In this video I demonstrate how I get into and own a vulnerable virtual machine from hackthebox.eu. This box, as its name might suggest, is vulnerable to a shellshock exploit. For those who don't know, shellshock is a vulnerability that has been laying unpublished for years, until it was released a couple of years ago. So, this exploit has been existing in unix based systems since 1989. A decent estimate would be that during all of its years of existence, the vulnerability might have been affected billions of devices. So, this vulnerable machine and its main vector of attack is based on the shellshock vulnerability. First you get a shell using a shellshock exploit and then you escalate your privileges (you get inside the machine as an unprivileged user). I hope you enjoy this video and I hope that you learn something useful from it - that will help you protect and secure the systems you manage. <center>https://www.youtube.com/watch?v=ovyJxDrB3C8</center> ___ ### <center>To stay in touch with me, follow @cristi</center> ___ [Cristi Vlad](http://cristivlad.com) Self-Experimenter and Author
author | cristi |
---|---|
permlink | walkthrough-for-shocker-a-vulnerable-machine-hackthebox |
category | cybersecurity |
json_metadata | {"community":"busy","app":"busy/2.4.0","format":"markdown","users":["cristi"],"links":["/@cristi","http://cristivlad.com"],"tags":["cybersecurity","busy","pentesting","penetration-testing","offensive-security"]} |
created | 2018-05-23 11:20:42 |
last_update | 2018-05-23 11:20:42 |
depth | 0 |
children | 1 |
last_payout | 2018-05-30 11:20:42 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 13.296 HBD |
curator_payout_value | 2.484 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 1,114 |
author_reputation | 128,305,218,872,904 |
root_title | "Walkthrough for Shocker - A Vulnerable Machine [HackTheBox]" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 57,248,800 |
net_rshares | 4,094,654,522,148 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
analisa | 0 | 417,212,186,381 | 10% | ||
pharesim | 0 | 82,808,211,808 | 0.02% | ||
donkeypong | 0 | 1,358,082,099,024 | 10% | ||
gavvet | 0 | 293,692,389,899 | 2% | ||
kevinwong | 0 | 154,335,958,253 | 2.3% | ||
dragonslayer109 | 0 | 45,379,552,915 | 2% | ||
thecryptofiend | 0 | 21,051,236,089 | 25% | ||
coinbitgold | 0 | 53,546,965,688 | 100% | ||
schro | 0 | 1,650,443,430 | 100% | ||
jacor | 0 | 1,258,174,680 | 2% | ||
jens84 | 0 | 46,333,345,091 | 25% | ||
arconite | 0 | 904,896,734 | 1.15% | ||
team-leibniz | 0 | 44,870,627,545 | 40% | ||
ace108 | 0 | 162,620,421,558 | 17% | ||
jasonstaggers | 0 | 54,990,648,994 | 25% | ||
timsaid | 0 | 10,916,688,089 | 2% | ||
cristi | 0 | 449,240,528,926 | 100% | ||
scaredycatguide | 0 | 17,926,678,091 | 24% | ||
geke | 0 | 37,889,293,669 | 50% | ||
mrtv2 | 0 | 55,450,159,735 | 100% | ||
busy.pay | 0 | 642,211,402,297 | 7.62% | ||
mitchelljaworski | 0 | 5,498,968,189 | 25% | ||
decebal2dac | 0 | 66,115,792,951 | 100% | ||
brobear1995 | 0 | 1,636,928,765 | 100% | ||
alexvan | 0 | 16,660,207,056 | 20% | ||
mandela | 0 | 11,976,451,526 | 2% | ||
veleje | 0 | 11,844,368,667 | 100% | ||
sportspodium | 0 | 6,795,596,314 | 2% | ||
viorel | 0 | 462,490,830 | 75% | ||
africaunited | 0 | 3,057,875,275 | 2% | ||
ngos | 0 | 8,165,230,472 | 2% | ||
nurhayati | 0 | 100,247,737 | 1.15% | ||
sme | 0 | 4,650,023,428 | 2% | ||
jakescvlog | 0 | 534,320,274 | 100% | ||
gordon92 | 0 | 95,968,303 | 1.15% | ||
hxr | 0 | 592,521,537 | 100% | ||
thetroublenotes | 0 | 225,612,242 | 2% | ||
brightideas | 0 | 980,357,502 | 2% | ||
jacor-witness | 0 | 367,451,751 | 2% | ||
zam398 | 0 | 1,251,396,818 | 100% | ||
filterfield | 0 | 390,953,264 | 100% | ||
scribdbloat | 0 | 90,470,549 | 100% | ||
amphora | 0 | 84,357,670 | 100% | ||
expectantfig | 0 | 92,304,338 | 100% | ||
sendingtime | 0 | 612,717,794 | 100% |
I am curious about this though. More please
author | zam398 |
---|---|
permlink | re-cristi-walkthrough-for-shocker-a-vulnerable-machine-hackthebox-20180523t141911330z |
category | cybersecurity |
json_metadata | {"tags":["cybersecurity"],"app":"steemit/0.1"} |
created | 2018-05-23 14:19:15 |
last_update | 2018-05-23 14:19:15 |
depth | 1 |
children | 0 |
last_payout | 2018-05-30 14:19:15 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 43 |
author_reputation | 10,349,188,767,982 |
root_title | "Walkthrough for Shocker - A Vulnerable Machine [HackTheBox]" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 57,274,441 |
net_rshares | 0 |