HackTheBox — Writeup Pilgrimage [Retired]

This page summarizes the projects mentioned and recommended in the original post on dev.to

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • GitTools

    A repository with 3 tools for pwn'ing websites with .git repositories available

  • ┌──(root㉿kali)-[/home/…/machines-linux/pilgrimage/GitTools/Dumper] └─# ./gitdumper.sh 10.129.30.129:80/.git/ dest ../../dump ########### # GitDumper is part of https://github.com/internetwache/GitTools # # Developed and maintained by @gehaxelt from @internetwache # # Use at your own risk. Usage might be illegal in certain circumstances. # Only for educational purposes! ########### [*] Destination folder does not exist [+] Creating dest/.git/ [+] Downloaded: HEAD [-] Downloaded: objects/info/packs [+] Downloaded: description [+] Downloaded: config [+] Downloaded: COMMIT_EDITMSG [+] Downloaded: index [-] Downloaded: packed-refs [+] Downloaded: refs/heads/master [-] Downloaded: refs/remotes/origin/HEAD [-] Downloaded: refs/stash [+] Downloaded: logs/HEAD [+] Downloaded: logs/refs/heads/master [-] Downloaded: logs/refs/remotes/origin/HEAD [-] Downloaded: info/refs [+] Downloaded: info/exclude [-] Downloaded: /refs/wip/index/refs/heads/master [-] Downloaded: /refs/wip/wtree/refs/heads/master [+] Downloaded: objects/e1/a40beebc7035212efdcb15476f9c994e3634a7 [-] Downloaded: objects/00/00000000000000000000000000000000000000 [+] Downloaded: objects/f3/e708fd3c3689d0f437b2140e08997dbaff6212 [+] Downloaded: objects/93/ed6c0458c9a366473a6bcb919b1033f16e7a8d [+] Downloaded: objects/c2/cbe0c97b6f3117d4ab516b423542e5fe7757bc [+] Downloaded: objects/6c/965df00a57fd13ad50b5bbe0ae1746cdf6403d [+] Downloaded: objects/dc/446514835fe49994e27a1c2cf35c9e45916c71 [+] Downloaded: objects/46/44c40a1f15a1eed9a8455e6ac2a0be29b5bf9e [+] Downloaded: objects/f1/8fa9173e9f7c1b2f30f3d20c4a303e18d88548 [+] Downloaded: objects/c4/18930edec4da46019a1bac06ecb6ec6f7975bb [+] Downloaded: objects/36/c734d44fe952682020fd9762ee9329af51848d [+] Downloaded: objects/b2/15e14bb4766deff4fb926e1aa080834935d348 [+] Downloaded: objects/8f/155a75593279c9723a1b15e5624a304a174af2 [+] Downloaded: objects/9e/ace5d0e0c82bff5c93695ac485fe52348c855e [+] Downloaded: objects/a7/3926e2965989a71725516555bcc1fe2c7d4f9e [+] Downloaded: objects/98/10e80fba2c826a142e241d0f65a07ee580eaad [+] Downloaded: objects/26/8dbf75d02f0d622ac4ff9e402175eacbbaeddd [+] Downloaded: objects/81/703757c43fe30d0f3c6157a1c20f0fea7331fc [+] Downloaded: objects/76/a559577d4f759fff6af1249b4a277f352822d5 [+] Downloaded: objects/ff/dbd328a3efc5dad2a97be47e64d341d696576c [+] Downloaded: objects/f2/b67ac629e09e9143d201e9e7ba6a83ee02d66e [+] Downloaded: objects/8a/62aac3b8e9105766f3873443758b7ddf18d838 [+] Downloaded: objects/e9/2c0655b5ac3ec2bfbdd015294ddcbe054fb783 [+] Downloaded: objects/c2/a4c2fd4e5b2374c6e212d1800097e3b30ff4e2 [+] Downloaded: objects/88/16d69710c5d2ee58db84afa5691495878f4ee1 [+] Downloaded: objects/96/3349e4f7a7a35c8f97043c20190efbe20d159a [+] Downloaded: objects/2f/9156e434cfa6204c9d48733ee5c0d86a8a4e23 [+] Downloaded: objects/b6/c438e8ba16336198c2e62fee337e126257b909 [+] Downloaded: objects/11/dbdd149e3a657bc59750b35e1136af861a579f [+] Downloaded: objects/c3/27c2362dd4f8eb980f6908c49f8ef014d19568 [+] Downloaded: objects/8e/42bc52e73caeaef5e58ae0d9844579f8e1ae18 [+] Downloaded: objects/5f/ec5e0946296a0f09badeb08571519918c3da77 [+] Downloaded: objects/50/210eb2a1620ef4c4104c16ee7fac16a2c83987 [+] Downloaded: objects/06/19fc1c747e6278bbd51a30de28b3fcccbd848a [+] Downloaded: objects/54/4d28df79fe7e6757328f7ecddf37a9aac17322 [+] Downloaded: objects/1f/8ddab827030fbc81b7cb4441ec4c9809a48bc1 [+] Downloaded: objects/47/6364752c5fa7ad9aa10f471dc955aac3d3cf34 [+] Downloaded: objects/b4/21518638bfb4725d72cc0980d8dcaf6074abe7 [+] Downloaded: objects/49/cd436cf92cc28645e5a8be4b1973683c95c537 [+] Downloaded: objects/1f/2ef7cfabc9cf1d117d7a88f3a63cadbb40cca3 [+] Downloaded: objects/23/1150acdd01bbbef94dfb9da9f79476bfbb16fc [+] Downloaded: objects/ca/d9dfca08306027b234ddc2166c838de9301487 [+] Downloaded: objects/fd/90fe8e067b4e75012c097a088073dd1d3e75a4 [+] Downloaded: objects/c4/3565452792f19d2cf2340266dbecb82f2a0571 [+] Downloaded: objects/29/4ee966c8b135ea3e299b7ca49c450e78870b59 [+] Downloaded: objects/fb/f9e44d80c149c822db0b575dbfdc4625744aa4 [+] Downloaded: objects/2b/95e3c61cd8f7f0b7887a8151207b204d576e14 [+] Downloaded: objects/a5/29d883c76f026420aed8dbcbd4c245ed9a7c0b [-] Downloaded: objects/23/12310101010101010101410301010101210101 [-] Downloaded: objects/23/03032323230123232323212123212303632303 [-] Downloaded: objects/23/21236303230321632123036767012147470701 [-] Downloaded: objects/47/07412547250503474341056701016565070147 [-] Downloaded: objects/41/61416543747052570741470565674701054165 [-] Downloaded: objects/65/43450543454147054147414565014170505650 [-] Downloaded: objects/54/74547454747476767476767676767236323632 [-] Downloaded: objects/36/76745054545454545456545454545454545454 [-] Downloaded: objects/76/76701676767670105676767672167676767010 [+] Downloaded: objects/cd/2774e97bfe313f2ec2b8dc8285ec90688c5adb [+] Downloaded: objects/fa/175a75d40a7be5c3c5dee79b36f626de328f2e ┌──(root㉿kali)-[~kali/…/pilgrimage/GitTools/Dumper/dest] └─# git checkout -- D assets/bulletproof.php D assets/css/animate.css D assets/css/custom.css D assets/css/flex-slider.css D assets/css/fontawesome.css D assets/css/owl.css D assets/css/templatemo-woox-travel.css D assets/images/banner-04.jpg D assets/images/cta-bg.jpg D assets/js/custom.js D assets/js/isotope.js D assets/js/isotope.min.js D assets/js/owl-carousel.js D assets/js/popup.js D assets/js/tabs.js D assets/webfonts/fa-brands-400.ttf D assets/webfonts/fa-brands-400.woff2 D assets/webfonts/fa-regular-400.ttf D assets/webfonts/fa-regular-400.woff2 D assets/webfonts/fa-solid-900.ttf D assets/webfonts/fa-solid-900.woff2 D assets/webfonts/fa-v4compatibility.ttf D assets/webfonts/fa-v4compatibility.woff2 D dashboard.php D index.php D login.php D logout.php D magick D register.php D vendor/bootstrap/css/bootstrap.min.css D vendor/bootstrap/js/bootstrap.min.js D vendor/jquery/jquery.js D vendor/jquery/jquery.min.js D vendor/jquery/jquery.min.map D vendor/jquery/jquery.slim.js D vendor/jquery/jquery.slim.min.js D vendor/jquery/jquery.slim.min.map

  • CVE-2022-44268

    A PoC for the CVE-2022-44268 - ImageMagick arbitrary file read

  • GitHub - voidz0r/CVE-2022-44268: A PoC for the CVE-2022-44268 - ImageMagick arbitrary file read

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • imagemagick-lfi-poc

    ImageMagick LFI PoC [CVE-2022-44268]

  • GitHub - Sybil-Scan/imagemagick-lfi-poc: ImageMagick LFI PoC [CVE-2022-44268]

  • ImageMagick

    🧙‍♂️ ImageMagick 7

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts