create account

Walkthrough for Shocker - A Vulnerable Machine [HackTheBox] by cristi

View this thread on: hive.blogpeakd.comecency.com
· @cristi ·
$15.78
Walkthrough for Shocker - A Vulnerable Machine [HackTheBox]
In this video I demonstrate how I get into and own a vulnerable virtual machine from hackthebox.eu. This box, as its name might suggest, is vulnerable to a shellshock exploit.

For those who don't know, shellshock is a vulnerability that has been laying unpublished for years, until it was released a couple of years ago. So, this exploit has been existing in unix based systems since 1989. 

A decent estimate would be that during all of its years of existence, the vulnerability might have been affected billions of devices. So, this vulnerable machine and its main vector of attack is based on the shellshock vulnerability. 

First you get a shell using a shellshock exploit and then you escalate your privileges (you get inside the machine as an unprivileged user). I hope you enjoy this video and I hope that you learn something useful from it - that will help you protect and secure the systems you manage. 

<center>https://www.youtube.com/watch?v=ovyJxDrB3C8</center>
___
### <center>To stay in touch with me, follow @cristi</center>   
___
[Cristi Vlad](http://cristivlad.com) Self-Experimenter and Author
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
properties (23)
authorcristi
permlinkwalkthrough-for-shocker-a-vulnerable-machine-hackthebox
categorycybersecurity
json_metadata{"community":"busy","app":"busy/2.4.0","format":"markdown","users":["cristi"],"links":["/@cristi","http://cristivlad.com"],"tags":["cybersecurity","busy","pentesting","penetration-testing","offensive-security"]}
created2018-05-23 11:20:42
last_update2018-05-23 11:20:42
depth0
children1
last_payout2018-05-30 11:20:42
cashout_time1969-12-31 23:59:59
total_payout_value13.296 HBD
curator_payout_value2.484 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,114
author_reputation128,305,218,872,904
root_title"Walkthrough for Shocker - A Vulnerable Machine [HackTheBox]"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id57,248,800
net_rshares4,094,654,522,148
author_curate_reward""
vote details (45)
@zam398 ·
I am curious about this though. More please
properties (22)
authorzam398
permlinkre-cristi-walkthrough-for-shocker-a-vulnerable-machine-hackthebox-20180523t141911330z
categorycybersecurity
json_metadata{"tags":["cybersecurity"],"app":"steemit/0.1"}
created2018-05-23 14:19:15
last_update2018-05-23 14:19:15
depth1
children0
last_payout2018-05-30 14:19:15
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length43
author_reputation10,349,188,767,982
root_title"Walkthrough for Shocker - A Vulnerable Machine [HackTheBox]"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id57,274,441
net_rshares0