<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>HackTheBox - SneakyMailer</title>
        <link>https://stream.echo6.co/videos/watch/d06fc995-b918-40a3-b20d-e45afaab98f0</link>
        <description>00:00 - Intro 00:45 - Start of nmap 03:10 - Poking a the websites 04:20 - Starting gobusters in the background while we look at the site 07:00 - Grabbing a list of emails off of the website 08:40 - Using SWAKS to mass email users with a link 14:45 - User went to our website, grabbed credentials 17:50 - Failing to do FTP User Enumeration, do this at the end of the video 19:00 - Failing with Thunderbird to login 22:30 - Switching to the Evolution Mail client to check mailboxes, finding FTP Details in Sent Mail 28:40 - Using wget to mirror the FTP Directory, then poking at PHP Files 30:50 - Showing pypi/Register.php, which should have been used during the phishing stage 31:30 - Checking if we can upload files to the FTP Directory and finding the dev VHOST 35:00 - Shell Returned 37:00 - Discovering a HTPASSWD file, then cracking it with hashcat 39:50 - Checking out pypi.sneakycorp.htb:8080 and finding a pypi server 41:00 - Creating a Malicious PyPi Package 43:30 - Adding a reverse shell to our pypi package 44:45 - Creating a pypi configuration file 47:00 - Uploading the package and getting a shell as low 50:10 - Checking sudoers, and finding low can run pip3 - Use GTFO Bin to get root 53:30 - EXTRA: Enumerating the FTP Users by creating a quick webapp then using FFUF against it.</description>
        <lastBuildDate>Wed, 15 Apr 2026 11:10:35 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://stream.echo6.co</generator>
        <image>
            <title>HackTheBox - SneakyMailer</title>
            <url>https://stream.echo6.co/client/assets/images/icons/icon-512x512.png</url>
            <link>https://stream.echo6.co/videos/watch/d06fc995-b918-40a3-b20d-e45afaab98f0</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://stream.echo6.co/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://stream.echo6.co/feeds/video-comments.xml?videoId=d06fc995-b918-40a3-b20d-e45afaab98f0" rel="self" type="application/rss+xml"/>
    </channel>
</rss>