Cypher (HTB)
Intro.
Enumeration.
Port scanning.
# Nmap 7.95 scan initiated Wed Mar 5 03:40:59 2025 as: nmap -vvv -p 22,80 -4 -A -o scan.nmap 10.10.11.57
Nmap scan report for cypher.htb (10.10.11.57)
Host is up, received syn-ack (0.014s latency).
Scanned at 2025-03-05 03:40:59 +08 for 8s
PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack OpenSSH 9.6p1 Ubuntu 3ubuntu13.8 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 be:68:db:82:8e:63:32:45:54:46:b7:08:7b:3b:52:b0 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBMurODrr5ER4wj9mB2tWhXcLIcrm4Bo1lIEufLYIEBVY4h4ZROFj2+WFnXlGNqLG6ZB+DWQHRgG/6wg71wcElxA=
| 256 e5:5b:34:f5:54:43:93:f8:7e:b6:69:4c:ac:d6:3d:23 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEqadcsjXAxI3uSmNBA8HUMR3L4lTaePj3o6vhgPuPTi
80/tcp open http syn-ack nginx 1.24.0 (Ubuntu)
| http-methods:
|_ Supported Methods: GET HEAD
|_http-title: GRAPH ASM
|_http-server-header: nginx/1.24.0 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Read data files from: /usr/bin/../share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Wed Mar 5 03:41:07 2025 -- 1 IP address (1 host up) scanned in 7.62 secondsEnumerate Web application.


CustomFunctions class.
HelloWorldProcedure

Neo4j Injection.


Bypassing Neo4j.


Command Injection to RCE.





Shell as graphasm




Last updated