Myvideo

Guest

Login

HackTheBox - Bucket

Uploaded By: Myvideo
6 views
0
0 votes
0

00:00 - Intro 00:57 - Start of nmap discovering the HTTP Site 03:30 - Poking at the website, using the developer console to discover 05:00 - Using curl to view HTTP Headers and discovering amazon 05:30 - Oh god... I forgot to edit the URL in this gobuster! Actually created a feature request in GoBuster to fix this mistake from happening. 05:45 - Installing AWS CLI 06:30 - Using the aws to connect to a custom endpoint, then configure credentials 07:30 - Exploring the S3 Bucket 09:25 - Using S3 to add a reverse shell to the website 11:15 - Reverse Shell returned, spending some time to start taking notes. 16:30 - End of notes, poking around on the terminal to find 19:00 - Discovering some weird ports, checking the apache configuration to see if they are related 20:55 - The Apache mpm_itk_module specifies the site is running as root and not www-data 23:50 - Poking at DynamoDB to get user credentials 26:10 - Doing some jq fu to get exactly the

Share with your friends

Link:

Embed:

Video Size:

Custom size:

x

Add to Playlist:

Favorites
My Playlist
Watch Later