Official PC Discussion

yeah I’ve assumed it’s injectable somehow but im just not sure how exactly

edit: nvm, figured it out

Arrived so late for this one, I confess the ports scared me a little, but it was a sweet cake after I could see it

I believe it is the breeze before the storm which looks to be coming, the machine scheduled for the next week looks creepy :sweat:

Besides, if anybody needs any help, R is always here :heart:

2 Likes

Hope I can help people on the discussions again, here are some details that may help you, classic Raquel’s little tips :heart:

  • If you have no idea what you are dealing with, search google, after you find it, search the same along with “tool” or “exploit”
  • Doesn’t only a ssh port and another one for communications with a database look suspicious? Maybe there are more, linpeas will show you, but you are also able to execute a little command to enumerate
4 Likes

Can I DM, I’m somewhere close to gaining foothold

At anytime you wish :heart:

1 Like

hello R good evening, could you help me please?

I’m stuck with the token and I’m not able to export a .proto file to use in postman

Of course, it depends on what exactly you are trying to get :sweat_smile:

.proto was not needed for me, you should be able to get it working using the tools designed to communicate with the service :smiling_face:

3 Likes

Guys, I was able to perform all the interactions with the services, but when I try to use the credentials to authenticate on the machine, it doesn’t work, could someone help me

1 Like

If you found the obvious user, then there is another one. There’s more than one user.

2 Likes

Hello i was stuck on the nmap, i just see ssh and 50051 port and i trying to see website server it gives me broken text what should i do ?

you can’t use netcat for every service, many of them have a specific method/tool

same bro i tried to connect with nc with -n or -u but no sign , anyone can help me?

1 Like

same here, it’s weird…

unable to use token,tried several thing with token,as api key also used after removing b’ continue getting type error and other error

1 Like

Anyone could help me about the first port? I using tool g**url and login with my account, but when I invoke methed get****, it always shows error missing header. But I used option about header and with base Authorization, where my fault?

Hi, can I DM you? I’m kinda stuck on the reconnaisance phase. Nmap isn’t giving me anything valuable for some reason.

DM is OK, about nmap :slight_smile:
And I passed the error about missing header! I was so stupid that not showed detail message to missed important strings, so I used the token strings that was created by myself with base64…

thats the normal functionality

I have the same thing. Quickly got to this point and then I don’t know what to do. I was thinking about sqlInject or some kind of brute force but I don’t think I’m on the right track

Same here…