Friendzone - HackTheBox

Type your comment> @Slowloris said:

Watched ipsec’s bank video and got good information from dns but I need help figuring out how to route to the subdomain. All I’m getting back is localhost with etc/resolv.c

If I’m understanding you correctly, the typical thing I’d do at that point is to edit my hosts file (will be in a different place depending on what OS you’re using, google is your friend). In this case, you can supply the address you have for the main site for “localhost”.

Just got user, gonna start working on root tomorrow.

I lost a lot of time because of the PortSwigger certificate and burp. So keep that in mind for User is you are stuck after the first enumeration :).

hello guys, could someone please help me here… i am stuck at image_param is missed page

Type your comment> @sodex said:

hello guys, could someone please help me here… i am stuck at image_param is missed page

Read up on LFI, as well as NMAP enumeration of a certain brazilian dance.

Hi, can someone please PM for the LFI part. I tried the 3 parameters, i beleive if have the info from S*B enum as well. Also, no able to get the php source code.
THanks.

Type your comment> @d3v1ant said:

Type your comment> @workabhiwin09 said:

Type your comment> @d3v1ant said:

Type your comment> @publicist said:

So after I get results from dig, I’m stuck at what to add to my hosts so that I can access the subdomains. Can anyone PM me a hint?

This is where I’m at… Been at this for hours. D** returns different subdomains based on the domain name i try, but they all point to localhost. I’m not sure if this is right or what to do next… Can anyone give me a nudge?

same here!! :frowning:

@workabhiwin09 - you ever figure this one out? PM me if you need a nudge or have questions.

yes i did and thanks to @jarvis95 great guidance!!

Rooted.
User needs enumeration and a little bit guessing.
Root is about task scheduling and file permissions.

.

How can i scan the port 53, i tried so much…

Hey all,

I’m struggling with my enumeration of the port 53 subdomains. I’ve come across several, but much like others in this thread I am struggling to properly change my hosts/resolv.conf file to continue.

If anyone could give me a nudge I’d appreciate it.

I did find an interesting .txt through enumerating another port as well.

Rooted. PM me if you need help.

been hammering away at the lfi for about 2 hours by trying to get output to appear on page. going to mess with other pa**ms and see if something changes.

I’ve enumerated port 53 and found some useful info. And I’ve edited the /e**/h**** file, but it still doesn’t load in the browser. Help please?

Same as @riazufila. Enumerated 53 got some stuffs. Edited same file and got nothing.
I also don’t get why editing that would even help. It’s looking for an IP not a name???

Type your comment> @blackseal1337 said:

Same as @riazufila. Enumerated 53 got some stuffs. Edited same file and got nothing.
I also don’t get why editing that would even help. It’s looking for an IP not a name???

Dude I solved it. If you look at nmap scan. What other ports is there? Besides 80? What other variations are there?

Found something interesting. If you want to test whether you’re hitting correct subdomains or domains or domains and don’t want to mess with resolv.conf or hosts, you can use curl with --resolve.

Need Help with subdomain…not able to see anything in browser…got 4 subdomains…

Type your comment> @wish said:

Need Help with subdomain…not able to see anything in browser…got 4 subdomains…

Have you updated them in /e**/h**** ?

Can anyone PM me with some hints. I’ve used dig, dnsrecon and nslookup to enumerate port 53, but am not finding any subdomains.

Type your comment> @Steve333 said:

Can anyone PM me with some hints. I’ve used dig, dnsrecon and nslookup to enumerate port 53, but am not finding any subdomains.

There’s a four letter switch you need to use with dig.