<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hackthebox on shibajutsu</title><link>https://blog.shiba.onl/tags/hackthebox/</link><description>Recent content in Hackthebox on shibajutsu</description><generator>Hugo</generator><language>vn</language><copyright>© shibajutsu</copyright><lastBuildDate>Wed, 09 Jul 2025 00:03:00 +0700</lastBuildDate><atom:link href="https://blog.shiba.onl/tags/hackthebox/index.xml" rel="self" type="application/rss+xml"/><item><title>CachedWeb - Hackthebox challenge</title><link>https://blog.shiba.onl/posts/cachedweb/</link><pubDate>Wed, 09 Jul 2025 00:03:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/cachedweb/</guid><description>CachedWeb {% embed url=&amp;ldquo;https://app.hackthebox.com/challenges/503&amp;quot; %}
Application Overview Truy cập trang thấy 1 form take screenshot từ url và lưu lại.
Trong thư mục blueprints @api.route(&amp;#34;/cache&amp;#34;, methods=[&amp;#34;POST&amp;#34;]) def cache(): if not request.is_json or &amp;#34;url&amp;#34; not in request.json: return abort(400) return cache_web(request.json[&amp;#34;url&amp;#34;]) Hàm cache_web:
def cache_web(url): domain = urlparse(url).hostname scheme = urlparse(url).scheme if not domain or not scheme: return flash(f&amp;#39;Malformed url {url}&amp;#39;, &amp;#39;danger&amp;#39;) elif not is_scheme_allowed(scheme): return flash(f&amp;#39;Scheme {scheme} is not allowed&amp;#39;, &amp;#39;danger&amp;#39;) elif not is_domain_allowed(domain): return flash(f&amp;#39;Domain {domain} is not allowed&amp;#39;, &amp;#39;danger&amp;#39;) elif cache.</description></item><item><title>Stylish - Hackthebox challenge</title><link>https://blog.shiba.onl/posts/stylish/</link><pubDate>Mon, 09 Jun 2025 00:01:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/stylish/</guid><description>Stylish Dạo đầu Tìm điểm G Đầu tiên thì cứ phải quan sát để phân tích xem khai thác vào đâu.
Vì challenges cung cấp cả mã nguồn nền sẽ dễ dàng hơn.
Cái website nó trông thế này
Tổng quan thì đây là một trang web cho phép ta upload 1 đoạn CSS lên xong sẽ có con bot admin nó review gì gì đó.
Ngó qua file database.js thì thấy rõ mục tiêu là đọc flag trong database thông qua lỗ hổng SQL Injection.</description></item><item><title>Builder - Hackthebox machine</title><link>https://blog.shiba.onl/posts/builder/</link><pubDate>Mon, 09 Jun 2025 00:00:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/builder/</guid><description>Builder Writeups này có sự tham khảo từ 0xdf và ippsec.
Machine link
Recon nmap sudo nmap -sC -sV nmap 10.10.11.10 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-05-13 22:05 +07 Nmap scan report for 10.10.11.10 (10.10.11.10) Host is up (0.49s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.6 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 3e:ea:45:4b:c5:d1:6d:6f:e2:d4:d1:3b:0a:3d:a9:4f (ECDSA) |_ 256 64:cc:75:de:4a:e6:a5:b4:73:eb:3f:1b:cf:b4:e3:94 (ED25519) 8080/tcp open http Jetty 10.</description></item><item><title>HTB Proxy - Hackthebox challenge</title><link>https://blog.shiba.onl/posts/htb-proxy/</link><pubDate>Wed, 14 May 2025 00:02:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/htb-proxy/</guid><description>HTB Proxy https://github.com/hackthebox/business-ctf-2024/
Application Overview localhost:1337
Truy cập vào /server-status cho phép ta xem được thông tin về machine.
/server-status
Phân tích source code ├── build_docker.sh ├── challenge │ ├── backend │ │ ├── index.js │ │ └── package.json │ └── proxy │ ├── go.mod │ ├── includes │ │ └── index.html │ └── main.go ├── config │ └── supervisord.conf ├── Dockerfile ├── entrypoint.sh ├── flag.txt Trong Dockerfile ta thấy được 1 vài thông tin như công nghệ machine sử dụng (nodejs, go, &amp;hellip;) và các config cơ bản khác như mọi CTF challenges khác.</description></item></channel></rss>