Mango

PM for Nuggers

Hack The Box

Spoiler Removed

Rooted, nice box. PM if you need pointing in the right direction

Nice box! User wasn’t as straightforward as I was expecting, if you write your own script don’t forget to escape special characters because I lost a few hours of my life to this.

Best box for ages. Thanks @MrR3boot

@BinaryStrike said:
really a jjjjuicy machine !!! Thanks for the machine @MrR3boot !!!

@izzie said:
Best box for ages. Thanks @MrR3boot

@halisha said:
r00ted, enjoyed the machine.

Glad you had fun with Mango :slight_smile:

Rooted this morning, really amazing box and big thanks @MrR3boot ,the the scripting part was quite bit frustrating :), learn something Important for any successful Penetration tester don’t bypass anything without check further.

Type your comment> @Impulse said:

For people who have no idea where to begin once u get the login page

The box is named for a reason … Once u get that hint
there is a good blogpost literally explaining the entire user process :slight_smile:

I found this blog post, but only by accident, otherwise I never would have had the remotest chance of getting father (I’m a big noob). Curious to know the thought process of people who figured this out on their own. Is this a known thing that if you got the hint the name of the box alone would make you realize to try, or are there things you are doing in enumeration that would tell you that this exploit would work?

@Icyb3r said:
Rooted this morning, really amazing box and big thanks @MrR3boot ,the the scripting part was quite bit frustrating :), learn something Important for any successful Penetration tester don’t bypass anything without check further.

Welcome :slight_smile:

Rooted.

I agree to understand how to play this machine.
Brainfuck for me to get,

“rhyme mango” , “hint mango”

I think soooooo far.

I learned a lot on this machine.

Thank you

User : no comment
Root : gtfobins is best friend.

Finally rooted and got shell.
Personally I don’t like “guessing” but when I got it it was SOOOOO funny to get the credentials.
And I also learned something really new.
Moreover, I love when getting the shell involves your fantasy.
Thanks @MrR3boot !

Nice box

Juice Extraction part was interesting I totally loved it.
User: no comments
Root: Pretty straightforward basic enumeration is the key.
Thanks to box maker @MrR3boot

guys i need help in user enum, i got logged in but the gears keep rolling without any changes, so i’m in /ho**.p*p what to do?
I’M REALLY STUCK AT THIS STEP

delete

Thanks for a fun box @MrR3boot! I learned quite a bit, and really enjoyed it!

@blink3r said:
Finally rooted and got shell.
Personally I don’t like “guessing” but when I got it it was SOOOOO funny to get the credentials.
And I also learned something really new.
Moreover, I love when getting the shell involves your fantasy.
Thanks @MrR3boot !

@breaker said:
Juice Extraction part was interesting I totally loved it.
User: no comments
Root: Pretty straightforward basic enumeration is the key.
Thanks to box maker @MrR3boot

@thr33per said:
Thanks for a fun box @MrR3boot! I learned quite a bit, and really enjoyed it!

That’s a joyful feedback. That makes me to do more in future :slight_smile:

hi guys should I enumerate password for login page?

I’m stuck on the login page. I think I understand what the “mango” hint is but I have no clue about how to extract to get to the next part. Any nudges are appreciated.

I got this Error
Current key is only applicable for *.codepen.io.
Read more info about this error
You are trying to use the following key: Z7U7-XHIF9V-4A5Q3S-343X5O-0P5G1R-5G2G25-6S5F2Q-0Q0F5Z-37