00:00 - Introduction
00:56 - Start of nmap
02:15 - Running Gobuster in VHOST Detection mode to find the dev subdomain
03:50 - Intercepting a request to and seeing an cookie and x-powered-by header saying express, both indicating it uses NodeJS/Express
05:00 - Explaining why I’m trying these injections
07:00 - Bypassing login with mongodb injection by setting both username and password to not equals instead of equals
09:10 - Playing with the e-commerce store and seeing it gives us a PDF
10:45 - Using exiftool to see how the PDF was generated
12:05 - Inserting an HTML IFRAME when we purchase an item to see if the PDF Generated will include local files
17:00 - Extracting /var/www/dev/ and getting the mongodb password which lets us log into the server
19:50 - The order numbers don’t appear to be that random, looking at the source code to identify how this is generated. It’s just mongo’s object ID which is heavily based upon time st
5 views
219
76
4 months ago 00:10:23 1
I Played HackTheBox For 30 Days - Here’s What I Learned
7 months ago 00:00:00 1
Хакерство для всех: понятные инструкции для начинающих | Иван Глинкин HydrAttack
9 months ago 00:04:06 1
Решаем “Тред Ариадны“ | TINKOFF CTF 2024 | EASY
9 months ago 00:32:44 18
HackTheBox - Analytics
9 months ago 00:34:38 2
HackTheBox - Manager
9 months ago 01:27:34 5
HackTheBox - AppSanity
9 months ago 00:37:18 6
HackTheBox - CozyHosting
9 months ago 00:41:25 5
HackTheBox - Visual
9 months ago 01:46:13 2
HackTheBox - Drive
9 months ago 01:12:42 4
HackTheBox - Builder
9 months ago 00:26:29 1
HackTheBox - Keeper
9 months ago 02:06:46 2
HackTheBox RegistryTwo
9 months ago 00:54:43 11
HackTheBox - Clicker
9 months ago 02:05:30 1
HackTheBox - Bookworm
10 months ago 00:33:44 1
Best Hacking Laptop 2023
10 months ago 00:27:16 1
Top Hacking Books for 2023
10 months ago 00:30:39 1
Прохождение Linux-машины средней сложности SANDWORM HackTheBox | КАК ПРОЙТИ
11 months ago 11:21:04 1
Bug Bounty Course 2024 Updated
1 year ago 05:30:24 3
George Hotz | Programming | Hack The Box | ctf practice for skill (should tomcr00se return?)
1 year ago 01:02:06 17
HackTheBox Zipping
1 year ago 00:16:21 18
HackTheBox - Sau
1 year ago 02:09:39 15
HackTheBox - Coder
1 year ago 00:29:19 2
Прохождение Linux-машины средней сложности SURVEILLANCE HackTheBox | КАК ПРОЙТИ