Bank WriteUp
Recon/Scanning
Server headers show its an Ubuntu box

NMAP:

Adding bank.htb to your hosts file will reveal a login page

Tried SQLi with no success…
/index.php (Status: 302)
/uploads (Status: 301)
/support.php (Status: 302)
/login.php (Status: 200)
/assets (Status: 301)
/logout.php (Status: 302)
/inc (Status: 301)
So many re-directs…
Lets “dig” around with DNS, TCP DNS usually means we can zone transfer…

We got a few other names we can add to hosts file


Gaining Access
Started dirsearch in the background, lets enumerate more on HTTP
After playing around with the redirects in Burp, I was able to bypass the redirect


Lets try to bypass with a simple rename and exiftool
After failing and failing, I found this…

After changing ext…


Privilege Escalation
Inside the inc directory, the user.php has MySQL creds…


No luck!

We have write access to passwd… we can get priv esc thru this but instead found a SUID bit binary called emergency

We hacked Bank! Great box