Magic

Less than 2 hours to go so starting the thread

Ah, got www-data. Enum enum enum …

Let’s do this, 10 seconds!

Found a login portal. Got only 1 hit when checking passwords. Is it sl****?
First time posting, so don’t know if it’s a spoiler or not.

Bypassed authentication, got the portal admin password, no idea what to do next

Type your comment> @myrtle said:

Ah, got www-data. Enum enum enum …

lol thanks

Got user…
Pretty easy so far.

03 hours, 18 mins, 31 seconds. 1st blood… box ain’t even live that long ??

Type your comment> @Wolfman000 said:

03 hours, 18 mins, 31 seconds. 1st blood… box ain’t even live that long ??

This feature is little buggy :d shows first blood + 3 hours

bruh it’s so laggy

Is the password found by bruteforcing is the way to go? doesn’t seem to work :frowning:

slow slow slow i think everyone is trying to brute force it

Type your comment> @dc9th said:

bruh it’s so laggy

Yeah that’s why i will try to root it when everyone calms down and leave this box alone :slight_smile:

I am able to upload, but I can’t figure out the name of what I uploaded after it gets uploaded

Type your comment> @sakas4 said:

Type your comment> @dc9th said:

bruh it’s so laggy

Yeah that’s why i will try to root it when everyone calms down and leave this box alone :slight_smile:

Type your comment> @init5 said:

I am able to upload, but I can’t figure out the name of what I uploaded after it gets uploaded

Same here! Can’t open/find the original filename after upload…

just got www-data, can’t find a way to privesc

Meh, everything I try just results in a “What are you trying to do there?”. Wondering, if I’m on the right track, or if I should look elsewhere :smiley:

im www-data, found t****** password but aint working…rabbit hole?

Edit: yep, you need to find the real pass
now for root
Edit 2 : got root! cool box

@Try said:
Is the password found by bruteforcing is the way to go? doesn’t seem to work :frowning:

I thought that machines on HTB don’t require brute forcing for website login creds?