Official Sea Discussion

Having a many attackers on the machine is curse and a blessing. The look at what the exploit is trying to do.

no this machine is not easy

1 Like

Can someone please share some hint instead of saying they got the foothold and that it is easy.

1 Like

I feel like I’m very close, but I can’t for the life of me figure out where my script gets uploaded to.

maybe a form

Rooted! Took me a while

I am really trapped in this machine may be need help now every time I tried to get sh3ll from website it does not work??
Any hint?

try to get cookies and not a shell, then perform manual rce if you can’t get rce

4 Likes

ok, i will try it

Is there a way I can completely reset this seasonal machine? The issue is that even after resets, the exploit endpoint still remains there. My assumption is that it should clear by itself…I am not sure if any other player triggered the exploit and I merely used it for foothold!!!

PS: Can someone please try and check if the machine resets to default clean slate after switching VPN/resetting?

For me the box does not reset to a clean default state - How can I fix this? Please help.

Okay the machine is easy because we do not have to exploit anything for foothold → Everything is already there. We just need to call it. The software is built and shipped with exploit LOL
This does not really makes sense - what a rabbit hole this is.

2 Likes

Is the machine working properly?
I get some responses from the XSS but if i try to request for example /test from my server, it dosen’t work and i still recive responses only for /

@insomnia 's hint above about the cookies is what got me in there

2 Likes

Rooted. From my point of view, the root is ā€œVery Easyā€. However I did not get root access to the machine, just read a flag.

UPDATE : after reading a source file, get root access too.

the dir’s are all in the html source… remember some OS’s are case sensitive too!

Hi, can i dm someone about the foothold? Im stuck with the cookie stealing.

Wow :rofl:. It is true. The reverse shell is already in a box after restarting.

1 Like

got root, thanks @Ashishgupta and @SouLXIX for reminding me that I’m an idiot :slight_smile: kidding, thanks guys

2 Likes

if you did what I did in the same way you can do a lot more, just tweak the payload

1 Like

It might be necessary to reset the box so that you may submit forms successfully.

1 Like