Swagshop

I completed this box. If you need a hint, feel free to message me and include where you are, what you’ve tried, and what you’re thinking is up next and I’ll do my best to nudge you.

Rooted, a realistic easy box.
Quality content from @ch4p as always, thanks.

I think the 503’s are coming from people trying to exploit the connections manager and stuffing it up.

Type your comment> @kira0204 said:

Got the user flag but stuck on that and I can’t escalate to root. Lol, this is checking my patience.

Root was easy, back to basics kinda stuff. Don’t overthink

Cant do the reverse shell part, someone could help me? If someone could help me, i can explain what i did in PM. Thank you!

I’ve found root password for mysql db but I’m not sure if I can use it cuz mysql doesn’t listen on 3306 and it seems like phpmyadmin is not installed? Am I on right path or should check something else ? I also found an exploit (py) where installation date needed to be updated (it’s easy to find) but also credentials are needed. Is this correct exploit ?

Type your comment> @dewille said:

I’ve found root password for mysql db but I’m not sure if I can use it cuz mysql doesn’t listen on 3306 and it seems like phpmyadmin is not installed? Am I on right path or should check something else ? I also found an exploit (py) where installation date needed to be updated (it’s easy to find) but also credentials are needed. Is this correct exploit ?

Sounds like you’re on the wrong track there.

Rooted. ■■■■■■■ I feel stupid.

Hello guys, i am new to this but still struggling,
i trying to locate user flag and i feel as i have exhausted my attack strategies lol, i have done a port scan, checked site, attempted reserve shell, enumeration, etc… etc… attempted to gain access via either open ports shown but nuh da, if i could get some guidance much would be appreciated.
Thank yous

Why the heck cant i use the exploit again to get admin account? worked last night now when i try again it works but it says wrong creds when i try log in?

i even tried gaining access to available open ports shown but nuh da

Stuck in 503 many times. ?
Please exploit carefully. ?

Just ROOTED!!! Finally. For a noob it took me a bit… Hit me up if you need help!!
Hints: USER - Enumerate webapp to find a place for the shell
Root - this thread made me think it was super easy… I struggled for awhile. Find out what you can do and how to leverage that to get a shell with root privs

hi can someone pm me on user on this box, ive found some credz and a login pannel. also tried a number of exploits but nothing…

Type your comment> @unashamedgeek said:

I completed this box. If you need a hint, feel free to message me and include where you are, what you’ve tried, and what you’re thinking is up next and I’ll do my best to nudge you.

Needed help stuck at admin page for 2 days

Got user via RCE, but can’t for the life of me get a reverse shell… I think I know what to do for root, but without that shell I can’t execute it.
Anyone around who can give me a hint?

EDIT: Got a reverse shell, now for root
EDIT2: Root done!

EDIT3: Naturally, you can PM me if you need any help!

got root - pm me if you need any help :slight_smile:

Type your comment> @hxmo said:

Why the heck cant i use the exploit again to get admin account? worked last night now when i try again it works but it says wrong creds when i try log in?

I am getting exactly the same thing today. was working fine yesterday even after resets and no luck today!

Type your comment> @Sav said:

Type your comment> @hxmo said:

Why the heck cant i use the exploit again to get admin account? worked last night now when i try again it works but it says wrong creds when i try log in?

I am getting exactly the same thing today. was working fine yesterday even after resets and no luck today!

yeah mate , i switched from VIP to free server and the free server it worked… wow lol

but the free server the website keeps getting 503 error paged ALL the time its so frustrating man

Hit me up for help with root. Also, for anyone who already got root, pm me if you get a chance. I want to see how you did it, have some questions…