Official Stocker Discussion

I have an idea of what’s happenning but I am still learning. I already tried adding it into /etc/hosts and it didn’t work

1 Like

Rooted! DM me on discord (n3hal#1527) if anyone needs a nudge!

2 Likes

Can’t tell if you’re being serious

1 Like

I am kidding for the NSA just a joke but I am serious for Chat GPT come on it is better to learn than doing it by an AI no what do you think anyway ? just saying no worry :stuck_out_tongue:

at the beginning me either I got trouble :stuck_out_tongue_winking_eye: for adding to the local host, please just type: subl /etc/hosts +enter it will open your local host file then write your IP address you want to access. write it down this way in your file subl /etc/hosts

#HTB
10.129.23.242 stocker.htb
10.129.23.242 dev.stocker.htb

then refresh the page or go the page and it will work

do not forget to save your file; subl /etc/hosts with your IP you added. otherwise it won’t work

warning this is the IP address I got so take the one from your HTB session it must be different I guess

I replied to you below
:stuck_out_tongue:

thanks, I already fixed it

Can inspect be used on this box, instead of burb, to finish the webpage section?

I got login page but I am stuck after that, can you please help me what next i need to do?

PM me and I’ll give you some hints. I’ve rooted this box not so long ago :slight_smile:

2 Likes

Hi, I need help I sent you a friend req

Finally rooted this machine.
Feel free to ask for some tips :smiley:

Rooted. Nice Box thanks to the creater :green_heart:.

1 Like

Just got root. User was a lot harder than root in my opinion. Very fun box though I had a good time with this.

The hints already posted here should be just about enough. Especially @Wiiz4Rd’s are good.

Couple things I’ll add:
Perhaps after you discover the frame to look through, see if you can change the size of said frame.
Also, what is running the site? You can use the wappalyzer extension to find out. This may help you determine what file to read.

Feel free to DM with questions, I’ll get back as soon as I can!

2 Likes

This box was awesome with tons of helping tips in this discussion, if anyone still struggling with this box wants some tips to get their mind in the right place feel free to dm me anytime.

Hmm I bypassed the login page, but not sure what to do next, clues seem to be referring to some kind of frame, but absolutely no idea what that means, also got logged out and can’t bypass login again, which is weird. Any pointers on what to do next, on the page with all the items, adding to basket etc.

UPDATE: Nevermind, got there thanks to some help, then got root, fun box!

Every 5 minutes the machine becomes unpingable and its hard to try any exploits… anyone have workarounds for this stuff

Edit: Switched VPN to TCP and now everything seems peachy…

I don’t know if it was intended but when I logged in there was already a privesc.** file in home :laughing:

Anyway the challenge was an interesting one, I can notice my progress when I begin to notice things I already saw on previous challenges/machines, the only thing that bothered me was that after some seconds the ssh simply stopped responding and so I had to reopen the terminal many times

Aside from that, if anyone is needing help, R is always here, just send me a message and I will reply as soon as I log in :heart:

I bypassed the login page was not that hard but I am stuck after that I know that I should be able to read some file on the server to get the password for the user and ssh but cant quite it get it right
tried every trick i know still no good, I need a hint on the right direction

I am still up and can help you if you still need it, I sent a message on private :heart: