Official Freelancer Discussion

Yeah I just did another box a couple days ago that abused the profile picture and im kinda hung up on it that attack vector :skull_and_crossbones:

I didnt know much of IDOR Vulnerabilities and am reading up on that. That looks more like the correct path like you and @tekila84 said. Thank you.

i cant run nc to get shell it say The system cannot execute the specified program

Look for a tool on the admin page you found

1 Like

qr scan what next

login as employer account after recovery what next

Hi, can anyone tell me how to figure out the admin’s user id for the IDOR vuln?

Hi tekila84,
I’m stuck with initial foothold any help would be very helpful.

Thanks

I’m stuck with initial foothold, please help

If anyone can give a nudge I’d appreciate it. Stuck on initial foothold, I have an employer login and I’m working on the IDOR but I’m stuck trying to parse the correct otp link to get admin; cyberchef is only getting me so far :frowning:

Totally clueless on user xD
Am i blind? No useful privs on svc acc, cant see vector xD
Is it AD related? :smiley:

Try enumerating for some files

1 Like

Hi, how to figure out the admin user id for performing idor attack?

You can find ids by profile image urls. Or blog, comment, click username. Then burp intruder for example :slight_smile:

1 Like

Was able to login as admin on freelancer site, but really stuck on where to go from here. Having his account doesn’t offer anything…

1 Like

You have to login to the brutefored directory, and there you will find some terminal

nvm, we got it with some help from @hiperlinx - working on getting a shell now.

Anyone knows where I may read up on antivirus evasion techniques?
What are the common tools you use to get a a reverse shell that does not get detected?
I have been using all sorts of combinations of encoders from msfvenom to no avail.

1 Like

there is one base64 string you can try idor with it i am also stuck on it trying to use it with intruder always the different result

SQL terminal is killing me. Current user has no permissions. Any tips on priv esc here?

Still can’t find any IDOR with success response.
Had a base64 token that partially decoded to something readable yesterday, but now nothing.