HackTheBox - HackBack

Support me on Patreon: 00:01:30 - Begin of Recon, discovery of an HTTP API that has a few commands 00:06:00 - Using JQ to parse json output, use NetStat/Proc to find GoPhish 00:15:00 - Logging into GoPhish with default creds admin:gophish, finding DNS Names 00:21:15 - Discovery of Obfuscated JavaScript Deobfuscating it to find a hidden section 00:33:20 - Using wfuzz to bruteforce the password for 00:37:10 - Finding Code Execution in 00:44:00 - Creating a
Back to Top