ah thank you for this, got the user shell
trying it out now
any hints?
should I feel blind at this last part before what I assume to be user? Or am I overlooking something? Try harder?
have you managed to pass the token? I’m still strugglin’ with both postman and g****url
Stuck at will update soon for several hours now, can someone give a hint ?
Should i Brute Force the json data after login? If someone knows please dm me. Thanks
no bruteforcing required
any hints? im stuck in the message :" Will …"
You can DM me, I’ll help you there
Hey guys, so I registered and logged in using g*******. But where I do I get my token? All I am getting in the response is an ID.
You can DM me
You have to get more info, check the manual with -help for more verbose.
Hey guys! I’m wondering if I could get some help with root on this box?
Summary
post LinEnum I can see the p****d service but cant seem to exploit j***y vuln. Am I on the right track
Finally got User.txt, spend a lot of time fiddling due to my carelessness .
Rooted! Easy-medium box; would be piece of cake if the technology on the weird port doesn’t forces you to learn and understand what is and how it communicates with the server. The rest of the box was easy, and the root was just piece of cake. Google, google, google and eventually you’ll root this box! Thanks to Anonymousdestroyer for the hints and, as always, PM if you need help! I enjoy helping so we can all learn together.
Finally Rooted!! Thoroughly enjoyed the box, initial user was a bit tricky and took a bit of tampering. But root was easy. Thanks to @Dark0x3 and @Ab1z3r for the tips!
i stuck in the message
Hey, I’ve just got to the ‘will change soon’ part, any hints?
What do you think the server do with the id?