Official OnlyForYou Discussion

hi i am stuck at lfi so i find injection point but i didnt get the payload right can anyone help me ?

Rooted. I liked this box. Learned something new. Pm me if you have any questions.

can some one help me i did not found anything in nginx config file what can i fuzz for stuck for 2 days helppp

same here !

Can some one pm me for help with lateral movement?

can i get a nudge on injecting?

Got it

Can’t say it was easy :slight_smile:

2 Likes

Done!

1 Like

Looks like I am creating a new culture, it is lovely how recently much more people are willing to help the others :smiling_face_with_three_hearts:

14 Likes

Could I pm someone for a nudge on root ?

1 Like

because you showed us sharing knowledge is a common good

2 Likes

Am I the only one who encounters constant crashes? I’m using chisel to make portwf and it stops responding after a while.

When I connect in SSH, after a certain number of seconds the machine freezes.

I’m even using a VIP dedicated environment… I’m trying to use the PwnBox and I’m still getting crash after some second inside the machine…

I’m litterally getting stuck like every 10 sec… :frowning:

Yes. Great work sir. My supeR poweR R

2 Likes

It is always good to test out your payload with some online/offline resource: https://regex101.com/

3 Likes

Finally Rooted!!!

It was hard for me but thanks to @Paradise_R @hydra11 and @podsrus i could manage.

If you need something feel free to DM me! :slight_smile:

7 Likes

si justo es esa funcion que valida el correo esta el fallo, pero hay algo mas, imagina como puedes concatenar un comando en linux

This is specially true against harder boxes… top hackers/players are all from ā€œgroupsā€ and so they can share knowledge there just easier (and they never show here on the forums)…

We, on the other hand, are usually by ourselves and have to make it through a harder path just by being alone. So why not use the forums and share some insights… of course I’m not saying to do a full disclosure (as this would also make lots of people just lazy and be waiting for ā€˜everything ready’) but some valuable insights is very helpful to at least point everyone to the right direction…

A year ago this forum was only a place for bragging for ā€œrooted!! Yay!!ā€ or ā€œI’m firstā€ or ā€œThis is too easyā€ but no help/tips/anything at all that could really help…

Either thanks everyone for helping the forums getting better in my opinion…

P.S. I saw some PM to myself but unfortunately I was away for the last 3 or 4 days… I’ll try to reply there :slight_smile:

5 Likes

I agree, thanks to everyone who added hints (without giving it away) and answered questions. I certainly would have taken a lot longer without them and I learned a lot along the way.

Edit: the links to articles and research helped me to learn whilst pointing me in the right direction. I think enumeration awareness is key here and we gain that through experience.

hello, i’ve been commenting a lot here but at least i’m learning many new things in this machine

i’m currently stuck at the c***** I part, i was able to exfiltrate information about the u*** label but it only revealed the credentials which i already had, am i missing something here? there doesn’t seem to be another label in the db but I could very well be wrong

You can dm me @adusir