Official Shoppy Discussion

Hi,

This is my first time posting on forums, apologize if I make any mistakes. I need some help.

I’ve hit the page where you need to perform injection, however all I get are bad gateways. I’m not familiar with *** or nl. I’m trying to learn how to tweak the injection payload and using burp’s intruder to automate requests. Without having to take a nl course, how does one even know where to tweak the payload? I’ve tried everything I could find on Google, even other’s writeups, and they don’t explain how they’ve got to the conclusion as well. I have a feeling I’m not learning anything anymore and just wasting time. I could just use the online writeups injection, but I would rather prefer learn why it works, the resource used, or how you made the resource yourself. etc.

Thanks

bypassed auth found some md* h**** got one (j***) but the other (a****) may require some real effort. I know user account on the box but the creds I have don’t match. Do I need to brute or dic both h****? I really don’t want to spend the effort going through an actual brute force if it is not necessary.

Finally rooted.

For foothold:

  • getting timeouts? Try switching up the parameter your tweaking. Sometimes values are hashed ya know :wink:
  • maybe there’s more than one site running… Try enumerating with some wordlists

For root:

  • Dig into info you uncovered from the foothold… and explore what the user is capable of

Rooted.

Fun easy box, DM if need help.

Hi there,
I’m stuck after finding the hashes. I look up what comes next in some writeups and i cant find this m**m subd. I used almost 15 different wordlist to brf and gobuster, fuff, wfuzz and dnsrecon and nothing. How did you get it?

EDIT: got one!

Which too you suggest? Which Wordlist?

Managed to root the box! It’s my first :slight_smile: Messing around with /etc/hosts was the biggest hurdle for me in the end :see_no_evil:. One problem though; both the user.txt and root.txt are not accepted by HackTheBox, does anybody else have this problem? I cannot reset the machine as the reset limit is reached for today… So I’m not sure if somebody changed the flags. You are supposed to submit the hash right?

1 Like

Hey can you help me pls :slight_smile:

Seclists DNS

1 Like

Just use a basic injection. Maybe the operator “OR” can be written in another way.

1 Like

Anyone got a quick sec for DM help on foothold? I feel like im almost there.

Im getting timeouts and iv tried switching the payload to other parameters, I don’t understand how hashes come into play. I mean, I understand that the **sql database is most likely storing hashed passwords, but im not really sure how my injection technique can take that into account?

Please can I request some help. I have found the hidden subdomain and service running on the non standard port. I am convinced I need to do something with the URL for the service but I can’t find anything in my research.

Thanks

The login form injection for this seems anything but straightforward. It is definitely a bottleneck in the process and can bog people unfamiliar with injection (myself) down for hours or days. Is anyone willing to discuss at least what tool they used to accomplish the task?

1 Like

Rooted! DM me on discord (n3hal#1527) if you need a hint.

I would like to second this as I’m currently stuck on this step. Few people in this discussion mentioned that the solution didn’t make sense to them, even when they found the working payload. Spending hours on a pure brute force method seems to me like a waste of time, because it won’t teach me anything new.
I would be grateful for any hint, which would help me to approach this in a systematic way.

i have the same problem bro

Hi,
is there someone to write a direct message to?
I found the solution for the first “problem”, but I only found it through a walkthrough in google. I’d like to understand how you found a solution.

I need help, i got the export file downloaded with the creds, and trying to connect ssh with creds given, please help

Hey, I am stuck at this as well. How did you get the result - I have also tried a lot of different solutions, and looked at writeups, but nothing - only when I add the subd to the hosts file, it works