Admirer

Finally Rooted.

User was the hardest part; as everyone says enumeration is key, and when you get to the point where all the things you have aren’t working, google about the thing you’re trying to use (and the version) and you’ll find the answers.

Root was much much simpler and is difficult to hint at without giving too much away. Should be on the right track after basic enumeration.

This should of been considered a medium or hard box…medium at least. no way in all the boxes I’ve owned would this be considered an ‘easy’ box.

Found the page, set the b***-ad***** now getting “M*S** server has gone away”

Confirmed running on machine. What am I missing?

Trying the exploit for the login on the a*******.p** page but keep on getting ’ M***L server has gone away’ errors,. Has anyone experienced this or knows how to solve this problem? Thanks

@gahanar said:
Found the page, set the b***-ad***** now getting “M*S** server has gone away”

Confirmed running on machine. What am I missing?

SAME problem

@gahanar said:
Found the page, set the b***-ad***** now getting “M*S** server has gone away”

Confirmed running on machine. What am I missing?

Have a look at the network traffic, this error indicates that your set up is slightly wrong.

Type your comment> @markdc said:

@gahanar said:
Found the page, set the b***-ad***** now getting “M*S** server has gone away”

Confirmed running on machine. What am I missing?

SAME problem

make sure u configured M**q* correctly.
Message for any help.

I need some help. I’ve been fuzzing at / and /a****-**r but nothing using a lot of different wordlist and file extensions. Can someone give me a nudge with this?

Just rooted the box. Thanks to @coffeeBLK for helping me make it less complicated than I was wanting to do.
Worth talking to if you’re stuck.

Few rabbit holes, but nothing to get in a fuss over. The initial foothold is easier than it appears at a glance. Root is cake. Everything needed has already been mentioned. Thanks @polarbearer and @GibParadox

Hi Guys

Am i configure it right => connect to axxxxxr from remote MySQL server ?

Rooted. But twice I found that FUZZ could not find a particular file. Someone thought it was fun to delete cxxxxxxxxx.txx

Arrggg, feels like I’m going in circles…I’ve found that what can’t be see…
Having a 'mare fuzzing, trying mixed wordlists and extensions.
Any hints PM me…
Just need a prod in the right place as I feel like I’m missing something obvious.

Rooted :slight_smile:

Can any one help
open_basedir restriction in effect. Unable to open file ??
EDIT: Got it.

Howdy All,
i could use a nudge please, I’ve enumerated for a crazy amount of time. I found the a****_d** and the r*****.txt, but i cant find anything else.
Thank you!

Type your comment> @LazerH0rnet said:

Howdy All,
i could use a nudge please, I’ve enumerated for a crazy amount of time. I found the a****_d** and the r*****.txt, but i cant find anything else.
Thank you!

Fuzz the a****_d** you have seen in r*****.t** file.

Type your comment> @markdc said:

Trying the exploit for the login on the a*******.p** page but keep on getting ’ M***L server has gone away’ errors,. Has anyone experienced this or knows how to solve this problem? Thanks

Check the user you’re trying to log in to.

rooted
box is easy, but with a lot of nuances.
If u making it for points in the night and hope to make it quick, just like me - forget about this, u will be delve into all rabbit holes, checking everything before realize that u need persistence for this one.
Main vuln is very cool, root looks unrealistic scenario for me, but I’m not very familiar with it.
Thanks for the box @polarbearer and @GibParadox, I don’t get why rating so low…

Interstellar OST… seriously though? lol