Can’t find any posts about this one yet. I’m a bit stuck on this and I’m not sure if I’m going down a rabbit hole. I found a script that would suggest one popular type of vuln, all i’ve managed to actually get work is xss unfortunately. It blocks certain attempts to inject stuff and you end up with that ■■■■■■ smiley lol.
I cannot find a way in!! I have found a user? and another place to scan, but nothing that squeals come in!!! Can someone assist (I don’t want the answer just to see if I am going way off target).
I’ve also manage to enumerate some users, but any web based scanning doesnt give me what im looking for, nikto doesnt run, even using WAF bypasses… it just hangs.
dirb only find one interesting page, but it redirects to a dead page… am i rabbit holing, i feel like i am…
this might be a nice machine. But so far I have found nothing interesting if Waf bypass is not the intention. There is one thing, which is quite old, but even that needs a key.