Friendzone - HackTheBox

not sure if this upload successful is a deceiving message or its something like that help box where it was obfuscating names based on timestamps or its a rabbit hole all by itself lol

i enumerate more and more but cant found a way for see where go our uploaded files…

I’m more mad that i enumerate the particular server for that exact thing (even in bb’s) and the ONE FUCKING TIME I DON’T DX

Type your comment> @Tepidangler said:

I’m more mad that i enumerate the particular server for that exact thing (even in bb’s) and the ONE FUCKING TIME I DON’T DX

what? XD

So I got the creds, did enum with port 53. Does this have to do with Virtual Hosts?

if you did enum port 53, you know what to do, where to do, and what the creds is for

Something went worng !

Is being able to access only 1 out of 4 of the pages normal?

Type your comment> @cazzipro said:

Something went worng !

Ha Ha! :slight_smile:

Type your comment> @cazzipro said:

Something went worng !

I’m stuck in the same place …

Type your comment> @jkr said:

Type your comment> @cazzipro said:

Something went worng !

Ha Ha! :slight_smile:

can you please look private messages?

Just dig a little deeper and you will find it.

LOL , i have 2 type of creds and i dont where to put them :frowning:

Ha Ha! :slight_smile:
Something went wrong
stuck here, any hints?

tons of fun on this box so far. here at *******rd.php and have learned SO MUCH about dns enumeration. I havent even got user and i already want to say thank you.

join us on discord at Discord

Type your comment> @Ozunu said:

Ha Ha! :slight_smile:
Something went wrong
stuck here, any hints?

still stuck here too

WHAT ARE YOU TRYING TO DO HOOOOOOMAN !

lololol i love this box.

i am a real beginner, but i am still stuck at the nmap scan, can someone pm me a hint?

I tried to do a ze t*er via NSE with the -e flag hence the boxes name. Am I in the right mindset? I’m not getting any information back with any of the other D tools and I don’t think there’s a way to route it through the VPN interface if I’m not mistaken.

Wow… this box. holes everywhere. Interesting path to user. Don’t worry about the actual timestamp or the encoded one. The “timestamp” param is key, but not as a timestamp…

Root requires some custom work. Fun box, but I think it probably should have been a 30 point box.