Official Format Discussion

Hello All,

Can someone dm and give me a sanity check on root?

Thanks!

Got it rooted.

dm

Hello all,

I have managed to get pro account and I think I have spotted the path to get a reverse shell. Although I pass the tests the application uses at the start of the vulnerable page and see my payload in the blogname, my payload does not seem to run. Is anyone available for a sanity check?

Thanks!

Hi,
Where is the flag in Busqueda? Hack The Box
I have access but don’t know where to search…

user flags are in /home/user and root flags are in /root/root.txt

So it’s always in a text file?

the point of every box is to get a stable shell both as user and root to freely browse the filesystem and read the flag files
so yes they are always in files at least in machines, for fortresses and such it could change

ok thank you

1 Like

How did you guys get a shell after getting pro? Everything I upload gets a defined mime type as the extension which I dont see how I should be able to change it. Bypassing the check is easy, but it wont get stored as this extension

got it, something I thought I tested before I did not test enough

Hi there!
I understand what i need to get, but i don’t know how. (Struggling around 6 hours)
Can someone DM me: UndecimoDia#1532

Your comments are a breath of fresh air, always spreading knowledge and positivity. <3 Thanx

1 Like

Is log poisoning a good path?

It shouldn’t be, try to refer to the machine name and format your way :smiling_face:

Im still not sure how to communicate with redis. Using the CLI i can’t even ping the server. Which direction do I need to go?

yes :slight_smile:

Unable to resolve microblog.htb and app.microblog.htb

dumb question, have you added them to your hosts file?

Sorry. First timer. Do they have some specific dns servers that need to be added to hosts ?

You should add an IP that’s displayed after starting machine