Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Second Degree Black Belt : XML External Entities environment hostname is not getting set #139

Open
bilalk88 opened this issue Jan 3, 2024 · 3 comments

Comments

@bilalk88
Copy link

bilalk88 commented Jan 3, 2024

While I'm trying to solve the Second Degree Black Belt : XML External Entities challenge, observed that levering the previous challenge i.e. Injection got that there is one 'connecttocommandproc.sh' file when I try to read to content it is observed that the in URL only host2:8080 is mentioned, I think when deploying the hackerden challenge the environment value for host2 and flag-_secret values are not getting set.
Can someone please look into this and help me to get the host2 value,

@bilalk88
Copy link
Author

bilalk88 commented Jan 3, 2024

Also, just to check whether the XXE Flag value are getting set or not. from the codebase figured out, how to solve the solve challenge and did manage to solve partial part however after getting the 'JSESSIONID' used the commandproc and got the result as "Good for you! You got this far. Here's your challenge code url:" , however in the response not getting the challengeURL after solving it.
for reference, refer to below screenshot.
image
cc - @paul-ion

@paul-ion
Copy link
Collaborator

paul-ion commented Jan 6, 2024

Hi @bilalk88 , the hosted version of the Dojo is a few versions behind due to some resource compute issues. Working on solving.

@paul-ion
Copy link
Collaborator

@bilalk88 this issue should now be solved

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants