Can anyone give me a hint on minion? I’ve found the command shell page but don’t think it’s possible to use as is because it wants a POST.
Am I in a rabbit hole or is this the right path forward?
Can anyone give me a hint on minion? I’ve found the command shell page but don’t think it’s possible to use as is because it wants a POST.
Am I in a rabbit hole or is this the right path forward?
Ah nevermind lol figured it out
Any tip for finding the page… dirb,gobuster, and wfuzz (with various lists) turn up nada?
the worst box
crazy shell…lol.
@blobbo said:
Ah nevermind lol figured it out
Hey blobbo, I feel I found the “ack**” command shell page. However, I think it is no longer responsive (I reset the machine twice). The page says it is “not running.” In an effort to confirm I have the correct page, could you please check if the page still works? Thanks!
@peek said:
the worst box
glad to read taht you liked it
@ShadyAck said:
@blobbo said:
Ah nevermind lol figured it outHey blobbo, I feel I found the “ack**” command shell page. However, I think it is no longer responsive (I reset the machine twice). The page says it is “not running.” In an effort to confirm I have the correct page, could you please check if the page still works? Thanks!
If you reset it, it will work. If it’s not doing what you want it to do, you’re not on the right page.
I’m stuck finding the entry point to this machine. I have enumerated, ran gobuster, dirb and tried many different types of requests. I have found the single /b* directory and the encoded quote on the front page. I have uses this quote to build a custom wordlist but my brute forcing is going nowhere. Can someone offer a hint?