I’m hard stuck. I found 4 subdomains. Can’t seem to find any more top level domains. Still looking for haha. Found the under development page. Can only access the latter one and the popcorn one. Can someone give me a nudge.
I’m hard stuck. I found 4 subdomains. Can’t seem to find any more top level domains. Still looking for haha. Found the under development page. Can only access the latter one and the popcorn one. Can someone give me a nudge.
I’m hard stuck. I found 4 subdomains. Can’t seem to find any more top level domains. Still looking for haha. Found the under development page. Can only access the latter one and the popcorn one. Can someone give me a nudge.
there are two domain you can enumerate. after that you can enumerate few subdomain belong to that every domain (two) domain using DNS ZN. it mean You do twice DNS ZN with that two domain.
Somebody help me with d******rd page. I tried all the params trying to include my image(shell) but failed. Now I am banging my head against the wall. It’s been hours since I am there. Sombody show me some light.
Same problem as a lot of other folks here. Found the RW share for the brazilian dance (worst codeword ever btw haha, might as well use the actual word for it at this point). Used nse script to figure out the local path, uploaded shell. Can’t get to the shell from d********d. I’ve tried pretty much everything. If anybody could help me out here that would be really cool Cheers
EDIT: Finally got user. Some hints for those who are struggling to get a shell even after figuring out the right path:
Try to get an absolute rather than a relative path
You might not need to use the file extension
EDIT #2: And rooted finally. What a wild ride. Very fun box, thanks @askar
I am in the same boat as you ^^, enumerated Brazilian dance, got the absolute path, uploaded the file and just cannot seem to get the LFI to work. Clearly an education here for me on LFI. I have looked on google for LFI syntax and I believe (I did say believe) I understand what LFI parameters are available to me but nothing seems to work. If anyone could help me out too - I’d appreciate the education.
EDIT: I was overthinking it way too much. Finally got my shell, now to privesc
h3llo, hey guys I’m stuck on the LFI portion. I feel like I’m overthinking it…can someone help point me in the right direction? I’ve been dancing for a couple of days so I know that part and I’ve got my other s4uff all gewd. New on here btw
only this appears below!
NOTE: we are dealing with a beginner php developer and the application is not tested yet! something went wrong, the script include wrong param
Can anyone PM me some tips for enumeration? I found 4 subdomains and an empty(?) directory. I also can’t seem to figure out how to access the different subdomains; they all say localhost.