HackTheBox: Editorial

Enumeration 1 export target=10.129.50.62 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target -oN nmap_editorial Add it to the /etc/hosts 1 echo '10.129.50.62 editorial.htb' | sudo tee -a /etc/hosts Web Application (80) There is a book upload page I’ve tried to upload a php file VHost fuzzing, no luck There is a cover URL we can provide, try SSRF: ...

August 17, 2026 · 3 min · 445 words · burkocyigit

HackTheBox: Dog

Enumeration 1 export target=10.129.231.223 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target Add dog.htb to hosts Nmap says there is are git repo found. Let’s download it. 1 wget -r -np -R "index.html*" http://$target Looking around, I find the mysql password of root 1 BackDropJ2024DS2024 Found another user in the repo: 1 tiffany Web Application (80) Blog, powered by Backdrop CMS ...

August 12, 2026 · 2 min · 255 words · burkocyigit

HackTheBox: Busqueda

Enumeration 1 export target=10.129.47.156 Port Scanning Add the domain to hosts: 1 sudo nano /etc/hosts Web Application (port 80) We see some kind of search engine: We see a version info on the footer: Searchor 2.4.0. Let’s search it if it is vulnerable. After googling, we find out that there is a CVE (CVE-2023-43364) with a public exploit PoC. https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection Download the PoC: 1 git clone https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection.git ...

August 10, 2026 · 2 min · 299 words · burkocyigit