Official Format Discussion

As @ooscubyoo mentioned you have to add FQDN to your hosts file…
I did same silly mistake and lost half day on it :man_facepalming:

1 Like

Thabk you very much. Yes I have already added to /etc/hosts all the information of app.xxxxxx.xxx and also of the blog that I have create.
I think was a problem of connection because I have checked that I lost always the ping connection

Anyone want to help with escalation to PRO user?
Feel free to DM me

To all those struggling with pro user:
Keep in mind what type of DB is running on the background to check everything. Also that the http server is built on n***x.

Maybe it’s missconfigurated?

Google is really your friend here! try to link up both concepts.

1 Like

Need help for getting pro, please DM.

how to go from www-data to user? Any hints??

1 Like

Have tried pretty much everything I know of, but still cannot get pro…

i feel you :smiley: i can leak stuff. i kinda get the structure of the web server but i cannot figure out how to reach redis with that informations i got here.

okay, to all those struggling with the machine:

  • Foothold: As the machine creator itself said: get pro. To do so, you need to keep in mind what DB is running behind, and how to interact with it using the web page’s “Engine”, look for some obvious files… and try to link up both concepts using google. Once you manage to go pro, look at what you can do by reading the source code!
  • User: Some basic enumeration.
  • Root: Box’s name. Google is your friend. Once again, keep in mind what DB is running in the backend.

Hope y’all get it!

2 Likes

Is there someone I can PM to get a nudge on what to do after getting pro? I think I know what I need to do next but I am having some difficulties with doing that thing.

Thanks!

What is running on the system? What can’t we see? Or we can see if we want?

that’s a huge spoiler bro xD

1 Like

need hints … Simple#3503

Can anyone dm with help on foothold?

Finally rooted. This is a brainfuck if you’re completly new.
USER HINT: Read, read, read the source code. If you see what’s working on the page, the exploitation is very logic when you connect the pieces, especially when you consider the r***s db and how communicates the page with the database. Read and you’ll see how to get pro. (or maybe *set pro) :wink:

ROOT: If you’re not a master with python, you’ll need to google. There’s articles there that teaches you how to exploit the machine name!

As always, thanks to @Paradise_R for the help. DM if you need bigger hints!

2 Likes

Think it was the hardest for me to understand how to interact with r***s in the beginning to get pro :slight_smile: . I think this box is closest to hard

Anyone available to bounce some ideas on how to interact with the famous keys service?
I’ve been hitting my head to the wall trying to make this work or do anything for me.

DM me if you need help

2 Likes

Great thanks for your help, @Yovecio18 !!!

1 Like

hi ! anyone around for a nudge on getting pro?