Post

HackTheBox_Nibbles w/o Metasploit

HTB - Nibbles

Image

Enumeration

Nmap Scan Results

Image

Homepage

Image

Source Code

Image

Nibbleblog Directory

Image

Dirbusting Results

Image

Content Page

Image

Users File

Image

Admin Username

Image

Admin Login

Image

Vulnerabilities

Nibbleblog v4.0.3

File injection multi/http/nibble_file_upload

Exploitation Without Metasploit

PHP Exploit Upload

Image

Attempting Exploit

Image

Image

Reverse Shell Script

After uploading the file, visit:

1
http://10.10.10.75/nibbleblog/content/private/plugins/my_image/image.php?cmd=id

Reverse Shell

Image

Upgrading Shell

Image

Sudo Privileges

Running sudo -l reveals script with root privileges:

Image

Script Path

Image

Adding Reverse Shell

Image

Root flag:

Image

User flag:

Image

This post is licensed under CC BY 4.0 by the author.

Comments powered by Disqus.