OpenAdmin

Would anyone be able to help me with user?

Get j**** shell

I’m still fuzzing dirs, they’re a tad slow.

Rooted, fun box with a pretty standard path, but mad respect for @Kucharskov for doing it in 11 mins! wondering if there is an unintended way…

Initial foothold: enumerate, pretty much any wordlist will give you the one you need. Exploit for the service is also one Google search away.

User: that was the fun part. Once you get the initial access, enumerate the system, Google this service and understand what’s its file structure and where you can potentially find something useful. Think like someone who has access to the box, what else can you see which you shouldn’t be able to see externally…

Root: it’s right in front of you , standard CTF-like scenario used on a lot of machines.

Rooted.

Very easy box for begginer.

I’ll highly suggest it for pentest newbies :slight_smile:

Rooted. Easy box, all you need to do is to enumerate and google. If you get stuck, you can DM me.

Stop reseeeeeeeeeeeeeeeet

is the box down on free server ? i can see port 80 on nmap but when i open it in browser it’s always connection time out

More root than users xD

Type your comment> @CGonzalo said:

More root than users xD

yeah thats right, i was managed to get the root key while I havent been root yet :expressionless:

…and finished. kinda sure I didnt do it the intended way. (root and user)

Im pretty confused, because i got root before user, and I’m not even actually root user… Is root flag intended to just be laying around like that?

Type your comment> @Kwicster said:

Im pretty confused, because i got root before user, and I’m not even actually root user… Is root flag intended to just be laying around like that?

I am having the same issue :slight_smile:

Hi. I followed some of the tips here and I think I found the right thing but kind of stuck. Can someone give me a hand?

Msf doesn’t work? any leads?

rooted on normal way

Impressed how you guys get root/user so quick. I still only have www shell and cant find anything that helps me here.

Rooted the intended way.

Mp if needed with what you’ve done and where you’re at

Got www-shell too but cannot find anything to get user

Type your comment> @roelvb said:

Got www-shell too but cannot find anything to get user

Im at the same stage, still searching