Official Trick Discussion

how to get admin login and password
or bypass

In need of a hint/nudge I found that with a certain ā€œmapā€ I can read files but that takes a very very long time so Iā€™m not sure thatā€™s the right way. I have some source files as well but donā€™t know if Iā€™m supposed to analyze them to figure something out and I also have two subs donā€™t know if there is more or not.

FOR EVERYONE:

There are 3 subdomains

If youā€™re stuck, youā€™re probably missing one :face_with_monocle:

I am stuck on getting the foothold. Through dns, i got one subdomain. But dont know what to do further.
I have done url fuzzing and even tried smtp recon, but found nothing. Please provide me a nudge

found subdomain, now stucked on admin panel tried default credentials but not worked any hint plsā€¦

I found a domain through DNS service. However, I canā€™t find a valid subdomain using the vhost. Can anyone send me a DM?

Can someone give me some tips iin how to get the L* I , found two types of X**, ā€œS * Liā€ , but cannot get the L* I and cannot keep looking for the next subdomain.
Iā€™ve tried to enumerate DNS as much as i could but only found 2 subdomains, so maybe with the L* I I can get what i want.
THXX

I am stuck on the ad*** panel got the creds as well but donā€™t know where to get from there, can someone drop me the hints :slight_smile:

You can try ā€œdefaultā€ configuration files.

There are lots of way to read files from the file system.

1 Like

is it using ***map?

I didnā€™t use that tool but the technic was the same.

I canā€™t find anything :slight_smile:

hello, iā€™m adm********** on the adm** page, but i donā€™t know what to do know.
someone could please give me a hint on how to precede ?

1 Like

This admin page is a rabbit hole, find anothers subdomains.

used diffrent tools and diffrent pretty big wordlists for the DNS fuzz found nothing. Any leads ?

Other ā€œpreā€ subdomains. may exist.

1 Like

I think I got user access an unintended way. People here talking about an admin page in the p****** web, and I didnā€™t have to even touch that web to get user.

iā€™m sorry but I never heard of a ā€œpreā€ subdomain

Have you enumerated all ports?