check what you can download
Could someone assist me with gaining root access? Iāve already managed to get user flag.
Rooted.
Hint for user:
Take a close look at the parameters and try to add something after them. Look at the result.
There are no LFI here. Try to find a blind command injection.
For root:
Maybe using the PATH can help?
Rooted!
Thanks a lot to @Nevuer for the hints.
For the rest of the people, I think everything has already being said here:
- For user: Check the download request and its parameters
- For root: Thereās something the user can execute⦠Could we modify the PATH for it?
Hello, can someone help me? Itās giving me 504 time out and the nc didnāt receive the rvshell
any hint for root ???
Any hint for user? Not getting anywhere messing with the Post data and this is supposed to be an easy boxā¦
Is anyone able to dm me a nudge on the user? Iām as the āsecondā stage and have a basic idea of something that is giving me some additional information than intended. But I have been at this for hours and havenāt been able to make progress.
perhaps u wanna inspect the site .?
ROOTEDā¦!!! really nice boxā¦if u guys stucked anywhereā¦just dm for hintsā¦!!! ![]()
ah okay, I got user. I feel a bit dissapointed that I needed so many hints, but I spent too much time on this box
.
Like everyone else said, the hints are here. The solution isnāt incredibly trivial, but also pretty straightforward.
inspect the site
Uhhh, so iāve found the photobomb.js file but all it shows is the text āouiā and no javascript. This just seems weird and i doubt is part of the machine, anyone know what this is or why this is?
Thatās strange. Not ringing a bell for me. Try restarting the machine. Iāll PM you what itās supposed to be if that doesnāt work.
Finally got user flag but I had to look up a writeup. There was nothing easy about that solution and I probably never would have come to it without being told. Not sure how everyone else is finding this stuff.
Root was 100x easier than user. User was pretty tricky, but luckily I have burp suite pro which found it for me
Iām not sure I would have come across it otherwise
This one has been a challenge! When I tried to establish a reverse shell it appears to work / says the connection has been established but Iām unable to get a response back when I run commands.
Edit: finally got user!
Error code (500 Internal Server Error) when I try to go further with params. Is it a vm error?
Finally rooted!!! Great box.
Keep always network concepts! Owned ![]()