I’m in same situation and thank you for the info. it would be great if you could tell me which post mentioned that.
Can anyone give me a nudge on the foothold into DC02?
Rooted everything but Admin network, WS02, and SQL01
Somebody can give a nudge regarding NIX01? I can’t root this machine. I get password of b**.I don’t think it’s CVE because it’s later than the date dante opened. is there an “intended” way to root? am I right?
edit:rooted. maybe I mistyped it before.
Are you sure that you’re brutforcing is working well ? Are you sure that there is no mistake in your command, or request you’re using ? If you don’t find any password, this is because you did a mistake somewhere. That’s it. Try harder.
Anyone have any tips for foothold on .100? I have wp-admin creds, but metasploit module doesn’t seem to work and plugin manager is messed up.
Solved my issue, just needed to look a bit deeper.
Hi everyone! I have been stuck on NIX-02 and Jenkins machines. For NIX-02 i pwned M***** account and can access machine with ssh, also found passwords for F**** account started from ST***** and 69*********, i tried both but they don’t work. For jenkins i trying few exploits and bruteforce but it doesn’t work. What I do wrong? Can anyone give some tips and tricks?
Update: 29.12.2022 NIX-02 solved.
Hello everybody, I’m stuck getting an initial foothold =/. I’m fairly new to doing HTB style items. I found the very first flag, and I found the backup file from the website. But I have tried bruting the login, but can’t seem to make a dent. I even tried to make my own wordlist using the documentation that’s pinned to this thread. Dante guide — HTB. Dante Pro Lab Tips && Tricks | by Karol Mazurek | Medium
I’m sure I am missing something stupid, but I am awful with WordPress XD, any help is greatly appreciated.
There are no tips. You did not found the correct password that’s it. Keep looking for it.
Ok, thank You. I will try harder.
Hello, I’m stuck on initial foothold, I’m connected to Wo***** as Ja**** but cannot find a way to gain access to the server. I tried some vulnerabilities that have been found by WPS**** with no success, any hint ?
Hi, I’m stuck on SQL01 and NIX04. Can someone DM me for some help ?
No one ? When I tried to edit themes and plugins but I have an error message. And don’t have FTP credentials to upload plugins or themes. Am I in the wrong way ? (I also tried using metasploit but cannot get a session too)
DM if you want
I have pwned a few of the machines on the Dante network, but am lost for direction on where to go next (my understanding is that the FW01 machine is out of scope). This is the list of machines I have pwned:
DANTE-WEB-NIX01
DANTE-WS03
DANTE-WS02
DANTE-WS01
DANTE-NIX04
DANTE-NIX03
DANTE-NIX02
DANTE-DC01
I am currently looking at SQL01 and the J****ns machine, but none of my collected creds so far seem to be working. Am I on the right track or is there a way onto the admin subnet from one of these machines that I have missed? Help would be very much appreciated.
How did you get escalate on NIX02 to Frank? I found his “password” in Slack files, but have been trying for the last two days and its not working =X. Other than that I can’t get anything with Margaret. Suggestions, thoughts?
Hello, you can upload a plugin from the W******** web interface…
Hello, I don’t know if it’s the same case but for me one faster method/ATTACK with WP**** (x**** c) wasn’t successful… default p*******-*****k method was enough.
Hey no this is a different box I believe. This one is for (.10). I can ssh in with Margaret, and escape her restrictive shell, but post-enumeration has given me nothing besides what I thought was franks password, but it doesn’t work. LinPeas doesn’t show anything so it makes me feel like the I’m supposed to do something with frank, but I can’t login as him and I’m stumped lol. Any thoughts?
lol my answer was for the .100, your old post (-5d).