Redcross

A discussion thread about Redcross machine

Dam I wanted first.

me too! hehe… still enumerating…

whenever I try to connect to the machine in the browser I get server not found error !

got the same - just a weird redirect

yeap, you have to do some easy trick to make it happens… a “virtual” dns… with no dns at all…

That’s weird
I don’t know how this “virtual” dns works

perfect hint @gudj4qu3r without spoilering!

thanks @nullorzero, that is the idea!

Fuzz the world (?
Nain?

Halp

I got a sub domain
On .redcr**.b

@gudj4qu3r said:
yeap, you have to do some easy trick to make it happens… a “virtual” dns… with no dns at all…

Just think about “what would ippsec do”

@Senpaisol said:

@gudj4qu3r said:
yeap, you have to do some easy trick to make it happens… a “virtual” dns… with no dns at all…

Just think about “what would ippsec do”

lol that’s very true

Logged in to the webpage and might have found a vuln but can’t seem to exploit it…

Still no bloods?

@s1gh did you use a dict, I guess I know a user… any hint that you can share us?

No need to bruteforce.

■■■■!

Found three pages with logins but no credentials.

xsmile same