Official OpenSource Discussion

no. Backend box is only hint for foothold, has nothing to do after that.

you should have a credential in hand. if not, back to enumeration and review what youā€™ve got, it is hidden somewhere.

1 Like

hey i dont find any link im stuck at LFI pin exploit can anbody help where can i find that link

I also got stuck in L**, can anyone give me some hints, thanks

Can anyone tell me how to use the secret encoded string?

no I found the encoded string on c pageā€™s s code but it should decode to give the p** to use c

can anyone help me ? im stuck in L**, can u guys give me some hints please ? Thanks :slight_smile:

/console this is the LFI i think but it is protected

is there a L** in the parameters of the c****** page?

I also got stuck in L**, can anyone give me a hint. DM me.

1 Like

Any hints where shall I look in source.

Iā€™ve got the hidden creds, but I donā€™t know what to do with them. I spent hours trying to exploit the LFI but now I donā€™t really think its exploitable. Can anyone DM me for small hint?

1 Like

I didnā€™t figure out how i can get the L**. The filter on /u***** sounds solid, so, anyone can give some tip?

Edit 1: Get the LFI, but canā€™t figure out on how i can get the revshell. Any tip?

Edit 2: Get revshell, now i need get the usercreds

1 Like

is L** the right track?

Hey Guys, looking for some help on this one- my discord is krafty1120- someone please hit me up iā€™ve been down many rabbit holes and need some assistance lol- thanks in advance

i cant find you on discord

Now Iā€™m stuck at p***t

krafty1120#7197

try to access something starting with root /

Iā€™m having trouble knowing what needs to happen next. I know that I need L** but where would I apply that?

1 Like