<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xmlns:xhtml="http://www.w3.org/1999/xhtml">
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2025-01-14</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/api-interaction</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-14</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/9d5bb784-55fa-42b9-ac59-b9a90cedfc22/Screenshot+2025-01-14+at+1.56.45%E2%80%AFPM.png</image:loc>
      <image:title>So You Wanna Be A Hacker - API Interaction - Make it stand out</image:title>
      <image:caption>It worked.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/44964993-34dc-4aca-8a73-661e1f1d79aa/Screenshot+2025-01-14+at+2.07.43%E2%80%AFPM.png</image:loc>
      <image:title>So You Wanna Be A Hacker - API Interaction - Make it stand out</image:title>
      <image:caption>Detroit now changed to Dallas</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/90f4239e-7d0a-4ff0-96a1-ab3cc628da70/Screenshot+2025-01-14+at+1.43.04%E2%80%AFPM.png</image:loc>
      <image:title>So You Wanna Be A Hacker - API Interaction - Make it stand out</image:title>
      <image:caption>Json text</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/672dcb8e-279f-4a9f-a4b5-a1839d582eff/Screenshot+2025-01-14+at+1.51.50%E2%80%AFPM.png</image:loc>
      <image:title>So You Wanna Be A Hacker - API Interaction - Make it stand out</image:title>
      <image:caption>POST: Creating a new entry</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/880deacf-e369-4cfc-bd85-8273294deb75/Screenshot+2025-01-14+at+2.07.06%E2%80%AFPM.png</image:loc>
      <image:title>So You Wanna Be A Hacker - API Interaction - Make it stand out</image:title>
      <image:caption>PUT request</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/8e012841-b8d3-48e3-ac05-80ded07ac779/Screenshot+2025-01-14+at+1.44.41%E2%80%AFPM.png</image:loc>
      <image:title>So You Wanna Be A Hacker - API Interaction - Make it stand out</image:title>
      <image:caption>formatted json</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/59a4b388-a473-4981-ab19-c64fb209bf8c/Screenshot+2025-01-14+at+2.08.47%E2%80%AFPM.png</image:loc>
      <image:title>So You Wanna Be A Hacker - API Interaction - Make it stand out</image:title>
      <image:caption>DELETE on London</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/http-response-status-codes</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-07</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/lets-curl-in-cyberspace</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-12-05</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/analytics-htb</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-06</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/blog-post-title-three-ntmsm</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-06</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/9c18868e-bae7-4644-9189-ea2f724e5404/Pasted+image+20240302011305.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>Now isn’t that way prettier? If you scroll down you will see the password nicely stored for your viewing pleasure. I immediately tried to use the creds for ssh that we found in our nmap scan. That failed but we had the admin page so I logged in there and it worked like a charm.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/e8dab1b8-fa90-4016-9aad-f5de8e74b418/Pasted+image+20240228160924.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>Is that an admin panel?</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/ad8720b5-d237-4e5a-9209-864ffe5d1faa/Pasted+image+20240229165659.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>Now do what you do. We are root.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/1e43a338-8799-45d7-9d60-bbce9672fee5/Pasted+image+20240229165017.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>After doing some research I found that you can exploit the sudo -l gives us acess to what we can use. We can use /usr/bin/apport-cli but I spent so much time looking on how to generate a crash file its embarrasing. Finally, I tried to just use the program itself and used the -f option. It literally can generate files for you.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/c5e5020f-af08-4f69-b238-edaa5312e350/Pasted+image+20240228232941.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>I went ahead and made it just a little bit better by selecting what we needed. I think its better to work with everything and then tune it to what you need anyway.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/91237cb7-ebe7-43af-aca0-4e47a6cbb584/Pasted+image+20240229164506.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>lets just pick 1 and see what happens.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/2deff330-e81d-4eca-bb46-2ee6ff8e9fcf/Pasted+image+20240228235014.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>It worked. I like to run sudo -l, whoami, uname -a, ifconfig, netstat -ano, ps -ef and getcap -r / 2&gt;dev/null before doing anything. You can also start trying to transfer things like linpeas etc. but I like manual gathering. sudo -l gives us /usr/bin/apport-cli nice. We need a version.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/daec7ab8-9b1b-496e-a3b6-517878093815/Pasted+image+20240302011725.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>In the site templates do you see how it says “site templates” and “Administrator Templates”… yeah that’s awesome. I did not see this for the longest time and could not understand for the life of me why I could not edit the site templates as an administrator. Don’t be like me.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/bd3f1c11-abd4-4dc7-8392-0610dc51303b/Pasted+image+20240228144426.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>After doing the directory bust with fuzz we get a lot of fluff. The byte size for what we see is 154 so lets get rid of it with the -fs switch.