Official Freelancer Discussion

So rushing to sql console and trying to crack the found user hashes is a waste of time? :confused:
~8min left said by hashcat so i will find out soon :sweat_smile:

No cracking is required to user

1 Like

Yay cool :slight_smile:

Look for xp_cmdshell

Oh sh!t i always overcomplicate :sweat_smile:
So it kind of svc acc->user->root?

yep until user it is.

I have used the release arena to no avail, I bit the bullet and got Vip+, it works now. a bit pay to win but I was fortunate enough to be able to shill the extra cost. After getting port 80 it is fairly straight forward. I wish you the best of luck mate!!!

1 Like

Could any of this be related to DDoS? I see there is a HTTP/2 and even on a VIP+ fuzzing causes 503 after a few mins. Are we accidentally DDosā€™ing the box? And on the free tier is this why no one else is able to see the port??? Lmaooo

Stuck at admin panel. Canā€™t execute windows command

fucking xp_cmdshell doesnā€™t work

Same xD cant enable it. No perm. I dont see how could we use it :slight_smile:
Im in with id 2, johnhalond, admin, superuser. Idk. We must overlooking something trivial i guess :slight_smile:

Still trying to find a SQLI entry point.
Tried SQLMap with different request files and none of them returned nothingā€¦

Anyone have a hint for what to do once we have an employer user?

You have to scan some code, then find the IDOR Vuln, In that code/link, to make your user admin, which you would then later login into the brute forced directory that you have found

2 Likes

Let this be a lesson to others never to miss the equals sign when copying values!

1 Like

Is XSS required on the recovery pages? If so can i get any hints please. Do I have to do both freelancer and Employer or just one?

No, XSS not required. Definitely need employer so far.

1 Like

for the fucking second part which program did you use? volatility fucking giving nonse errors that are unsolveable

Is the profile picture a rabbit hole or is that how I proceed ? becuase trying to get exiftools to play nice is frustrating Lol.

1 Like

i donā€™t think you need it?

1 Like

Apparently so. Went through this rabbit hole yesterday and realized it wasnā€™t storing the file.
Ran Ffuf for the profile picture name, got a couple that could be accessed, but nothing useful.

Got an admin page and with the hint from @tekila84 I presume there is a Back End script that could make the registered user an admin, but Iā€™m busting to find something.
Running Feroxbuster trying to find anything useful. From the source code I couldnā€™t find anything as well.

1 Like