at least I’m learning to try and push the limits of L** …
/pr** and /ec have interesting files that can be read, but none helpful so far
need a better tool than B** that can sort responses by length, not by status code
at least I’m learning to try and push the limits of L** …
/pr** and /ec have interesting files that can be read, but none helpful so far
need a better tool than B** that can sort responses by length, not by status code
People asking for nudges / hints - the box has been up for under two hours with about <5 people getting root. Calm down a little, practice some patience and enumerate more.
You can’t tell us what to do and what not to do in this forum, its a completly open forum and everybody can write whatever they want in here. Its the people’s choice to answer the questions or to ask them.
What is with this aggressive response? Taz made a sensible post regarding early box nudges. Calm down buddy!
any hints after L** Tried every approach log ones and procs one also but got nothing tried to get ssh keys and tomcat files but nothing
Put yourself in the shoes of the person who installed tomcat.
Edit: Just rooted this box no more than 5 minutes ago. Fun box, learned a few things. Often found myself going around in circles when the way out was under my ■■■■ nose. Foothold is the most challenging part. After that it’s a breeze.
The foothold is completely clueless. I know there is “some sense” behind it … but this is another one of those CTF-style steps. I don’t mean that this is all bad, it all depends on what you are looking for when solving a box. For me … this was not “real life” at all.
For those who are stuck on foothold … well, pay attention in a particular page information. That’s all I could say without spoilers.
User: I know you are seeing that file… Yes… go ahead, it is there.
Root: Basic enum. You will notice something unusual.