Swagshop

Type your comment> @DameDrewby said:

Type your comment> @thewildspirit said:

i have a script that i run yesterday and it worked, now i run it, it says it works but i cannot login. Please someone pm and tell me what im doing wrong!

Chances are you used it and didn’t really work… Even though it reports it did. And someone else used it (after modification)and it worked correctly, and by chance you got in with the same creds.

yes thats what im thinking about right now

Who’s killed the box :tired_face:

Finally able to log into admin panel but I’m stuck here. Any hints on how to get a shell?

Rooted! Thank you @sarange for the help.

Finally rooted (the hardest thing was only 503’s)
User: 3h, the CMS is big, there are may be several interesting places with login forms
Root: 2 mins, siiimplest enumeration, u don’t even need LinEnum

Edited - Got my exploit script to work, so moving on from there. I was trying to make it a lot more complicated than it needed to be.

ive got access to the admin panel, unsure of how to get a shell. i think i have an idea but i cant find much with googling about what im looking for. most results are for getting me into the admin panel, very limited for what i can do with it after im in. Could someone PM me with a nudge ??

edit…nvmd

the box is easyyy to handel with . but the probleme is the availibiity , it crashes all the time.

Complete noob at this…I’m in a reverse shell as www-***a. I get the sudo -l command output and wish to do so. I can’t because my shell sucks. There is no python instaled. The guides on Upgrading Simple Shells to Fully Interactive TTYs - ropnop blog aren’t working for me without killing my shell…I’m lost for words. Sudo -u root and a little more gives me no tty present and no askpass program specified. I’m right there but my shell is killing me.

A gentle nudge would be very kind. I know there is a lesson in shells here. It really doesn’t have too much to do with the box, but more with shells and maintenance and the reseting of the box every 15-30 minutes. How I’m feeling after a few hours at this box :angry: Ugggggh why can’t I do these things when I am in a terminal…“must be run from a terminal”.

I’ve lost the loving feeling -Tom Cruise

Rooted… relatively simple box but took me forever to get RCE because I was overlooking things. Root was super simple once I got a fully interactive shell.

Hints:
For User: Pretty straight forward, enumerate and exploit. Get creative with code execution.
For Root: back to the basics. Some things aren’t as they appear… versions are important!

please help me with the admin section. I got into the page. Unable to find any workable rce exploit

Type your comment> @xChucKx said:

Complete noob at this…I’m in a reverse shell as www-***a. I get the sudo -l command output and wish to do so. I can’t because my shell sucks. There is no python instaled. The guides on Upgrading Simple Shells to Fully Interactive TTYs - ropnop blog aren’t working for me without killing my shell…I’m lost for words. Sudo -u root and a little more gives me no tty present and no askpass program specified. I’m right there but my shell is killing me.

A gentle nudge would be very kind. I know there is a lesson in shells here. It really doesn’t have too much to do with the box, but more with shells and maintenance and the reseting of the box every 15-30 minutes. How I’m feeling after a few hours at this box :angry: Ugggggh why can’t I do these things when I am in a terminal…“must be run from a terminal”.

I’ve lost the loving feeling -Tom Cruise

Python is installed, just check which one

Rooted! Thanks @ch4p for the great experience!

If anyone need help, feel free to PM :wink:

Very easy box. Nothing learned on this one.

Type your comment> @ecdo said:

Very easy box. Nothing learned on this one.

Great input

The box is very slow for me, it either times out or I’m getting the “Service Temporarily Unavailable” page… :frowning:

This box was going well but I constantly running into the CONNECT ERROR: Unsupported resource type… Anyone else have this issue. Please pm me if you can help

FOR ALL GUYS WHO SEE THIS:

PLEASE STOP MODIFYING THE INDEX.PHP

WE ALL HATE RESETS AND 503 ERROR!

Can someone please PM me where to upload/edit code for my shell in the admin console? Sounds dumb but been stuck on this for a few hours now…