4 :80 chiv login + SSTI
# got creds chiv:ch1VW4sHERE7331
# can use creds to login to spider.htb/login as chiv
Welcome to the admin panel, chiv.
| can submit new message
| view Messages
| View Support
http://spider.htb/view?check=messages
Staff of ID: '1' posted on: 2020-04-24 15:02:41
Fix the /a1836bb97e5f4ce6b3e8f25693c1a16c.unfinished.supportportal portal!
http://spider.htb/a1836bb97e5f4ce6b3e8f25693c1a16c.unfinished.supportportal
Submit a support ticket!
Welcome to the support portal!
| Contact # or Email:
| MessageSSTI (again)
injecting in both fields at
http://spider.htb/a1836bb97e5f4ce6b3e8f25693c1a16c.unfinished.supportportalchecking reponse at
http://spider.htb/view?check=support
Using https://hackmd.io/@Chivato/HyWsJ31dI
Using https://www.webforefront.com/django/usebuiltinjinjastatements.html
SSH User key
Last updated