Skills Assessment
Scenario
In-Scope Subdomains
Target
Local Port
Setup /etc/hosts
sudo tee -a /etc/hosts > /dev/null <<EOT
## inlanefreight hosts
<Target_IP> library.inlanefreight.local vault.inlanefreight.local webmin.inlanefreight.local pdf.inlanefreight.local
EOTQuestion 1: Library Web Application Flag
Vulnerability: WebSocket SQLi
Exploitation
Question 2: htb-stdnt Password
Exploitation
Question 3: Vault Admin Password
Vulnerability: Second-Order IDOR
Exploitation
Question 4: PDF Application Flag
Vulnerability: DNS Rebinding SSRF Bypass
Step 1: Access Webmin
Step 2: Change DNS Settings
Step 3: Setup DNSrebinder
Step 4: Exploit
Attack Chain Summary
Last updated