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/ac30f359-f2f9-4a12-b545-fbd77d9cf7af/Pasted+image+20240302011055.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>Leveraging the exploit we get the result above. But it looks like dogwater, we can make it look better. We pipe the command to ‘jq’</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/69245bc4-3000-4996-9275-ba3430b69ebe/Pasted+image+20240302005751.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>It is in fact an admin login. I tried default creds but got nowhere. I also read some of the documentation in “forgot your login details”. As I was reading I thought well I don’t know the version to do some research for exploits. So I did research on finding a version, and used that - thank you HackTrickz.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/b39d8c6c-3fae-43ec-992b-ca324b49306f/Pasted+image+20240302011449.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>Once in the page I knew there was a way to get a reverse shell because I have done it before.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/c8ebf6d7-0612-400c-b57b-6d930c6d4486/Pasted+image+20240301214415.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>After taking a look around the webpage there isn’t much. There are no forms for injection or anything sticking out and there is no login page so lets directory bust. (I did check robots.txt always check it)</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/838bbc51-7f47-4686-abf4-7dd4cb125d91/Pasted+image+20240301213603.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>Now we scan what we gathered.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/b36af14d-12d8-4942-8354-f5c48a9889a7/Pasted+image+20240302003548.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>And we ended up with a whole lot of nothing. Fantastic. However, if you can go forward into directories, I remembered you can go backward into subdomains. My tool of choice ffuf for this but you can use other tools like gobuster or sublist3r.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/99227dae-fb30-4e16-ac5c-b1f123d94acf/Pasted+image+20240228144610.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>We got dev. Sweet lets add to our /etc/hosts and check it. Lets navigate to it and check /robots.txt (I know there is a better way to deal with virtual hosting and subdomains so you dont have to add each individual one. I learned it from an OffSec stream and I dont know where I wrote it down. Noob move.)</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/3c4a578f-6064-49bf-a5ae-e92ea6f04bbe/Pasted+image+20240229165734.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>Grab that flag.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/76bc8b5a-e9d8-4910-ba51-6c406e351be9/Pasted+image+20240301213533.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>So we know we have a webpage so lets add to /etc/hosts and check the web page.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/83d3f760-4d5e-4116-b97a-56175ec9d031/Pasted+image+20240228233421.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>now we know we can crack this…. or atleast we should. I have the hashcrackbook on my desk here so I looked at that but if you read the hashcat manpages it should tell you what to use. You could use john/jtr as an alternative, up to you.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/543939ab-920e-4146-ba6a-8612d58689ce/Pasted+image+20240302012108.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>This is the correct admin template you wanted. Using that I was able to pop a shell. Once I got in I was able to enumerate what was on the machine and something I found was a mysql service running and we had creds so we might as well try. Again this is where I lost one of the pictures I initially had for you but poof computer deleted them.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/ccdbc20d-da8a-493e-a694-28a6bab560f8/Pasted+image+20240229165528.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>Now lets go forward and press 3 (to be completely honest this was a miss click and I meant to press 2 but lest just go with it) When you get to the final option press "V" to view. Now type in !/bin/bash and you get root</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/96f25b9c-ab0b-459d-85d4-5414873f8a3c/Pasted+image+20240228162544.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>Version 4.2.6, now we have something. Time to go research. I found an exploit using CVE-2023-23752 but I dont remember the random site as it got lost in the first version of writing this.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/1647943c-bdb9-44d5-a24b-786e1e9a39dc/Pasted+image+20240228234732.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>We got a new password. Lets try to use it to login to ssh, then do some recon if it works.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/12debc79-54a1-436d-8502-5cbecce661ab/Pasted+image+20240228144323.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>Go ahead and steal the command above.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/6c2b1ad6-720e-4934-8e18-9189cef8bfbc/Pasted+image+20240228232451.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Devvortex - Make it stand out</image:title>
      <image:caption>So we were able to log in. Now I’m a big fan of just dumping everything from a table because....well I’m lazy if were being honest but this looked like crap</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/lame-htb</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-05</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/759632d2-4c41-4a2b-af5e-cd2de9e27272/Pasted+image+20240304172259.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Lame: HTB - Make it stand out</image:title>
