help me with root please
I have the reverse shell and I have the password of the user but I cant find the location of the user flag.
any hints would be appreciated
yeah, it was a hosts issue, resolved it after quite a while
please i try all but cant reead root.txt
you are trapped, try to get out. maybe there is some info or something on the shadows to go to the main lobby
any one can make privilege escalation from Michael to john to can read root.txt that is make me stuked to get root because Michael not has sudo privilege ā¦ any help in that point i hacked Froxlor but stuked because Michael not sudo
Definitely an interesting box.
User: this was pretty easy, use Google, and then for āprivescā you donāt need a script just think thatās the first thing you look for.
Root: Weirdly, I could not get the exploit for which this box is named to work. But you donāt need to. Ask yourself: What is it you actually want and where is it? Treat it like an LFI instead. Cheating, perhaps? But it works.
Look around Froxlor carefully, reach through each tab. Then remember what nmap said.
āresolved it after quite a whileā? For me the error message still exists. Pretty depressing if this isnāt fixed soonā¦
There isnāt a problem with the machine, try editing the /etc/hosts file
someone put root.txt in userās home directory lol
I am receiving the below error , after i port forwarded froxlor to my localhost.
Can anyone help with this ?
Domain not configured
This domain requires configuration via the froxlor server management panel, as it is currently not assigned to any customer.
Please ask your provider/hoster if you have any questions.
I have the same problem did you find?
a hint to connect to the f**** panel?
a hint to connect to the f**** panel?
I have reached Froxlor and got stuck. I would appreciate any hints or advice to continue and log in to the form.
when i open localhost:*** why im getting localhost:****/notice.html not login page like i see at the localhost ctf machine ? anyone know ?
Couple of options:
- Update your /etc/hosts file with the new domain
- Create an intercept/replace rule in Burp to change the Host: header to the new domain
Iām not sure I solved root the intended way. Was 2FA required? Because thatās what I needed to complete the box. If not, can someone DM me how they did it?
Got it eventually. The user flag was nice and straightforward but I admit I needed some help on the 2nd part of the root flag after getting to the 2nd subdomain. Some may find it easier than me but I had a really rough time!
PSA: if you get to the end, after restarting, it may take about 3-5 minutes to see some changes!