GithubHelp home page GithubHelp logo

santosomar / yascon Goto Github PK

View Code? Open in Web Editor NEW
1.0 2.0 0.0 3 KB

This repository is to track and accept the write-up submissions for the WebSploit Labs workshop hosted by the Red Team Village during YASCON.

yascon's Introduction

WebSploit Labs workshop hosted by the Red Team Village during YASCON

This repository is to track and accept the write-up submissions for the WebSploit Labs workshop hosted by the Red Team Village during YASCON.

How to Submit Your Write-up

To submit a write up simply create an issue to this repository. The first person that submits an issue with the full write up (all vulnerabilties) in the WebSploit container created for YASCON will receive a prize.

Please feel free to ask any questions to the voluteers at the YASCON Discord Server.

yascon's People

Contributors

santosomar avatar

Stargazers

fyezool avatar

Watchers

 avatar  avatar

yascon's Issues

WebSploit Challenge Completion Submission - YASCON

about me

Hi im Arnold Prakash,im a noobie in this field the workshop was a great help for me ,please forgive my mistakes.This is my firstever write up in my life. and im using github also for the first time even though i had an account.

writeup

First lets update the docker. use this command

wget https://websploit.org/update.sh
and
bash update.sh

Screenshot (3803)
sorry for the long screenshot i didn't get time to edit it.

now lets have fun
'docker ps' to see the status
Screenshot (3808)

when everything is going right go to your browser and type
http://127.0.0.1:9002

Screenshot (3810)
the web app is ready to get abused.

while surfing through the page i saw an hash below the google maps.
Screenshot (3811)
this is a base 64 hash so lets decode it with an online decoder
Screenshot (3812)
may be this is a clue.. we should check all the directories now.
lets see....

wait what am i seeing here

Screenshot (3813)

Screenshot (3814)

is this the flag ..?

not sure im just a curious beginer. hahaha.

let's analysze this hash using any online hash analyzer.

Screenshot (3817)
its a SHA2-256 type of hash.
lets try to decode it.

i cross cheched with built-in tool of kali

Screenshot (3818)

sudo hash-decoder

just paste the hash there

Screenshot (3820)

seeing this you might feel like how can some one be so nooobbbieee hahaha i am :)

im just adding screenshot of the agrassive scan done to the ip also,i have no reason for it, i just felt like doing it.

Screenshot (3822)

flag: f15f48da327e692e8f36e583426b95edc9838bbf1382508f0044a18df59e5ddd

since there i couldnt find no other place do any xss or sql injection type acctacks im wraping up here.
thank you for reading. Happy hacking. Peace out.

contact : [email protected]

while i scaned with a tool called nikto i could find more about the server and version and its vulnerabilities.
Screenshot (2)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.