OpenAdmin

Rooted the intended way.

Mp if needed with what you’ve done and where you’re at

Got www-shell too but cannot find anything to get user

Type your comment> @roelvb said:

Got www-shell too but cannot find anything to get user

Im at the same stage, still searching

Spoiler Removed

How to upgrade initial www-data foothold into a nice shell please?

After weeks of fighting with the hard machines its so relieving to have an easy box pwned within two hours (even though first blood was within 11 minutes)…

so incredibly slow.
I think this time they’re going to push the new machine even harder.
everyone is blood hungry after such along time without a new box! :smiley:

Can someone give me a nudge? found a possible R** for ON***N. just want to check i’m not off down a rabbit hole.

Type your comment> @GreyHat86 said:

Can someone give me a nudge? found a possible R** for ON***N. just want to check i’m not off down a rabbit hole.

Should give you a shell so no rabbit hole.

Low level shell acquired. Working on user now, any hints appreciated!

Need a nudge? Just let me know and send me a DM

Almost everyone is having issues getting the user shell.

Can anyone dm me what to do with www-data shell?

Type your comment> @Warlord711 said:

Type your comment> @GreyHat86 said:

Can someone give me a nudge? found a possible R** for ON***N. just want to check i’m not off down a rabbit hole.

Should give you a shell so no rabbit hole.

Nada… l’ll check my syntax over, i’ve tried the payload after plodding through pages in burp, a script and a curl command.

couldn’t get an interactive shell after sending an net*** command via b***. any nudge? got a low level shell but nothing works inside.

Spoiler Removed

Fun box. Root was maybe way too simple?
Small hint for the initial shell, since it’s a new box - just do it manually.
DM if you’re stuck and need a little nudge

seems like someone left end part open - there for www-data :stuck_out_tongue:

User and root owned

I’ve seemed to have found the vulnerable service and found the exploit. Could anyone DM me a hint for the initial foothold please? I’m not sure I’m understanding the exploit.