Netmon

If anybody needs help PM me! Root is pretty simple once you know what to look for :slight_smile:

Starting to understand everyone’s complaint about people resetting the box. Makes testing the priv esc a real PIA.

i have found **t and **d file but unable to find password as password in encrypted can anyone help me to tell what type of encryption use i’ve tried b64 but nothing happens.

I got the user. I got Website creds. I read about vulns and I tryed to do some c****** i******** but I can’t get any result :frowning: Any hint for root?

Any help with Login Page :disappointed: PM please.

finding login credential drived me crazy. Can anyone give me a hint on this?

Anyone knows why I’m getting incorrect username/password when trying to run the RCE? I’m using the same credentials which were used for the web UI.

Seriously, Its time to stop.
Stop resting this poor box.
And to the person who set the web app language to Russian, you are not alone in the universe so dont mess things up for the rest of us (good thing I know Russian to set it back to its original state without resetting the box for the X,XXX,XXXth time).
STOP IT.

ok

In the app what am i trying to look a for? for the root?

STOPPPPPP restarting the box…geeeeeeez

Just rooted… can help someone with right path… just PM me :slight_smile:

Guys, you need to stop:

  1. use first google result for “prtg exploit”
  2. break the box using the above
  3. repeat steps 1 to 3

Spoiler Removed

Type your comment> @Monty said:

Guys, you need to stop:

  1. use first google result for “prtg exploit”
  2. break the box using the above
  3. repeat steps 1 to 3

THIS. STOP THIS.

Type your comment> @Falsey said:

Anyone knows why I’m getting incorrect username/password when trying to run the RCE? I’m using the same credentials which were used for the web UI.

I’m also facing the same issue. Please PM me if you find the solution.

@gneelwarna said:
Type your comment> @Falsey said:

Anyone knows why I’m getting incorrect username/password when trying to run the RCE? I’m using the same credentials which were used for the web UI.

I’m also facing the same issue. Please PM me if you find the solution.

Got the root.

Got the root. Special thanks to @4r514n for tips and help.

I seem to be missing something very obvious as I have been unable to find the unencrypted credentials for the web application for days. I’ve got the .**t file but can not find either .**d or .bak. Someone please DM me and get me out of this missery.

Type your comment> @urssunil4u said:

special thanks to @w4l73r for tips and help, i know there is enough hints here, i now have creds, and be able to use them, found a way to run commands in remote system, but based on blog i am unable to spawn reverse shell. can someone help??

Got Root… Learned alot and a really interesting one. i think i still can learn alot on this box. be careful with people removing files and hashes from box. if you cannot find what you are looking for best way is to reset the box. Again special thanks to @w4l73r