grok Filters - HTB Sherlocks - BrutusHackTheBox - AxlleHackTheBox - UsageHackTheBox - Signed
IppSec |

HackTheBox - Dog

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER