Official Chemistry Discussion

DM me

That’s the assumption that makes the most sense, I guess. But I don’t know. Even if you could automate the whole thing or a big chunk of it, and account for every possible scenario (including a CIF file), the runtimes seem too good to run all steps to reach the flag with its different possible options. I have a hard time believing in such ā€˜miraculous’ scripts, but I’m probably wrong :monkey:

Maybe there’s another way in that doesn’t have anything to do with the apps or services of the challenge, but with the box itself.

How did you make the list, is it available anywhere? It sounds like a good idea, just wondering if there’s a quicker way of grabbing it than manually copying each payload!

Found a PoC for exploiting a CIF file, swapped the code with a reverse shell payload from reverseshell.com. I’ve got my listener running on my host, tried running it on the server, and even tested different payloads with Burp Intruder, but I still can’t get the code to execute through the CIF file. Any idea what I might be doing wrong?

I used the sh based reverse shell payload in file upload but getting an error of 500 internal server so how to fix it any leads ?

hi everyone, just started this machine 2 days ago. At that time i got also 8080 tcp open, now i cant see it open… is there a problem with the machine or thats for real?

real.

1 Like

Search ā€œCIF file exploitā€ in Google and look the code

Who can I DM for help?

DM me

What payload are you using?.. use the Busybox payload if you aren’t already and make sure your using sh instead of bash.

I have found vector to come to machine. but when i use poc file it returns 500 internal error. anyone help me? i use cif file poc.

Maybe that’s a big hint, idk.

First: Google ā€œCIF file exploitationā€ and look at the code to see where to place the payload correctly.

Second: Encapsulate the payload to make it work

Good luck

check your netcat listener for a callback…

I opend port for reverse shell. but i can’t get any callback… i used bash, nc reverse shell but nothing come back…

DM me

1 Like

I can’t see the upload option in the site.
only login and register is there

you need to register first