Swagshop

Hi guy
this is my first box and i got user shell
for root shell i did some enum and found a way. But i am not really sure how to use it. can someone who has rooted the box ping me.
And if someone needs help with user shell you can pm me
For people who struggling with user shell

  1. You have to use an exploit to access admin panel
  2. then use another to gain a shell

Okay rooted! Yaaaay. PM if you need help

I figured it out!!! Holy Brain Washed Batman!!! This is NOT an easy box… but guess that’s what I get for being a noob. LOL

Hi All,
Newbie here trying to hack my first box!
I’ve for to the admin portal, but am stuck trying to get a user shell.

Can anyone PM me with a pointer in the right direction?
Thanks!

PM me

is there anyway to get an interactive shell after rooting?.

Yay, got user and root! Thanks to joenibe for the pointers!

empty…

empty

Got to the admin panel, and got stuck. Have no idea to upload shell payload since the CM is disabled. Can someone PM hints ?

Im so confused right now. Can someone give proper tip on how to get user shell? This forum is full of “its that other exploit thats not using downloader and is also not froghopper”.

@Hexploit said:

Im so confused right now. Can someone give proper tip on how to get user shell? This forum is full of “its that other exploit thats not using downloader and is also not froghopper”.

Not sure why people are saying that, Frog is the way to go

Type your comment> @Ir0nGe3ks said:

Type your comment> @bestion2 said:

 any other way @lr0nGe3ks

Including the myriads of other post you made… they’re all going in the wrong direction, trust me, I’ve done all that…

What is right direction ??

Type your comment> @bestion2 said:

Type your comment> @Ir0nGe3ks said:

Type your comment> @bestion2 said:

 any other way @lr0nGe3ks

Including the myriads of other post you made… they’re all going in the wrong direction, trust me, I’ve done all that…

What is right direction ??

if your looking for user shell, search for froghopper vuln and read the first article carefully.

I think something has been deleted.

This was a great box!

The hardest part at times was to outlive the resets / slow backend… Just figured out you can cancel them via the shoutbox on the website which gave me a few minutes to get the user and root keys.

I’m stuck with the froghopper exploit. Where do I upload it? I know I’m supposed to see it in /m****/c******/cy, but I don’t, it find it in /m/c****/product/etc… Am I just uploading it in the wrong place?

Type your comment> @HackermanJosh said:

I’m stuck with the froghopper exploit. Where do I upload it? I know I’m supposed to see it in /m****/c******/cy, but I don’t, it find it in /m/c****/product/etc… Am I just uploading it in the wrong place?

nvm, I was uploading it in the wrong place. Still don’t have a shell yet…time to experiment with payloads, I guess.

Did somebody break the box?

It ain’t broken! - @garffff Look for a different route if some backend parts aint working… (It might be disabled, read the forum for more info :wink: )
Also for the people resetting the box - No need, it IS working.

Type your comment> @rawzone said:

It ain’t broken! - @garffff Look for a different route if some backend parts aint working… (It might be disabled, read the forum for more info :wink: )
Also for the people resetting the box - No need, it IS working.

Pings to the box keep on dying. Right in the middle of something then it goes down again, comes back up for a little then back down