I found root creds in keepass, is that a rabbit hole?
This was a very peculiar experience indeed.
If the entry point is from the ( sqlpad) itâs just the starting line
Has anyone encountered an ECONNREFUSED error while exploiting the CVE? I tried using a public RCE exploit I found on GitHub, which generates a shell, but when I attempt to execute it myself using Burp, I keep receiving an ECONNREFUSED error
Yep itâs normal you have to adapt the payload
alleged f***** entry point but i cant for the life of me find an admin panel, only a notice that the domain isnt configured. did somebody vandalize or am i missing something?
Please tell me how to forward ports from the machine. I do ssh -L port_form_me:localhost:port_machine user@ip but it doesnât work.
For exemple :
ssh -L 9999:localhost:8080 user@domain.htb
â add bla.domain.htb at the end of 127.0âŚ1 on /etc/hosts on your working machine
â go to your navigator web
Itâs a basic setup for ssh tunneling
You can also use tool like chisel or ligolo For easy setup like this or more complex structure
Thanks, I will definitely try it today
This is where I am at. I have root in container and a cracked pass from shadow but cannot for the life of me figure out the next step to escape.
Thatâs the point you donât need to escape, youâve the credentials just use them
The answer is in the nmap scan youâve done at startâŚ.
I know what I need to do in the admin panel(D-T-s) but I donât know which ports to add.
Has anyone fixed the âDomain not configuredâ?
I am stuck after getting the rev shell, any tips where I should go next? I tried linpeas but I cant find anything, nothing in the home directory only a dir called âm******â and the root is empty, am I in the right place? Did I overlook something, help :,)
you did, re read this discussion then re read your linpeas result, the hint was given multiple times
Found it just now, I shouldâve paid more attention
Work out what type of hash it is that might?
i got an intial access but it turned out to be a whale jail which wonât let me do much.
In its shadows however, i found something i fed the cat with (it liked just r** not m**, maybe iâm missing the correct recipie) and another thing which could be used with the pad. Using the pad i found some more i could feed the cat with.
none of those led to an open door on the 2 ports starting with â2â.
Reading through the previous messages one could assume for more ports somewhereâŚ
I really need a nudge to carry on. thanks
replying to my self: turns out john sees things a cat doesnât
The root part is not that easy for a easy box, but here we go