Dev0ops hints

@trodix said:

@Vex20k said:
I got the user, working on root. I got something related to a protocol but I can’t figure out whats missing. Could someone shoot me a PM?

back to the past Marty !

At first I didn’t what people meant by this but I figured it out just now haha. I did get something out of it as well but not sure how to use it to proceed.

I’m stuck at the upload part and know what i need to upload but no clue what to do. Any help?

I think I have found the correct payload vector, could anyone PM me to help with formatting the payload?

@BobBobbington said:
I think I have found the correct payload vector, could anyone PM me to help with formatting the payload?

PM’d

I have problems with the payload too, someone can help me? (PM)

Stuck on the guessing for the file upload.

Note : I’ve read and use the obvious tips

Some comments have made it pretty obvious as to what is expected :slight_smile:

Really enjoyed this one.
Good job @lokori :wink:

Struggling with priv esc to root - I now the hints on how to go back in time, together with something devops use but can´t make any sense of it - need a nudge maybe I am overcomplicating it, please PM, I need to discuss my findings so far and a nudge will be much appreciated.

Anyone need hits (not answer), just PM me. :lol:

Got root… Liked this box ?

I’m completely stuck on the web api - I’ve found a couple things and found the source for ****.py but I can’t seem to figure out where to go from here. Any hints appreciated.

use the source @lurchman . Perhaps google for “exploiting *******” based on what you see there. Internet will tell you many things if you search for known vulnerabilities and flaws in some technology/library/framework/component.

Great box @lokori ! I learned a lot about…well you know.

Ok so im stuck at the start. Found two pages on the website. Cant upload anything that works… do i need to know about XML coding?

good box. Had a lot of fun doing it.

@shane2483 said:
Ok so im stuck at the start. Found two pages on the website. Cant upload anything that works… do i need to know about XML coding?

You don’t need to know a lot about XML but if you’re doing an XML payload I’d say look at some example online and pay attention to the way it should be formatted

For initial foothold go through OWASP top 10 2017 they have examples too :slight_smile:
For priv esc look what is on box and read about it :slight_smile:

Three days “play” with payload. A have some questions. PM me somebody for help!

Got root. That was a fun box, took learning new things. :slight_smile: PM if you need help.