@Randsec said:
Unable to get anything apart from some directories. Typical crawlers are ok, or people is using another kind of tool?
Crawlers/spiders may not do anything for you…those just click on active links, they don’t really help you find directories that the server has no link to.
@isuckatcyber said: @Randsec said:
Unable to get anything apart from some directories. Typical crawlers are ok, or people is using another kind of tool?
Crawlers/spiders may not do anything for you…those just click on active links, they don’t really help you find directories that the server has no link to.
@Waffles said:
Having trouble with PrivEsc, if somebody feels like giving some advice please PM me.
Don’t over complicate, find the arch of the machine and follow this rabbit
Holy ■■■■!
I spent so long on getting a stable functional reverse shell that I didnt even notice this part. Literally after you said that the light bulb turned on and and 5 min later i had root.txt
Found interesting files. Do a google search and using dirb is enough. I think this step is uncommon so maybe you could skip it (for anyone found nothing in Web Server)
I’m uploading a file generated with msfvenom compatible with the web arch of this server, meterpreter/reverse_tcp and dosen’t work, does nothing, i tried also in one of my virtual machines with the same webserver installed on it and does not work the same. I think msfvenom has problems to generate working files for this specific web arch, has any of you the same problem?? Should i find an alternative way than msfvenom and metasploit handler to get a reverse shell??
Guys I strongly recommend doing this box in a private (FF) or incognito (Chrome) window and be sure to delete all site data (cookie, cache, offline data, etc.). Once I figured this out (with the help of @im4x5yn74x), I didn’t have to keep resetting the box. I was able to recover it after it started to hang, which it did A LOT. Practically after every “major” command I ran. Until I caught onto this, I was unable to “execute” despite my other successes. I hope this helps someone.
Remix: Ok, it’s actually better without the private/incog window. That way you can delete the site data when you need to without sometimes needing to reopen the window.