Yeah I just did another box a couple days ago that abused the profile picture and im kinda hung up on it that attack vector
I didnt know much of IDOR Vulnerabilities and am reading up on that. That looks more like the correct path like you and @tekila84 said. Thank you.
i cant run nc to get shell it say The system cannot execute the specified program
Look for a tool
on the admin page you found
1 Like
login as employer account after recovery what next
piyush
June 3, 2024, 8:14am
68
Hi, can anyone tell me how to figure out the admin’s user id for the IDOR vuln?
0xalam
June 3, 2024, 9:59am
69
Hi tekila84,
I’m stuck with initial foothold any help would be very helpful.
Thanks
0xalam
June 3, 2024, 10:00am
70
I’m stuck with initial foothold, please help
If anyone can give a nudge I’d appreciate it. Stuck on initial foothold, I have an employer login and I’m working on the IDOR but I’m stuck trying to parse the correct otp link to get admin; cyberchef is only getting me so far
Aleee6
June 3, 2024, 11:30am
72
Totally clueless on user xD
Am i blind? No useful privs on svc acc, cant see vector xD
Is it AD related?
Try enumerating for some files
1 Like
piyush
June 3, 2024, 12:42pm
75
Hi, how to figure out the admin user id for performing idor attack?
Aleee6
June 3, 2024, 2:11pm
76
You can find ids by profile image urls. Or blog, comment, click username. Then burp intruder for example
1 Like
Was able to login as admin on freelancer site, but really stuck on where to go from here. Having his account doesn’t offer anything…
1 Like
You have to login to the brutefored directory, and there you will find some terminal
nvm, we got it with some help from @hiperlinx - working on getting a shell now.
mokko
June 3, 2024, 3:03pm
81
Anyone knows where I may read up on antivirus evasion techniques?
What are the common tools you use to get a a reverse shell that does not get detected?
I have been using all sorts of combinations of encoders from msfvenom to no avail.
1 Like
there is one base64 string you can try idor with it i am also stuck on it trying to use it with intruder always the different result
SQL terminal is killing me. Current user has no permissions. Any tips on priv esc here?
bsnun
June 3, 2024, 3:54pm
84
Still can’t find any IDOR with success response.
Had a base64 token that partially decoded to something readable yesterday, but now nothing.