Teacher

@Laegir said:
Hint for Root: https://youtu.be/egMWlD3fLJ8

I just rooted this box and i don’t get this hint at all…

I have been enumerating since yesterday. There’s a ton of files which I looked at. Still can’t find any credentials. Can anyone give a hint?

@shortdevil101 said:
I have been enumerating since yesterday. There’s a ton of files which I looked at. Still can’t find any credentials. Can anyone give a hint?

In the same boat, any hints?

@Phrenesis2k said:

@Laegir said:
Hint for Root: https://youtu.be/egMWlD3fLJ8

I just rooted this box and i don’t get this hint at all…

Well, it depends. If you just want to read the flag then you don’t need to use the hint, so I think this is meant for those who are going for the root shell, which took me a while to figure the right steps.

@shortdevil101 It’s hidden in the masses. The filename does not stand out. The post by @SW4gb3JkZXIgdG already contains what you need.

[…] hint look at every file on every site

Taking a look what’s happening on the client side might help, too.

@fjv said:

@Phrenesis2k said:

@Laegir said:
Hint for Root: https://youtu.be/egMWlD3fLJ8

I just rooted this box and i don’t get this hint at all…

Well, it depends. If you just want to read the flag then you don’t need to use the hint, so I think this is meant for those who are going for the root shell, which took me a while to figure the right steps.

I rooted it with shell… i’ll pm you, i’m getting curious now… :wink:

@prokaryont said:
@shortdevil101 It’s hidden in the masses. The filename does not stand out. The post by @SW4gb3JkZXIgdG already contains what you need.

[…] hint look at every file on every site

Taking a look what’s happening on the client side might help, too.

It DOES stand out if you look at the right place.

■■■■! error database connection failed

I’m still not having any luck with getting logged in… I’ve tried the name at the bottom of the message where the password is but that didn’t work even when I tried bruteforcing it by adding a character to the end of the password but unless its using a character not available on keyboards normally then I don’t know…

@Richie said:
I’m still not having any luck with getting logged in… I’ve tried the name at the bottom of the message where the password is but that didn’t work even when I tried bruteforcing it by adding a character to the end of the password but unless its using a character not available on keyboards normally then I don’t know…

check your http response codes, you might need to think about how this works :wink:

So I found the hidden credentials but not finding where to apply them, is the login hidden? Do I need to do some more enumeration?

@ikuamike said:
So I found the hidden credentials but not finding where to apply them, is the login hidden? Do I need to do some more enumeration?

yes

@Phrenesis2k said:

@ikuamike said:
So I found the hidden credentials but not finding where to apply them, is the login hidden? Do I need to do some more enumeration?

yes

Alright, some more work to do. Thanks for confirming

is Teacher really unstable on free server for anyone else?

@quas said:
is Teacher really unstable on free server for anyone else?

yes. The creator did not exactly think how the machine will behave under load. Everything slows down, the web does not load, the shell is slow

So how does one make a Quiz in Spoiler Removed - egre55

Nvm found it

do i have to bruteforce the M*e passwd rt to**n ? :S

can you please stop resetting the box like crazy ???

Any tips you can give on the RCE part? Seen the video, tried the different inputs. No cigar, any help appreciated.

@Nirkeh said:
Any tips you can give on the RCE part? Seen the video, tried the different inputs. No cigar, any help appreciated.

Reboot the box if you can. It’s very unstable when other people are poking at it, it seems. I had this same issue and had to reboot and basically wait to be the only person on that step it seemed like.