HackTheBox: CozyHosting

Enumeration 1 export target=10.129.229.88 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target Add cozyhosting.htb to hosts 1 echo "10.129.229.88 cozyhosting.htb" | sudo tee -a /etc/hosts Web Application (80) Portfolio page There is a login page as well: Vhost fuzz 1 ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-20000.txt -u http://cozyhosting.htb/ -H 'Host: FUZZ.cozyhosting.htb' --ac Nothing shows up. Directory Search 1 dirsearch -u http://cozyhosting.htb/ A lot of output, but the actuator is interesting: ...

August 11, 2026 Β· 2 min Β· 276 words Β· burkocyigit

HackTheBox: Busqueda

Enumeration 1 export target=10.129.47.156 Port Scanning Add the domain to hosts: 1 sudo nano /etc/hosts Web Application (port 80) We see some kind of search engine: We see a version info on the footer: Searchor 2.4.0. Let’s search it if it is vulnerable. After googling, we find out that there is a CVE (CVE-2023-43364) with a public exploit PoC. https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection Download the PoC: 1 git clone https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection.git ...

August 10, 2026 Β· 2 min Β· 299 words Β· burkocyigit