Haystack

Type your comment> @qmi said:

@andresitompul said:

How did you figure out the username if you don’t know the password? B/c it’s in the same data dump but a little above. Did you get a spoiler?

i did a python script to check each default username.
and one of may tested username its valid… thats it.
I see.

i dont know how to dump the database.

any clue ?
You may need to use an extension to ELK which enables you to view data using SQL queries. You will see tables, columns and finally data dump by the help of the good old cURL.

does the ssh port forwarding also work on this machine without password ?
No. You will need to have SSH user/password.

i already have the sec login ssh and got user.txt
but no idea for getting the root.

how ?