Mango

191012141523

Comments

  • Type your comment> @frostydog said:
    > Would somebody be willing to look over my python script and point out any obvious issues? I'm generating password combinations but when I try to enter my final pwd it's not working the way that is expected.

    You may add some additional special characters to your “set”.

    bumika

  • Cannot find the credentials, but found the login page, the search page and a******s.p**.

    Any hint on how to find the creds to login?

  • Anyway I got root anyone need help, you can send pm!

    noi

  • Type your comment> @bumika said:

    Type your comment> @frostydog said:

    Would somebody be willing to look over my python script and point out any obvious issues? I'm generating password combinations but when I try to enter my final pwd it's not working the way that is expected.

    You may add some additional special characters to your “set”.

    I'm also struggling with my script. Would anyone PM me some help?

  • Type your comment> @bumika said:

    Type your comment> @frostydog said:

    Would somebody be willing to look over my python script and point out any obvious issues? I'm generating password combinations but when I try to enter my final pwd it's not working the way that is expected.

    You may add some additional special characters to your “set”.

    I have the same problem, password with $ to infinity.

  • Type your comment> @virtualShoot said:

    Type your comment> @bumika said:

    Type your comment> @frostydog said:

    Would somebody be willing to look over my python script and point out any obvious issues? I'm generating password combinations but when I try to enter my final pwd it's not working the way that is expected.

    You may add some additional special characters to your “set”.

    I have the same problem, password with $ to infinity.

    remove the $ from your char list then

  • Thanks for the great box

    tobor
    Gods make rules. They don't follow them

  • Anybody kind enough to help me out with how to find the login page? Happy to give reps. :) Thanks
  • Type your comment> @3l0nMu5k said:

    Rooted!
    Was Fun, thanks @MrR3boot for the tasty fruits, really enjoyed them.
    Thanks to @donkeysnore for the help with building of the script.

    Feel free to PM me for some help.
    PS: Sorry, discounts codes for the CyberTruck are exhausted.

    i am still in login page what can i do to get uername and password.. help me please

  • edited December 2019

    I found the Login Page, I am not sure what to do from here... Despite being told that brute forcing doesn't work, I tried it anyways just to get some practice and of course, it did not.... can someone PM and guide me through this next part. I think I have an idea, but just need a nudge. THANK YOU

    Edit 1: Nvm got it and User... Up next Root!

    Edit 2: Got root, if anyone needs some help, feel free to message me!

    H4ck3d5p4c3

  • plz stop smashin the box, hackers plz check the forums b4 forcing..its not needed and its disruptive.. thanks..carry on :)

  • Type your comment> @blay said:

    Nice box. learnt a lot. anyone who needs help can Dm me

    i am stuck in login page bro... cna you help me please

  • Type your comment> @c00de said:

    Type your comment> @c00de said:

    got user thanks to @SolidTuba
    now i'm stuck on the root part
    could anyone help me with this ? i've found a file '**s' in which i think i've got to use G***BINS but i'm stuck here

    Rooted, didn't except the root to be way easier than the user
    if anyone needs help can contact me

    i have gound under construction page now what shoul i do bro..

  • Type your comment> @H4ck3d5p4c3 said:

    I found the Login Page, I am not sure what to do from here... Despite being told that brute forcing doesn't work, I tried it anyways just to get some practice and of course, it did not.... can someone PM and guide me through this next part. I think I have an idea, but just need a nudge. THANK YOU

    Edit 1: Nvm got it and User... Up next Root!

    Edit 2: Got root, if anyone needs some help, feel free to message me!

    i ahve got user.txt now for root what should i do bro...

  • fun box :D
    coudn't write a script for user, for whatever reason it just woudn't work, but it takes about a minute or two with burp :P
    root was a little too easy and fast tbh and files in the users home directory might spoil even that

    0x41

  • Guys, can anyone help me out with the python script? It seems to be working for a single user, but not for another. From reading these posts, I think the problem may be related to special characters, but I'm at a brick wall. Help appreciated.

  • edited December 2019

    rooted this box last saturday night :)

    User is very tricky :) PayLoadAllTheThings can help you to dump users.

    Root is very straight forward :) #GTFObins

    Learn a lot on this box ! Thanks @MrR3boot

  • edited December 2019

    Need a bit of a nudge to esc to root...
    Found the **s from gtfo to use but am quite stuck as to how I am supposed to use that to my advantage...
    Hit me up if you can help pls..

    EDIT:okay I am very very dumb!!
    Just rooted,feel free to pm for nudge!

  • Is anyone available to point out where I'm going wrong with my python script? I am about to introduce my computer to the window! Any help appreciated.

  • edited December 2019

    i ahve got user.txt now for root what should i do bro...

    go get a good drink... relax... enjoy live.... do something good for mankind... and think about the meaning of life / the universe / and everything...
    but: just dont ask... (bro)

  • edited December 2019

    Ok, I've got right up to the end with user 2 and trying to run something through j*, but everything I try relating to privesc from g*b*s results in an unresponsive terminal with what looks like a shell hash at the beginning. Anyone have any pointers that will get me out of this rut? Been working on it on and off for a couple of days and getting nowhere.

  • Hey guys! Is there anyone that could help give me a nudge for my python script? Been stuck for a while now :(

  • Type your comment> @n00bsys0p said:

    Ok, I've got right up to the end with user 2 and trying to run something through j*, but everything I try relating to privesc from g*b*s results in an unresponsive terminal with what looks like a shell hash at the beginning. Anyone have any pointers that will get me out of this rut? Been working on it on and off for a couple of days and getting nowhere.

    don't expect too much... no shell needed for ctf.... somtimes reading is enough...

  • Finally got root! That juice extraction gave me a headache. Learned some new stuff.

    User: If you don't get all of the juice, just think about if you are looking at the right positions for new juice.

    Root: Basic enumeration should to it!

  • Can anyone give me a little PM nudge as to how to enumerate the box to find the login page ?

  • edited December 2019

    A shout out to @3l0nMu5k for helping me get user. Learnt something new, as usual.

    As for ROOT. WTF.. lol It was so stupid and simple to get the flag. It was so silly that I still feel incomplete in my soul. lol I did not use GO*b . Just something super simple. :)

    Happy to help with nudges. :)

  • edited December 2019

    I have some trouble in mango machines . now , i have a....n and t....2 ,m... and h.....U. they are true? but i can't connect 10.10.10.162:22 ’s SSH ,so what should i do . thx!!!

    now i got root , thx for @cloudkh

  • The initial part was very interesting, I had never used this technique.

    User: has already everything
    Root: if you can't do it from the inside, try it from the outside or change your point of view

    Tnx @MrR3boot for machine

  • Interesting box so far...
    Detected login page, can authenticate, no clue what to check next! Any hints?

  • Done! After some struggles and head banging. Thanks @Anonimbus for the push!

    Initial Access: The name of the machine + Payloads All The Things
    User: Almost same as the beginning
    Root: GTFO is the place to be.

    PM for push

Sign In to comment.