Swagshop

Hello guys, i am new to this but still struggling,
i trying to locate user flag and i feel as i have exhausted my attack strategies lol, i have done a port scan, checked site, attempted reserve shell, enumeration, etc… etc… attempted to gain access via either open ports shown but nuh da, if i could get some guidance much would be appreciated.
Thank yous

Why the heck cant i use the exploit again to get admin account? worked last night now when i try again it works but it says wrong creds when i try log in?

i even tried gaining access to available open ports shown but nuh da

Stuck in 503 many times. ?
Please exploit carefully. ?

Just ROOTED!!! Finally. For a noob it took me a bit… Hit me up if you need help!!
Hints: USER - Enumerate webapp to find a place for the shell
Root - this thread made me think it was super easy… I struggled for awhile. Find out what you can do and how to leverage that to get a shell with root privs

hi can someone pm me on user on this box, ive found some credz and a login pannel. also tried a number of exploits but nothing…

Type your comment> @unashamedgeek said:

I completed this box. If you need a hint, feel free to message me and include where you are, what you’ve tried, and what you’re thinking is up next and I’ll do my best to nudge you.

Needed help stuck at admin page for 2 days

Got user via RCE, but can’t for the life of me get a reverse shell… I think I know what to do for root, but without that shell I can’t execute it.
Anyone around who can give me a hint?

EDIT: Got a reverse shell, now for root
EDIT2: Root done!

EDIT3: Naturally, you can PM me if you need any help!

got root - pm me if you need any help :slight_smile:

Type your comment> @hxmo said:

Why the heck cant i use the exploit again to get admin account? worked last night now when i try again it works but it says wrong creds when i try log in?

I am getting exactly the same thing today. was working fine yesterday even after resets and no luck today!

Type your comment> @Sav said:

Type your comment> @hxmo said:

Why the heck cant i use the exploit again to get admin account? worked last night now when i try again it works but it says wrong creds when i try log in?

I am getting exactly the same thing today. was working fine yesterday even after resets and no luck today!

yeah mate , i switched from VIP to free server and the free server it worked… wow lol

but the free server the website keeps getting 503 error paged ALL the time its so frustrating man

Hit me up for help with root. Also, for anyone who already got root, pm me if you get a chance. I want to see how you did it, have some questions…

Ok, I’ve encountered alot of error 503s while I’ve been attempting this box. As I’m a noob could someone explain to me what might cause that error so that I can make sure that I am not part of that problem?

i literally can not do a single thing on this box because everytime i find something or get close it gives me a 503 and then i have to wait a couple min before i can even do anything this is so annoying

Just ridiculous at this point tbh… Its more of a race and who can execute the reverse shell first rather than hack the stupid box man im actually raging, been at this for HOURS man and all i see is 503 loool only had the reverse shell once cos every time after it gets ■■■■■■ bricked the website… VIP server doesnt even work on this box ■■■■

Same, same-same.
I’m going to retry under cover of darkness. This very EVENING.
#Naps

Pretty fantastic box. Not overly hard but fairly realistic and gave me several “I’m Stupid” moments.

@hxmo US VIP was very stable. I had shell for the last hour or so with several stupid CTRL+C moments requiring me to re-exploit.

Got my 20 points for this lovely and frustrating box. Thanks @ch4p for the work <3
PM me if you need help.

Got root! Great Box.
Returning the favor, if anyone needs a tip, feel free to pm.

@AndreiPintea @NPCMaster Thanks!