Hint for TartarSauce!

Deep fried cod goes well with TartarSauce.

i can not upload anything, and also can not find were page error404 stored

1 Like

@dshulman said:
i can not upload anything, and also can not find were page error404 stored

Enumerate more

I think I found the right place to upload my file but every time I upload the file it says “system error”. Can anyone help?

what if I am still stuck on the login page? i guess this is not a bruteforce thingy

@w31rd0 said:
what if I am still stuck on the login page? i guess this is not a bruteforce thingy

On almost any machine or web application (this one, others on HTB, and real-world scenarios), it is often more helpful to think like a lazy sysadmin or sloppy user than it is to bruteforce or try to get fancy.

@valentinelocke said:

@w31rd0 said:
what if I am still stuck on the login page? i guess this is not a bruteforce thingy

On almost any machine or web application (this one, others on HTB, and real-world scenarios), it is often more helpful to think like a lazy sysadmin or sloppy user than it is to bruteforce or try to get fancy.

that is true, but usually some hints are given to make your guess, or get an idea of how to approach. i feel here i am missing something.

hint for upload php file?

Onuma

@IrfanRizvi said:
Onuma

yes <— THIS
lol

Tartar_Sauce

@3mrgnc3 said:
Tartar_Sauce

Does your name related to escalate from Onuma in that strange file name :smiley: :smiley: ??

idk what you could possibly mean…

One of the submission rules for challenges on HTB is that the name should be a clue to solve the box

@3mrgnc3 said:
One of the submission rules for challenges on HTB is that the name should be a clue to solve the box

I meant ȜӎŗgͷͼȜ , never mind anyway :lol:

For anyone that has an idea on privesc, a pm would be helpful.

Do I have to look into the code? Because I don’t want to waste my time for something not needed…

I tried known vulnerabilities and common ways to get Shell but they wouldn’t work…

How can I upload PHP file … It cannot upload anything even a picture :frowning:

is the machine broken ? it even can’t upload allowed files.

Im thinking that this is one of those “immersion breaking” machines. The upload is a deadend. I tried creating a new snippet since I noticed they use php. The only hint Ive seen in this box that its related to Falafel somehow but I never completed that so thats dead too or just a rabbit hole. If anyone has a clue how to work up from here can you give me a PM?