Official Schooled Discussion

Type your comment> @1z3n said:

found exploit but i don’t know how can i get t*acher

Same here, stuck on getting t**cher account

Spoiler Removed

Type your comment> @cyleigh said:

Type your comment> @zAbuQasem said:

(Quote)
Is there some type of trick I’m missing (or haven’t learned)… I am not getting any results of interest. I’ve also tried dig.

It’s not a trick just see what does gobuster do beside directory busting

@Markerpullus said:
Type your comment> @1z3n said:

found exploit but i don’t know how can i get t*acher

Same here, stuck on getting t**cher account

Just the same. Jooking for some configs and soure code but still got no luck

Spoiler Removed

Spoiler Removed

I got a shell and dbae cress but it tells me that my* isn’t available and of course cannot connect from outside

PM for a nudge ?

@AbuQasem You can always “find” mysql :wink:

Spoiler Removed

Hello!
any hints for privesc to root please? :slight_smile:

A small hint about teachers account would be appreciated

Spoiler Removed

could someone pls help me with the cookie/sesskey ? :confused:

Type your comment> @michealbackson said:

could someone pls help me with the cookie/sesskey ? :confused:

try to intercept the request somewhere

@0xSecurity said:
Type your comment> @michealbackson said:

could someone pls help me with the cookie/sesskey ? :confused:

try to intercept the request somewhere

something related to the course

Type your comment> @AbuQasem said:

Type your comment> @cyleigh said:

Type your comment> @AbuQasem said:

(Quote)
Is there some type of trick I’m missing (or haven’t learned)… I am not getting any results of interest. I’ve also tried dig.

It’s not a trick just see what does gobuster do beside directory busting

I think something funky was not working with my Release Arena instance. The exact command fuzzing approach that got no results last night on the RA, worked this morning on the 10.10.10.* instance.

Has anyone else had trouble with getting the tr to mr l**i*as? I never see a “special link” appear under someone :neutral:

Stuck at privelege escalation part.
Found misconfiguration but have no idea how to exploit it.
Can someone kindly nudge me in right direction?

Spoiler Removed

fun box, root waaaay easier than user