ForwardSlash

no nudge yet? :smiley: seems to need to LFI/RFI but cannot find the script to do it :frowning:

what kind of hash this?

where is the hash:( cannot find any hash :frowning:

Type your comment> @Linoge said:

where is the hash:( cannot find any hash :frowning:

read the defaced page again :smile:

Woo!

i’m confused ,can’t find anything for the moment. anybody willing to give a hint where to look for?
nevermind got something new :slight_smile:

I just got the XML file I don’t have an idea about decrypting it’s new for me

So is fuzzing not going to find me that magical xml file? I may have gone down a rabbithole of following the hacker gang’s name and finding a related exploit.

found lfi :slight_smile:
now on to the reverse shell

any hits ??

Type your comment> @anuragd said:

So is fuzzing not going to find me that magical xml file? I may have gone down a rabbithole of following the hacker gang’s name and finding a related exploit.

try to fuzz something like a text, it will help you for next steps

Type your comment> @foxlox said:

try to fuzz something like a text, it will help you for next steps

been fuzzing file types for a couple hours now :frowning:
What I thought could be helpful from the site was less than successful ?

Spoiler Removed

Spoiler Removed

Rooted at last. This machine was quite cool. A very nice mix of techniques. Congrats to the creators for it!

In case you need a nudge:

  1. Once you get into the correct place, be a hero and point all the guns at yourself. If you’re lucky enough you’ll catch the bullet mid-air.
  2. Pretty standard technique to go from user A to user B. Enumerate!
  3. For root, sometimes you don’t need a key to open a broken door. Just focus on the cracks.

@munra said:

  • Once you get into the correct place, be a hero and point all the guns at yourself. If you’re lucky enough you’ll catch the bullet mid-air.

What kind of hint is this ?

I rooted, but I don’t quite understand why what I did works. If someone can explain the c****o part to me, that wouuld be much appreciated.

Type your comment> @clubby789 said:

I rooted, but I don’t quite understand why what I did works. If someone can explain the c****o part to me, that wouuld be much appreciated.

Any hits ?

My enum game is weak on this one, only found the text and can’t bust anymore from the ‘clue’ :frowning:

Edit:
nvm being lazy

Type your comment> @fmwd said:

Type your comment> @clubby789 said:

I rooted, but I don’t quite understand why what I did works. If someone can explain the c****o part to me, that wouuld be much appreciated.

Any hits ?

Consider doing one of the easier boxes first. The box has only been up for 12 hours…