Official Academy Discussion

@WHLSW said:

I was able to gain a foothold but i was not able to find the a-p page for login with a tool like dirbuster. I just lucked out with manual trying so could someone suggest a proper enum command to find that kind a thing in the future ? Also dirb just gives a lot of erros so i think i need a better toolset. Thanks :slight_smile:

I think, if you mean the page I think you mean, the simple answer is down to wordlists - there isnā€™t a right or wrong one - you just need to try different ones.

Its also worth combining directory enumeration tools with web application scanners like Nikto.

Type your comment> @Gaiaphage said:

So, I managed to get a www-**** shell and also found some creds (s***** and GkE*********1), but Iā€™m not finding out where to use them (I tried s and "s* - "). I only managed to get on my, but this doesnā€™t seem to help me. Could someone give me a nudge please?

I am at the same place, can you/anyone give me a nudge?

@xor2764 said:

Type your comment> @Gaiaphage said:

So, I managed to get a www-**** shell and also found some creds (s***** and GkE*********1), but Iā€™m not finding out where to use them (I tried s and "s* - "). I only managed to get on my, but this doesnā€™t seem to help me. Could someone give me a nudge please?

I am at the same place, can you/anyone give me a nudge?

I suspect youā€™ve looked in the wrong places. Have a look closer to where you landed.

Rooted. First box Iā€™ve completed, definitely learned a lot from it. Big thanks to TazWake and others in the discussion for the nudges.

Iā€™ve just reset the box. I can ping it and Iā€™ve redownloaded my vpn pack.

It takes anywhere from 5-10 mins to load the main webapp page. Iā€™m based in Aus.

Anyone else getting slow connections? I assume its from the virtual DDoS of noobies running nmap.

ROOTED!

DM me if you need a nudge!

I have found an exploit for the machine but i donā€™t get session anyone can tell me what I am doing wrong. Exploit: msf **** base64 app key *lara (I hope I didnā€™t gave extra hint)

Type your comment> @happykharoud said:

I have found an exploit for the machine but i donā€™t get session anyone can tell me what I am doing wrong. Exploit: msf **** base64 app key *lara (I hope I didnā€™t gave extra hint)

Try without the part before the : ( in the app key section also no : )

@happykharoud said:

I have found an exploit for the machine but i donā€™t get session anyone can tell me what I am doing wrong. Exploit: msf **** base64 app key *lara (I hope I didnā€™t gave extra hint)

Make sure youā€™ve got all the values correct.

Anyone have any hints on getting a foothold? Iā€™ve found d**-st****-.a****.com but not sure what to exploit to start attacking

Edit: Thanks @TazWake was relatively straightforward after landing the beachhead. Enjoyed the lateral movement then a straightforward privesc for root.

@jw0 said:

Anyone have any hints on getting a foothold? Iā€™ve found d**-st****-.a****.com but not sure what to exploit to start attacking

Look into what it is and search for exploits for it.

This was a nice box! :slight_smile:
From my beginnerā€™s point of view: It is easy to get into rabbit holes here.

Feel free to PM me for nudges.

finally rootedā€¦
uid=0(root) gid=0(root) groups=0(root)

Initial foothold - donā€™t look closely look deeper
donā€™t frustrate if not getting anything just start againā€¦
user- look wildly,again ā€¦
root - root is easy
thanks for amazing box
@egre55 , @mrb3n
need help ping me on twitter @saims0n

Hi! I need a little kick for foothold.
I successfully registered a new user after changing the r***d but I nothing works beyond that point; I cant get hold of any admin pages I found using the creds from the registered user. A little kick pls.

Type your comment> @C4P7A1NFlint said:

Hi! I need a little kick for foothold.
I successfully registered a new user after changing the r***d but I nothing works beyond that point; I cant get hold of any admin pages I found using the creds from the registered user. A little kick pls.

Got footholdā€¦Thanks for the tap @saimson

nice box !

Took me time to get user but root is very straightforward.

Iā€™m really struggling to get a shell. It says no session was created. Iā€™ve tried everything now and canā€™t do it. Help please.

Nevermind, finally found out why it wasnā€™t working >.<

Anyone for a hint to get user? I have initial foothold and Iā€™ve been enumerating for a long time with nothing obvious for me. Thanks!

Check this out to understand the technique used to bypass the login. One of the labs explains it.