xsspresso
xsspresso
Tags/ Cron

Cron

5 writeups tagged with Cron

WebEasyLinux

HTB — Planning

Grafana SSRF pivots to an internal Grafana instance. Credential reuse for SSH, then environment variable injection via root cron.

#Grafana#SSRF#Cron
May 31, 2025HackTheBox
WebEasyLinux

HTB — Networked

PHP file upload bypass with double extension and MIME spoofing. Cron-executed user script for lateral move, ifcfg privesc to root.

#File Upload#PHP#Cron
Apr 26, 2022HackTheBox
MiscMediumLinux

HTB — Solidstate

Apache James 2.3.2 arbitrary file read leaks user creds. Root via world-writable cron script executed by root.

#SMTP#James#File Read
Apr 2, 2022HackTheBox
WebMediumLinux

HTB — Cronos

DNS zone transfer reveals hidden vhosts. SQL injection login bypass, OS command injection for shell, cron privesc.

#DNS#SQLi#Command Injection
Mar 27, 2022HackTheBox
WebEasyLinux

HTB — Bashed

phpbash webshell discovered via directory fuzzing. Lateral movement through sudo scriptmanager, cron-based root.

#Webshell#Fuzzing#Cron
Mar 24, 2022HackTheBox