Official Resource Discussion

The HTTP service on the machine is down.

Jesus christ this is hard as ■■■■

2 Likes

I had the same issue and restarted the box and tried other VPN connections and finally got one that worked. It sucks.

I’ve finished the box but have some questions. Any idea what the intended path to foothold is? I know of 2 ways but am not sure how I would have know to do them without hints.

2 Likes

Irrelevant question to one you asked but what would you rate box on difficulty scale?

Does anyone know if the admin panel has a purpose or is it a waste of time?

(for foothold)

5 Likes

The intended seems to be Globbing at the moment. Since Staff made the box i doubt we will get a straight answer until its retired.

I dont see any other method and ive beat up this box for 3 days straight.

This machine is full of rabbit holes; it should be called ‘Discard the Rabbit Hole,’ many backdoors lol ##149

3 Likes

is this from the a**** page that we can do the xss because none of mine worked ? I alse tried to abuse the 2 functions on this page but nothing too and also filter:// … it’s the same .

It has something to do with the page a***, but it’s not an XSS or an IDOR. I found several XSS and several IDORs; you’re in the right place now, enumerate parameters

3 Likes

50/50

Ended up finding XSS and some other stuff but not getting much else. Just hit a wall now

It’s not xss

Yeah I figured that, just fully hit a wall now I’ve tried a bunch of attacks but maybe I’m overlooking something.

Send me a message and I can give you a hand

That was the intended way you think? Cuz that was the most unsatisfying way to root.

I have found a reverse shell and am looking the user flag. I have found a password somewhere in the system but try as I might, I am not able to login anywhere with the password. Anyone have any tips?

no, that’s not the way, i already found 3 ways to scale, lots of backdoors lol

Message me privately (the form isn’t letting me write the same thing anymore; if you need more help, message me on IG. It’s getting tiring to write the same thing in different ways just to be able to send it) :angry: