It did take a while. Finally got it, thanks!
Hi Erebus. Have a look at the web challenge āTemplatedā
Having trouble with foothold although I know what I need to do.
Am I supposed to upload different images multiple times? Because I have to figure out the indices of the s__classes? Or is there an easier way? Iāve never exploited S__I before.
Just got user after a lot of trial and error, couldnāt get a shell but I got the flagā¦ Iāll take it!
Thank you @M3rlin !
broda still trying
i too solved templated in challenge box
Iāve been stuck for some hours. Iām at the site and have gathered how to attempt to try running commands. Running them as the f*** name runs, but running them in the im*** doesnāt work because the environment is sanitized or something? I tried using container tags to cancel it and just run the code but that didnāt work either. Iād greatly appreciate anyone who could pm me or just point me in the right direction.
The RCE is a little bit annoying, it took me over an hour to make the RCE work.
A good tip here: submit your command WITHOUT the {{, so you can ātestā and see if the OCR is interpreting your font properly. Only after having the string being properly parsed, then add the {{ and try to execute.
Youāre welcome
Courier 36pt works like a charm
Can i get any hints on how to escalate? Has it something to do with the awsomely given path?
ok now i think im grasping what it is actually doing somehow manage to print simple text like 7*3
Can I ask, what app did you use?
Gimp the Box doesnāt seem to want to work.
Rooted! That was fun.
I canāt really think of a hint that doesnāt rehash what is already here. Anything Iād say would be giving too much away I think.
If you need a nudge though, feel free to dm me.
I used gimp ā monospace 36pt
works like a charm
Finally Rooted
The first part of the machine was clear. It is easy to āfindā the vulnerability, but it is disgusting the number of tries I made.
Root is āeasyā, you only have to make a good enumeration process to know what is going on.
Rooted! Canāt really offer too much more than others already have. @ruderabbitās hint was super helpful.
Shoutout to @lvruibr for the sanity check on foothold.
As always, feel free to reach out for help but let me know what youāve tried!
2 ways to root, intended and unintended.
iām stuck upload page, i need help
this is stupid ā or I amā¦ didnāt find a stable way to deal with __or`Ā“ā ā at least now I know the sum of 7times7 (:{)