So rushing to sql console and trying to crack the found user hashes is a waste of time?
~8min left said by hashcat so i will find out soon
No cracking is required to user
Yay cool
Look for xp_cmdshell
Oh sh!t i always overcomplicate
So it kind of svc acc->user->root?
yep until user it is.
I have used the release arena to no avail, I bit the bullet and got Vip+, it works now. a bit pay to win but I was fortunate enough to be able to shill the extra cost. After getting port 80 it is fairly straight forward. I wish you the best of luck mate!!!
Could any of this be related to DDoS
? I see there is a HTTP/2 and even on a VIP+
fuzzing causes 503
after a few mins. Are we accidentally DDosāing the box? And on the free tier is this why no one else is able to see the port??? Lmaooo
Stuck at admin panel. Canāt execute windows command
fucking xp_cmdshell doesnāt work
Same xD cant enable it. No perm. I dont see how could we use it
Im in with id 2, johnhalond, admin, superuser. Idk. We must overlooking something trivial i guess
Still trying to find a SQLI entry point.
Tried SQLMap with different request files and none of them returned nothingā¦
Anyone have a hint for what to do once we have an employer user?
You have to scan some code, then find the IDOR Vuln, In that code/link, to make your user admin, which you would then later login into the brute forced directory that you have found
Let this be a lesson to others never to miss the equals sign when copying values!
Is XSS required on the recovery pages? If so can i get any hints please. Do I have to do both freelancer and Employer or just one?
No, XSS not required. Definitely need employer so far.
for the fucking second part which program did you use? volatility fucking giving nonse errors that are unsolveable
Is the profile picture a rabbit hole or is that how I proceed ? becuase trying to get exiftools to play nice is frustrating Lol.
i donāt think you need it?
Apparently so. Went through this rabbit hole yesterday and realized it wasnāt storing the file.
Ran Ffuf for the profile picture name, got a couple that could be accessed, but nothing useful.
Got an admin page and with the hint from @tekila84 I presume there is a Back End script that could make the registered user an admin, but Iām busting to find something.
Running Feroxbuster trying to find anything useful. From the source code I couldnāt find anything as well.