A detailed walkthrough of the HackTheBox machine 'Gavel', a Linux box running a PHP auction website. The attack chain involves recovering source code from an exposed .git directory using git-dumper, exploiting a novel SQL injection that bypasses PDO's backtick-quoted prepared statements, cracking a bcrypt hash to access the

1h 36m read timeFrom 0xdf.gitlab.io
Post cover image
Table of contents
Box InfoReconShell as www-dataShell as auctioneerShell as rootBeyond Root - tmp Sandboxes

Sort: