NIbbles

@GhostCat said:

logedIn. enumerated directories. but cant find user.txt. any Hint ?

What can you find?

@c60cb859 said:

@GhostCat said:

logedIn. enumerated directories. but cant find user.txt. any Hint ?

What can you find?
all the directories keep changing but most recently i was able to find image.php.

@GhostCat said:

logedIn. enumerated directories. but cant find user.txt. any Hint ?

Did you get a shell?

@xdaem00n said:

@GhostCat said:

logedIn. enumerated directories. but cant find user.txt. any Hint ?

Did you get a shell?

image.php looked like shell but cannot execute any linux commands. Apart from that i found monitor.sh

Hello! I think I have a problem. When I thought I’m logged in the application, the web throws: “Nibbleblog security error - User not logged”. I’ve tried to change the params but nothings happens. Somebody could help me?

Spent half a day and so so frustrated with the admin panel. I saw the earlier messages and tried everything that I could think of! No matter what I try it won’t take it :anguished: Can someone please DM…I am just tired now!

@tang0charlie said:
Spent half a day and so so frustrated with the admin panel. I saw the earlier messages and tried everything that I could think of! No matter what I try it won’t take it :anguished: Can someone please DM…I am just tired now!

Never mind! Got it :slight_smile:

@GhostCat said:

@xdaem00n said:

@GhostCat said:

logedIn. enumerated directories. but cant find user.txt. any Hint ?

Did you get a shell?

image.php looked like shell but cannot execute any linux commands. Apart from that i found monitor.sh

You should get a shell where you can execute commands, like ls and whoami

Is there any telegram group of HTB users?

I’ve read through the whole thread but still couldn’t log into the web application. If anyone could give me some hints, please PM me. Thanks.

I managed to find the default login. Sorry for posting too hastily.

@c60cb859 said:

@GhostCat said:

@xdaem00n said:

@GhostCat said:

logedIn. enumerated directories. but cant find user.txt. any Hint ?

Did you get a shell?

image.php looked like shell but cannot execute any linux commands. Apart from that i found monitor.sh

You should get a shell where you can execute commands, like ls and whoami

got shell and user.txt. Thanks :slight_smile:

any hints on prev-esc? got results for LinEnum.sh

If anyone needs help with this pm me.

Can anyone give me hints on the priv esc part? Thanks!

I couldn’t upgrade shell. Can anyone give me little hint about that? (I think the solution doesn’t include python.Am I right?)

@ghroot @Jukz @SiegeMinion hint search in google nibbles :slight_smile:

@T3jv1l said:
@ghroot @Jukz @SiegeMinion hint search in google nibbles :slight_smile:

I already rooted yesterday. Thanks tho! :slight_smile:

Has someone reset the password on this? I don’t have any resets left.

I am kinda lost, after running LinEnum and finding a file with root privilege i have no idea how to procede after that, anyone got a link on what to try after that?