yes
Heya, I am kinda stuck on where to do the injection - I assume that the subdomain webapp thing, but I donāt have a connection there so itās kinda not doing anything? do I need to setup like a mock connection there? Iām kinda confused
Busca en youtube descencriptar s
yes. take a closer look at the links.
Did you enter it into your /etc/hosts?
yes, I can open the website and opened the subdomain website. But that subdomain website doesnāt have much in it and idk where to inject, I tried the obvious and didnt work :((
Take a look around, try find version numbers ect
I get the whole combining of certain files, got it, but simply canāt decrypt the pass for a certain user. Itās just running forever
Does someone can dm me to explain ?
Read the source. Follow the lines of code, and you shell find the path.
I am one step after that. Looking in the shadows
Fun and super easy box, took me more hard times to find the time to do it than actually doing it, I did had some formatting issues on the B***d X because Iām blind and did not see one crucial thing to modify, and wanted to do it the intended way with the actual POC instead of the other faster way. But overall fun and easy. Happy Hacking! dm me for tips here, in Matrix or Usenet.
TIP: for Froxlor, find a crucial server status to see if your payload is working⦠or at least is been run, will help you a lot.
Finally Rooted
Very fun Easy box, maybe I also found root a bit twisted close to a Medium
I dont know if mine was the intended path but seems like it since what I found was not at plain SIGHT And also everything I abused was straightforward you only have to look over and overā¦
Feel free to DM for a hint if you are stuck
Any hints for the docker escape? Iām root, but unsure how to escape
Some hint on root please?
Search in the shadows of the box when you enumerate. And yes, that is a real hint
How do you find the CVE for that subdomain found. I donāt understand what you search to find it.
Look around for version numbers
is it right to use hashcat for PE?
Iām getting the same, even in the docker instance, have you figured it out?