      <image:caption>This part of the exploit is what we are using.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/f35529f3-cf3f-4eef-a778-eac07f45ceb0/Pasted+image+20240304165530.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Lame: HTB - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/e35c0a3f-c4a7-4f24-80f5-ce0f996ff33f/Pasted+image+20240304155602.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Lame: HTB - Make it stand out</image:title>
      <image:caption>We were able to navigate to the one user that we see and find their user flag. Sick. Unfortunately, from here I had to back out and do something completely different because I could not figure out a better priv esc from where we were at the time. With smbclient and smbmap we are able to check possible shares and permissions on those shares we have access to.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/6fb563ce-cdbb-4bc4-8fb7-8335a97ba334/Pasted+image+20240304152823.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Lame: HTB - Make it stand out</image:title>
      <image:caption>(cont’d)</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/3685508d-e9e4-4a7f-b236-568e70dbf9ee/Pasted+image+20240304152841.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Lame: HTB - Make it stand out</image:title>
      <image:caption>Remember to do your due diligence and check everything listed. You may be surprised (for a quick win vsftpd 2.3.4 can be exploited via metasploit) FTP:</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/1830eac2-84cf-4236-b4d7-0ec4b9b3c4ba/Pasted+image+20240304153157.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Lame: HTB - Make it stand out</image:title>
      <image:caption>Unfortunately, nothing was gained from FTP. distccd: this exploit worked but I used the commented code that fixed the python3 issue to get it to work. https://gist.github.com/DarkCoderSc/4dbf6229a93e75c3bdf6b467e67a9855</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/1be8443f-f157-4550-9661-9c2df91b1b07/Pasted+image+20240304154749.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Lame: HTB - Make it stand out</image:title>
      <image:caption>Make sure to do information gathering about everything. There was a kernel level exploit that could have gotten you to root but I did not do that one. (I plan on doing this again with that exploit to play around with it.)</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/47a52a88-8a31-4afc-8688-6c9546a45d6f/Pasted+image+20240304154557.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Lame: HTB - Make it stand out</image:title>
      <image:caption>So we got in as daemon.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/7880a58a-cb1b-4b4c-a428-c96628b26ef7/Pasted+image+20240304154433.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Lame: HTB - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/33a489b9-5d58-4b04-af43-1b2dbd7f0e20/Pasted+image+20240304170237.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Lame: HTB - Make it stand out</image:title>
      <image:caption>With that we get root. As always. Stay curious my friends.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/dancing-htb</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-05</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/9a15d124-de87-4d51-9fa3-6f349c4a7b97/Pasted+image+20240303013413.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Dancing: HTB - Make it stand out</image:title>
      <image:caption>Oh no, can' believe we were right. Cant use that so lets try WorkShares instead which appears to be available</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/5e2cfc43-0df6-4fa9-8832-2688bd8db05f/Pasted+image+20240303013740.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Dancing: HTB - Make it stand out</image:title>
      <image:caption>Two directories, lets read their contents</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/9b140bdd-22f6-4ebb-9d12-2ac4a9529f6f/Pasted+image+20240303013003.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Dancing: HTB - Make it stand out</image:title>
      <image:caption>Port 445 looks juicy. lets enumerate the service with -L to list shares. You can use other tools like nmaps smb-enum, enum4linux and SMBMap (I have never used this one, but wanted to share) Initial Foothold:</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/779d6adf-15d9-4ac5-b268-0c8e056c7bd9/Pasted+image+20240303013824.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Dancing: HTB - Make it stand out</image:title>
      <image:caption>Grabbing contents from both to our local machine Exfiltration:</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/0ce9a1fd-2cf3-4ea4-9cec-51318e1aebbe/Pasted+image+20240303013243.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Dancing: HTB - Make it stand out</image:title>
      <image:caption>Lets try ADMIN$ though expect that not to work. Exploitation:</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/9f960ea9-a300-43d7-8646-190cc9f329ba/Pasted+image+20240303013955.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Dancing: HTB - Make it stand out</image:title>
      <image:caption>Lets actually read it now. Congrats you got root As always. Stay curious my friends.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/blue-htb</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-04</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/4f529d4f-813b-4872-b75e-4534538d476f/Pasted+image+20240304145210.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Blue: HTB - Make it stand out</image:title>
      <image:caption>Obligatory: “We’re in” We are system32 so we have admin access go get flag</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/44622c36-e7da-488d-b001-e8ed08cb0ab0/Pasted+image+20240304144352.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Blue: HTB - Make it stand out</image:title>
      <image:caption>We will use 0 Then set your options</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/595c69e8-bf34-4acd-9722-7d588b8328ad/Pasted+image+20240304145029.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Blue: HTB - Make it stand out</image:title>
      <image:caption>The 209.151.148.61 address is not correct Stares at camera</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/c772d8ea-2ec3-4382-a89e-837cc89da11b/Pasted+image+20240304143417.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Blue: HTB - Make it stand out</image:title>
      <image:caption>Port 445 is open so lets enumerate the service</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/97139422-5266-49b9-828b-fe5ac8e42208/Pasted+image+20240304144550.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Blue: HTB - Make it stand out</image:title>
      <image:caption>You can either type "run" or "exploit" to launch the attack NOTE: If you are using htb pwnbox set your LHOST to pwnbox or the exploit will not work</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/e7a2fb4a-d6da-4af1-95fd-ccddea18e5ba/Pasted+image+20240304143607.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Blue: HTB - Make it stand out</image:title>
      <image:caption>we get nothing for searching the shares but when you research the version of smb we have an exploit CVE-2017-0144. https://www.rapid7.com/db/modules/exploit/windows/smb/ms17_010_eternalblue/ start msfconsole -q so its quiet</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/d172349c-de88-44e7-84e4-8de943287b5b/Pasted+image+20240304145432.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Blue: HTB - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/8686dc09-2b6c-460e-a9b5-9da4be9b7842/Pasted+image+20240304145349.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Blue: HTB - Make it stand out</image:title>
      <image:caption>Don’t forget your user flag</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/2</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-05</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/5380107c-817f-4593-8a4b-ad008cb5b2bb/Screenshot+2023-08-10+at+10.32.05+PM.png</image:loc>
      <image:title>So You Wanna Be A Hacker - And So It Begins - Practical Recon | Meow: HTB - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/dd607b77-dab0-446b-9911-e1f5d7c9ccc6/Screenshot+2023-08-10+at+10.12.18+PM.png</image:loc>
      <image:title>So You Wanna Be A Hacker - And So It Begins - Practical Recon | Meow: HTB - Make it stand out</image:title>
      <image:caption>Verbose nmap scan</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/8a66abdd-dcce-4155-8371-1ad32d5a1974/Screenshot+2023-08-10+at+10.47.33+PM.png</image:loc>
      <image:title>So You Wanna Be A Hacker - And So It Begins - Practical Recon | Meow: HTB - Make it stand out</image:title>
      <image:caption>How do you read a file? I’m NOT doing it for you.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/712lel14b4yyp8y8tdqrebrtri0yyz</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-03</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/d9161e17-f580-4b67-a780-d12d163fc58f/Pasted+image+20240303004743.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Fawn: HTB - Make it stand out</image:title>
      <image:caption>Amazing we are already in! that was fast lets list the files ("ls" is the command) and grab what we can ("get" is the command)</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/2c51d232-d10e-4df7-bca9-cdcba9b0cf12/Pasted+image+20240303004836.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Fawn: HTB - Make it stand out</image:title>
      <image:caption>flag.txt is nice lets go read it. You can type exit to leave then you can type ls again in your directory on your machine</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/dfdf9f54-2937-4ceb-98e4-a9ee9208501d/Pasted+image+20240303005150.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Fawn: HTB - Make it stand out</image:title>
      <image:caption>if you want to read something on your personal machine type the command cat/less/more or you can view the files with nano/vi/vim (warning if you have never used vi/vim then I recommend you don't use those or prepare for frustration lol) Congratulations on rooting another box guys. As always. Stay Curious my friends.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/fe2a30e3-2f02-46ce-adf3-bb717cca2f77/Pasted+image+20240303005407.png</image:loc>
      <image:title>So You Wanna Be A Hacker - Fawn: HTB - Make it stand out</image:title>
      <image:caption>Okay cool so we discovered port 21 is open and it appears anonymous login is allowed and there is a file on the server called flag.txt so lets try it. Anonymous login means you can use the creds anonymous:anonymous to get in</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/Blog Post Title One-slgjt</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-03</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/so-you-wanna-be-a-hacker/blog-post-title-four-dx29r</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-05</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2025-02-03</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/reality-of-my-skillset</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-02-03</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/motivation-frustration-as-a-tool</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-02-03</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/question-what-is-your-talent-in-cyber</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-16</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/win-blogging-for-the-company</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-14</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/motivation-get-it-done</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-16</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/blog-post-title-two-hcxw6</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-07</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/taking-some-time-off</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-07</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/your-work-doesnt-speak-for-you-you