Watched ipsec’s bank video and got good information from dns but I need help figuring out how to route to the subdomain. All I’m getting back is localhost with etc/resolv.c
If I’m understanding you correctly, the typical thing I’d do at that point is to edit my hosts file (will be in a different place depending on what OS you’re using, google is your friend). In this case, you can supply the address you have for the main site for “localhost”.
Hi, can someone please PM for the LFI part. I tried the 3 parameters, i beleive if have the info from S*B enum as well. Also, no able to get the php source code.
THanks.
So after I get results from dig, I’m stuck at what to add to my hosts so that I can access the subdomains. Can anyone PM me a hint?
This is where I’m at… Been at this for hours. D** returns different subdomains based on the domain name i try, but they all point to localhost. I’m not sure if this is right or what to do next… Can anyone give me a nudge?
same here!!
@workabhiwin09 - you ever figure this one out? PM me if you need a nudge or have questions.
yes i did and thanks to @jarvis95 great guidance!!
I’m struggling with my enumeration of the port 53 subdomains. I’ve come across several, but much like others in this thread I am struggling to properly change my hosts/resolv.conf file to continue.
If anyone could give me a nudge I’d appreciate it.
I did find an interesting .txt through enumerating another port as well.
been hammering away at the lfi for about 2 hours by trying to get output to appear on page. going to mess with other pa**ms and see if something changes.
Same as @riazufila. Enumerated 53 got some stuffs. Edited same file and got nothing.
I also don’t get why editing that would even help. It’s looking for an IP not a name???
Same as @riazufila. Enumerated 53 got some stuffs. Edited same file and got nothing.
I also don’t get why editing that would even help. It’s looking for an IP not a name???
Dude I solved it. If you look at nmap scan. What other ports is there? Besides 80? What other variations are there?
Found something interesting. If you want to test whether you’re hitting correct subdomains or domains or domains and don’t want to mess with resolv.conf or hosts, you can use curl with --resolve.