Official Photobomb Discussion

check what you can download

Could someone assist me with gaining root access? I’ve already managed to get user flag.

Rooted.
Hint for user:
Take a close look at the parameters and try to add something after them. Look at the result.
There are no LFI here. Try to find a blind command injection.
For root:
Maybe using the PATH can help?

Rooted!

Thanks a lot to @Nevuer for the hints.

For the rest of the people, I think everything has already being said here:

  • For user: Check the download request and its parameters
  • For root: There’s something the user can execute… Could we modify the PATH for it?
2 Likes

Hello, can someone help me? It’s giving me 504 time out and the nc didn’t receive the rvshell

1 Like

any hint for root ???

Any hint for user? Not getting anywhere messing with the Post data and this is supposed to be an easy box…

Is anyone able to dm me a nudge on the user? I’m as the ā€˜second’ stage and have a basic idea of something that is giving me some additional information than intended. But I have been at this for hours and haven’t been able to make progress.

perhaps u wanna inspect the site .?

ROOTED…!!! really nice box…if u guys stucked anywhere…just dm for hints…!!! :wink:

ah okay, I got user. I feel a bit dissapointed that I needed so many hints, but I spent too much time on this box :sweat_smile:.

Like everyone else said, the hints are here. The solution isn’t incredibly trivial, but also pretty straightforward.

inspect the site

Uhhh, so i’ve found the photobomb.js file but all it shows is the text ā€œouiā€ and no javascript. This just seems weird and i doubt is part of the machine, anyone know what this is or why this is?

That’s strange. Not ringing a bell for me. Try restarting the machine. I’ll PM you what it’s supposed to be if that doesn’t work.

Finally got user flag but I had to look up a writeup. There was nothing easy about that solution and I probably never would have come to it without being told. Not sure how everyone else is finding this stuff.

1 Like

Root was 100x easier than user. User was pretty tricky, but luckily I have burp suite pro which found it for me :sweat_smile: I’m not sure I would have come across it otherwise

1 Like

This one has been a challenge! When I tried to establish a reverse shell it appears to work / says the connection has been established but I’m unable to get a response back when I run commands.

Edit: finally got user!

Error code (500 Internal Server Error) when I try to go further with params. Is it a vm error?

Finally rooted!!! Great box.

Keep always network concepts! Owned :sweat_smile: