DNS Rebinding, XSS & 2FA SSH – Crossfit2 @ HackTheBox
We are solving Crossfit2, a 50-point OpenBSD machine on HackTheBox.
Topics:
• SQL Injection
• DNS Rebinding with Unbound
• XSS into Websockets
• Node Module Path
• OpenBSD Backups & Unveil
• Yubikey SSH 2FA
Join the discord: https://discord.gg/qdbJqXKPQ3 !
[ Timestamps ]
00:00 Intro
00:55 User
23:23 Root
[ Notes & Links ]
• https://www.hackthebox.eu/
[ Desktop ]
• https://github.com/xct/kali-clean
[ About ]
• https://vulndev.io
• https://twitter.com/xct_de
• https://github.com/xct
• https://www.patreon.com/xct
This is purely educational content – all practical work is done in environments that allow and encourage offensive security training.
by xct
windows server dns forwarder