-speak-for-your-work</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-07</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/win-i-have-been-published-in-academia</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-07</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/compliance-the-double-edged-sword</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-07</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/mindset-is-everything</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-07</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/win-i-am-all-setup-in-our-new-place</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-14</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/sorry-for-the-delay</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-07</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/motivation-just-do-it</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-02-27</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/blog-post-1</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-04</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/motivation-wins-losses/blog-post-title-three-ze7fc</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-05</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/all-kinds-of-cyber-news</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2024-03-04</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/all-kinds-of-cyber-news/blog-post-title-one-expe8</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-02-24</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/all-kinds-of-cyber-news/blog-post-title-two-24ctt</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-04</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/home</loc>
    <changefreq>daily</changefreq>
    <priority>1.0</priority>
    <lastmod>2024-03-05</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/our-vision</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2023-05-31</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/1659403919193-JEOQ79YWPRL8BPT4XG15/unsplash-image-EUsVwEOsblE.jpg</image:loc>
      <image:title>Whoami - Whoami? You May Never Know.</image:title>
      <image:caption>If I gave you all some hints I would not be surprised that some of you could figure out the answer. What I will say is that I am a lover of knowledge, I have always been curious but never found everything interesting. Maybe after some time I will give more information as to who I am and you can do some OSINT to figure out my identity. — TheDarkMentor</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/our-team</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2024-02-24</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/3-skills-of-life</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2025-01-16</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/5ec321c2af33de48734cc929/1618511387030-5LI1E5QMVTQ2RY9S00A4/20140228_Trade+151_0046+1.jpg</image:loc>
      <image:title>3 Skills of Life</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/donate</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2024-02-24</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/journey-through-security-topics</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2025-02-04</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/journey-through-security-topics/cybersquatting</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-02-04</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/1716183906949-EFSJE1HYWRX3C2J7HPPO/image-asset.jpeg</image:loc>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/journey-through-security-topics/csrf</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-02-04</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/1738697981477-R43BWMVHWD90NH203W4I/unsplash-image-mNC_avQmeq8.jpg</image:loc>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/journey-through-security-topics/information-security-regulations</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-13</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/1716182109099-5IGHMAZ6M6NQMXML8E87/image-asset.jpeg</image:loc>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/journey-through-security-topics/new-portfolio-item</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-01-13</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/1716181314292-M3AW9S7D8A627WPVL8G4/image-asset.jpeg</image:loc>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/journey-through-security-topics/project-six-sz8wl-85ya7</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-02-04</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/journey-through-security-topics/xss-html</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-02-04</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/a89da8a0-03e9-4d11-9672-0a69a169eb8e/cookie.png</image:loc>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/f71743af-18a8-4060-a3a8-e276f3ce72b8/html+injection.png</image:loc>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/d27afbc3-e41a-42db-9239-4b5f0bcbb759/htb+injection.png</image:loc>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/60dbd282c5ae61712e97b143/4223b5b4-e1c1-4549-9608-511b27c3a18c/prompt.png</image:loc>
    </image:image>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/journey-through-security-topics/project-four-yjynj-44k58</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-04</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/journey-through-security-topics/project-three-8zgh7-m6cet</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-03-04</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/journey-through-security-topics/project-two-llrgk-mdr6y</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2024-02-24</lastmod>
  </url>
  <url>
    <loc>https://www.whatsahacker.com/journey-through-security-topics/project-one-ephnc-f5ax8</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-02-04</lastmod>
  </url>
</urlset>

