Official Clicker Discussion

can i dm someone about user? been stuck for hours…

Hey can i get help with user?, found what i need just dont know how to use it

Hi fiends.

May anyone help me with the user? I already have a shell, but I don’t know how to continue.
I have few possibilities and no one of them seems to work.

Thanks in advance :wink:

would you mind sharing? at the same stage, got the shell but dont know what to do, already saw that executable but dont know what to do with it…

Try to decompile it and see which options you have

any one may help to get root?, stuck since yeasterday

what academy modules should i learn to crack this one?

Some NFS and SQLi is required to get some decent foothold over the webapp but I don’t know anything that is required beyond that for now

any nudge for user please!

Finally rooted it !
a Great hint for root is asking your self why they give you this ability

hey! I got RCE in webshell… how you get reverse shell with nc? i try but dosn’t works.

thanks

some “key” value has to be injected right? also, be mindful that registered users get deleted pretty quickly.

Can someone tell me how to bypass quote, I’m going crazy and can’t do sqli

Hi,I want to know how to mount the /mnt/backups/? I use “mount -t nfs -o vers=4 10.10.11.232:/mnt/backups/ ~/”,but return error “Operation not permitted”

sudo

i am already root…in kali

sudo

This should help. NFS Enumeration (Port 111, 2049) - OSCP Notes
if you haven’t set the hostname in /etc/hosts you can do that too if it’s easier.

thanks,i already set the host in /etc/hosts.Then i tried "sudo mount -t nfs -o vers=4 clicker.htb:/mnt/backups/ ~/" . This return same error:mount.nfs: Operation not permitted :cold_face:

I ran your command exactly and it worked for me… I tried looking around for you but I’m not seeing anything other than maybe update, check permissions on the folder, look at logs. You can try sudo mount -v -t nfs -o vers=4 clicker.htb:/mnt/backups /mnt/nfs to for verbose output and see if anything makes sense. Sorry, @fanxiaoyao. I wish I had a better answer.

1 Like