Official Sightless Discussion

yes

Heya, I am kinda stuck on where to do the injection - I assume that the subdomain webapp thing, but I don’t have a connection there so it’s kinda not doing anything? do I need to setup like a mock connection there? I’m kinda confused :smiley:

Busca en youtube descencriptar s

yes. take a closer look at the links.

Did you enter it into your /etc/hosts?

yes, I can open the website and opened the subdomain website. But that subdomain website doesn’t have much in it and idk where to inject, I tried the obvious and didnt work :((

Take a look around, try find version numbers ect

I get the whole combining of certain files, got it, but simply can’t decrypt the pass for a certain user. It’s just running forever

Does someone can dm me to explain ?

1 Like

Read the source. Follow the lines of code, and you shell find the path.

I am one step after that. Looking in the shadows

1 Like

Fun and super easy box, took me more hard times to find the time to do it than actually doing it, I did had some formatting issues on the B***d X because I’m blind and did not see one crucial thing to modify, and wanted to do it the intended way with the actual POC instead of the other faster way. But overall fun and easy. Happy Hacking! dm me for tips here, in Matrix or Usenet.

TIP: for Froxlor, find a crucial server status to see if your payload is working… or at least is been run, will help you a lot.

2 Likes

Finally Rooted
Very fun Easy box, maybe I also found root a bit twisted close to a Medium
I dont know if mine was the intended path but seems like it since what I found was not at plain SIGHT :wink: And also everything I abused was straightforward you only have to look over and over…

Feel free to DM for a hint if you are stuck

4 Likes

Any hints for the docker escape? I’m root, but unsure how to escape

Some hint on root please?

Search in the shadows of the box when you enumerate. And yes, that is a real hint :slight_smile:

8 Likes

How do you find the CVE for that subdomain found. I don’t understand what you search to find it.

1 Like

Look around for version numbers

is it right to use hashcat for PE?

1 Like

I’m getting the same, even in the docker instance, have you figured it out?