> For the complete documentation index, see [llms.txt](https://ganesha-hk.gitbook.io/offensive-security-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/using-web-proxies.md).

# Using Web Proxies

## Skills Assessment Walkthrough

> **HTB Module:** Using Web Proxies **Difficulty:** Easy **Goal:** Use Burp Suite features to solve 4 challenges across different endpoints **Tools:** Burp Suite (Proxy, Repeater, Intruder), Metasploit, Browser DevTools
>
> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FiThWA9uZ0I70002Lomqr%2Fimage.png?alt=media\&token=6c2e0285-5bec-4e57-88a6-29ec95f1caa7)![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FUA2YAjx0N4rx1l8kaPx2%2Fimage.png?alt=media\&token=47e6995c-0a91-4774-8f00-3a244ed8b0a5)

***

### 📌 Scenario

We're performing an internal penetration test for a local company. As we come across their internal web applications, we're presented with different situations where **Burp Suite / ZAP** can help. Each question tests a different proxy feature.

### 🗺️ Challenge Overview

```
Q1 → /lucky.php  → Bypass disabled button + Repeater       → Flag
Q2 → /admin.php  → Decode cookie (hex → ASCII → base64)    → 31-char hash
Q3 → /admin.php  → Intruder brute-force with payload processing → Flag
Q4 → MSF module  → Proxy traffic through Burp → directory name
```

***

***

## Challenge 1 — Force the Button (/lucky.php)

Navigate to `/lucky.php`. There's a button that says **"Click for a chance to win a flag!"** — but it's **disabled**.

#### Step 1: Remove the `disabled` attribute

1. Right-click the button → **Inspect Element**
2. Find the `<button>` tag with `disabled` attribute
3. Double-click on `disabled` and **delete it**

The button HTML looks like:

```html
<button id="submit" class="btn block-cube block-cube-hover" type="submit"
  formmethod="post" name="getflag" value="true" disabled>
```

Remove `disabled` so it becomes clickable.

> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F9ePXSD3uZt5Ybdk3rOL8%2Fimg-000.png?alt=media\&token=f12e82d7-70a2-40f0-b71e-8778d5167329)

#### Step 2: Click & Capture in Burp

1. Make sure **Burp Proxy intercept is ON**
2. Click the button
3. Capture the POST request → **Send to Repeater**
4. Send the request **multiple times** (as hinted in the question)
5. The flag appears in the response

> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FBFK0Q6Hdq55hIlFvdvAa%2Fimg-001.png?alt=media\&token=0aef267d-ace2-40ac-a128-3723c8edee67)

***

## Challenge 2 — Decode the Cookie (/admin.php)

Navigate to `/admin.php`. There's a cookie set that contains encoded data.

#### Decoding Chain

The cookie value goes through this decoding chain:

```
Cookie value (hex encoded)
  → Decode from Hex → ASCII string
    → Decode from Base64 → 31-character hash
```

Result: a **31-character string** like:

```
3dac93b8cd250xxxxxxxxxxxxxxxxxx
```

This is 1 character short of an MD5 hash (32 chars). We need to brute-force the missing character — that's Challenge 3.

***

## Challenge 3 — Intruder Brute-Force (/admin.php)

We have a 31-character hash from the cookie decode. Adding 1 more character makes it a valid **MD5 hash**. We need to find the right character.

#### Step 1: Send /admin.php request to Intruder

1. Capture a `GET /admin.php` request in Burp
2. Send to **Intruder**
3. Select the **cookie value** as the fuzzing position

#### Step 2: Configure Payload

* **Payload list:** Load `alphanum-case.txt` (a-z, A-Z, 0-9 — 62 characters)
* **Payload Processing** rules (in this order):
  1. **Add Prefix:** `3dac93b8cd250xxxxxxxxxxxxxxxxxx` (the 31-char hash)
  2. **Base64-encode**
  3. **Encode as ASCII hex**

This reconstructs the cookie encoding chain in reverse for each candidate character.

> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FJJt5s8xafcdplVt930eA%2Fimg-002.png?alt=media\&token=e2ee3d4f-e79d-40bb-81f4-18ba0075d55c)

#### Step 3: Start Attack & Find the Flag

Run the attack (62 requests). Sort by **Status code** or **Length** — one request returns a **200** with a different response length (1284 bytes). That's the one with the flag!

> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F0SZoNqD1LbRj3GyN8Vus%2Fimg-003.png?alt=media\&token=1647cfed-0db3-429e-b148-07e99c778b02)

***

## Challenge 4 — Metasploit + Burp Proxy

Use a **Metasploit scanner module** and route its traffic through Burp to capture the HTTP requests and find a **directory name**.

#### Step 1: Configure Metasploit

```bash
msfconsole
```

```
use auxiliary(scanner/http/coldfusion_locale_traversal)
set rhosts 154.57.164.76
set rport 30148
set PROXIES HTTP:127.0.0.1:8080
run
```

The key settings:

* **Module:** `auxiliary/scanner/http/coldfusion_locale_traversal`
* **RHOSTS:** target IP
* **RPORT:** target port
* **PROXIES:** `HTTP:127.0.0.1:8080` (routes through Burp)

#### Step 2: Check Burp HTTP History

After the scan completes, go to **Burp → HTTP history**. You'll see the request MSF made:

```
GET /C<redacted>/administrator/index.cfm HTTP/1.1
Host: 154.57.164.76:30148
```

The directory name from the traversal path is your answer.

> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FY1AxrmA6xSWyGm7thzPQ%2Fimg-004.png?alt=media\&token=ad2c9d61-2c49-4120-b1aa-cf67825540d4)

***

## 🏆 All Challenges Complete!

#### Tools & Features Used

| Challenge | Feature Used                       | Purpose                                       |
| --------- | ---------------------------------- | --------------------------------------------- |
| Q1        | Browser DevTools + Burp Repeater   | Remove `disabled` attr, replay POST request   |
| Q2        | Burp Decoder / CyberChef           | Hex → ASCII → Base64 decode cookie            |
| Q3        | Burp Intruder + Payload Processing | Brute-force missing hash char with encoding   |
| Q4        | Metasploit + Burp Proxy            | Proxy MSF traffic through Burp to capture URL |

> **GG 🏴** — DevTools + Repeater + Intruder + MSF Proxy — all Burp features in one assessment.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/using-web-proxies.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
