ZeroBox

Source Code Review: practice machines and key commands

Reading the application source is often faster than blind testing. When a box leaks code through a repository, backup, LFI or a readable share, look for hardcoded credentials, secret keys, unsafe functions and trust assumptions. In web code, trace user input from the request to dangerous sinks: database queries, file paths, command execution, template rendering and deserialisation. Grep for words like password, token, secret and eval first, then follow the routes that require no authentication. Git history deserves a pass because removed secrets often remain in earlier commits. Compare the behaviour you see in the browser with what the code does to spot logic gaps. The boxes below reward careful code reading. Time spent reading code is rarely wasted, even when a quick scan finds nothing at first.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

Exposed .git Source Code Extraction

Dump full repository commits and source code from misconfigured public /.git/ directory.

git-dumper http://{TARGET_IP}/.git/ ./git-dump

PHP Filter Base64 LFI Wrapper

Read source code of PHP scripts through base64 conversion filter.

http://{TARGET_IP}/index.php?page=php://filter/convert.base64-encode/resource=config.php

ffuf Directory & Endpoint Fuzzing

High-speed directory enumeration with auto-calibrated filtering and extension recursion.

ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.html,.txt,.bak,.js -ac -mc 200,301,302,403

Keep going

Source Code Review machines (10)

Machines are matched by their technique tags. 9 Linux, 1 Windows.

Easy (3)

MachinePlatformOSTags
BountyHunterHTBLinuxHTB, Source-code-review, XXE-injection
HorizontallHTBLinuxCVE-2019-18818, CVE-2019-19609, CVE-2021-3129, HTB
RedPandaHTBLinuxHTB, Source-code-review, XML-Entity-Injection

Medium (6)

MachinePlatformOSTags
DevzatHTBLinuxCVE-2019-20933, Command-Injection, HTB, Source-code-review
Git HappensTHMLinuxGit, Information-Disclosure, Source-Code-Analysis
JewelHTBLinux2020, 8165, CVE-2020-8165, HTB
ObscurityHTBLinuxHTB, Known, Plaintext-Attack, Source-Code-Review
StreamIOHTBWindowsAutomatic-LDAP, HTB, LFI-using-PHP-wrappers, Source-Code-Review
WaldoHTBLinuxHTB, Linux-Capabilities, Rbash-escape-techniques, Source-code-review

Insane (1)

MachinePlatformOSTags
ResponseHTBLinuxAuthentication-Bypass, Directory-Traversal, HTB, SSRF-using-HTTP-long

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox