EvilCUPS
EvilCUPS is all about the recent CUPS exploits that have made a lot of news in September 2024.
Comprehensive writeups for HackTheBox machines across Easy, Medium, Hard, and Insane difficulties
Total 171 reports , currently page 6 of 18 (10 per page)
EvilCUPS is all about the recent CUPS exploits that have made a lot of news in September 2024.
1,Recon port scan ``` PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: ...
1,Recon port scan 22/tcp ssh 80/tcp http Apache httpd 2.4.58 There is a `http://instant.htb/downloads/instant.apk` for us to download this app.
1,Recon Port scan ``` PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.4p1 Debian 5+deb11u3 (protocol 2.0) | ssh-hostkey: | 3072 6...
*1, Enumerate the port and services* ``` 22/tcp ssh 80/tcp http redirect to http://monitorsthree.htb/ ```
A very good Active Directory machine, with a difficulty similar to that of the OSCP exam, which mainly requires continuous enumeration and continuous information collection at the current stage.
For the foothold, there is no way to directly use the exploit script to get the hot verse shell, and there are also rabbit holes for upload and upload, which is somewhat confusing.
1, Recon port scan ``` PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH for_Windows_9.5 (protocol 2.0) 53/tcp open domain ...
The Active Directory machine is not difficult, but the process is relatively long. It is suitable for beginners of AD environment to practice.
1,Recon port scan 22/tcp ssh `OpenSSH 8.9p1 Ubuntu 3ubuntu0.10` 80/tcp http `Apache httpd 2.4.52`