AJAshley Jovanskainashleyjovanska.hashnode.dev·Sep 25 · 6 min readCross-Site Scripting (XSS) | Hack The Box AcademyInteractive Sessions & Skill Assessment Section 2/10 To get the flag, use the same payload we used above, but change its JavaScript code to show the cookie instead of showing the url. Note: After ty00
AJAshley Jovanskainashleyjovanska.hashnode.dev·Jul 19 · 4 min readJavascript Deobfuscation | Hack The BoxInteractive Sessions & Skill Assessment Repeat what you learned in this section, and you should find a secret flag, what is it? Open a web browser > Navigate to target URL > Right click -> Inspect p00
AJAshley Jovanskainashleyjovanska.hashnode.dev·Jul 16 · 6 min readWeb Fuzzing | Hack the Box AcademyInteractive Sessions & Skill Assessment Within the "webfuzzing_hidden_path" path on the target system (ie http://IP:PORT/webfuzzing_hidden_path/), fuzz for folders and then files to find the flag. F00
AJAshley Jovanskainashleyjovanska.hashnode.dev·Jul 10 · 9 min readInformation Gathering - Web Edition | Hack The Box AcademyInteractive Sessions & Skill Assessment. Perform a WHOIS lookup against the paypal.com domain. What is the registrar Internet Assigned Numbers Authority (IANA) ID number? whois paypal.com What is 00
AJAshley Jovanskainashleyjovanska.hashnode.dev·Jun 27 · 8 min readUsing Web Proxies | Hack The Box AcademyInteractive Sessions & Skill Assessment Try intercepting the ping request on the server shown above, and change the post data similarly to what we did in this section. Change the command to read 'fla00