Thanks Frey, done that. Would doing so allow me to read a file that provides access to another service (lower port) on the box? Or am trying to achieve RCE?
You da man. Interesting article floating out there called "When All You Can Do Is Read" that really nailed this down for me. If this is considered a spoiler, please remove.
Enumerate, it is fairly obvious if you look around enough. (Sorry I know everyone hates that answer but especially in this case it should be pretty obvious if you look in the right area)
Feel free to follow me on Twitter @BenGrewell for tutorials, videos and other infosec related posts.
This is not strictly a hint, but the machine was designed to not require arbitrary guessing or finding the right wordlists because I don't really like that kind of hacking So the hints are not hidden, they are there. I hope you like it.
am i missing something? not finding anything in the available web pages. Dirbuster giving me errors.Also, tried using an exploit against the P***** Server but no output. am i on the right track or what? and if someone would PM me it would be great
@xtech said:
am i missing something? not finding anything in the available web pages. Dirbuster giving me errors.Also, tried using an exploit against the P***** Server but no output. am i on the right track or what? and if someone would PM me it would be great
nevermind found the page. better not ban dir scanners next time :P
@xtech said:
am i missing something? not finding anything in the available web pages. Dirbuster giving me errors.Also, tried using an exploit against the P***** Server but no output. am i on the right track or what? and if someone would PM me it would be great
Hey @cichy. Thanks I figured out how to read files and gotten some useful info like usernames but not sure where to go from here. Is bruteforcing required after that?
Comments
Spoiler Removed - Arrexel
Spoiler Removed - Arrexel
Spoiler Removed - Arrexel
Spoiler Removed - Arrexel
Thanks Frey, done that. Would doing so allow me to read a file that provides access to another service (lower port) on the box? Or am trying to achieve RCE?
you can get something, that will allow you to get a connection through that port
You da man. Interesting article floating out there called "When All You Can Do Is Read" that really nailed this down for me. If this is considered a spoiler, please remove.
Spoiler Removed - Arrexel
How did you overcome internal server error? I tried all techniques to read the files I found and none of them is working for me so far.
Spoiler Removed - Arrexel
Spoiler Removed - Arrexel
OSCE | OSCP | OSWP | CAST |CSTA | Sec +
Visit: https://3mrgnc3.ninja
I agree ... Too many spoilers in here!
Please watch the spoilers, there was one in almost every post so far.
Way to go, sorry for spoiling that much well for everyone that got the hints before Arrexel deleted them have fun.
Enumerate, it is fairly obvious if you look around enough. (Sorry I know everyone hates that answer but especially in this case it should be pretty obvious if you look in the right area)
Feel free to follow me on Twitter @BenGrewell for tutorials, videos and other infosec related posts.
i wont say anything anymore in the forum. (it's not a hint nor a spoil). feel free to report this comment as spoil.
stuck at Internal Server Error. Pm hint pls
hint is there infront of you
The best hint I would give is to read what you have found is actually telling you, and then check out the OWASP TOP 10 for 2017.
~|OSCP|OSCE|~
This is not strictly a hint, but the machine was designed to not require arbitrary guessing or finding the right wordlists because I don't really like that kind of hacking
So the hints are not hidden, they are there. I hope you like it.
am i missing something? not finding anything in the available web pages. Dirbuster giving me errors.Also, tried using an exploit against the P***** Server but no output. am i on the right track or what? and if someone would PM me it would be great
nevermind found the page. better not ban dir scanners next time :P
feel free to PM me.
| OSCP |
who keeps crashing the machine? OMG!! i managed to get user but someone keeps crashing it and i spent all my resets for the day.
Just rooted this amazing box. thanks @lokori you did a very nice job building it. and thanks @menoetius for help
Spoiler Removed - Arrexel
Spoiler Removed - Arrexel
Hey @cichy. Thanks I figured out how to read files and gotten some useful info like usernames but not sure where to go from here. Is bruteforcing required after that?