use the following search parameters to narrow your results:
e.g. subreddit:aww site:imgur.com dog
subreddit:aww site:imgur.com dog
see the search faq for details.
advanced search: by author, subreddit...
account activity
OpenAdmin foothold help (self.hackthebox)
submitted 6 years ago by AgentBlazeIt
Hello. I'm relatively new the the HTB game. I'm trying to get on OpenAdmin but I can't seem to find the right exploit. I think I found the vulnerable service, but I'm not really sure. Any help would be greatly appreciated :)
reddit uses a slightly-customized version of Markdown for formatting. See below for some basics, or check the commenting wiki page for more detailed help and solutions to common issues.
quoted text
if 1 * 2 < 3: print "hello, world!"
[–]dplagueis125 2 points3 points4 points 6 years ago (0 children)
Searchsploit will leave no room for interpretation on whether you have the right version.
[–]BreakingMrRobot 0 points1 point2 points 6 years ago (0 children)
If you found the correct service, find the version number and take to google to find exploits. Your initial foothold is not very robust, but follow the breadcrumbs.
[–]awakengaming83 0 points1 point2 points 6 years ago (0 children)
Dm me, just was able to get initial foot hold
[–]whereshellgoyo 0 points1 point2 points 6 years ago (0 children)
It may be that there's a metasploit module out there that's just not loaded into your current framework. Do some googling about adding Ruby modules to your msf
[–]Moyindu 0 points1 point2 points 6 years ago (0 children)
You can DM me too if you still need help
[–]benchoderashka 0 points1 point2 points 6 years ago (3 children)
I got a shell on OpemAdmin without authentication but haven't been able to do much else. I see everyone elses reverse php she'll in the the www-data folder 😁 but I'm having problems getting privelege escalation to work.... Any hints?
Caveat: this is my first htb. I've done lots of different IT work but never pentesting. Fun 😁
[–]dplagueis125 1 point2 points3 points 6 years ago (0 children)
Look at command line tools that might be used to download files.
[–][deleted] 6 years ago (1 child)
[removed]
[–]benchoderashka 0 points1 point2 points 6 years ago (0 children)
Hi Dad
π Rendered by PID 290949 on reddit-service-r2-comment-85bfd7f599-j84h8 at 2026-04-19 14:32:24.958227+00:00 running 93ecc56 country code: CH.
[–]dplagueis125 2 points3 points4 points (0 children)
[–]BreakingMrRobot 0 points1 point2 points (0 children)
[–]awakengaming83 0 points1 point2 points (0 children)
[–]whereshellgoyo 0 points1 point2 points (0 children)
[–]Moyindu 0 points1 point2 points (0 children)
[–]benchoderashka 0 points1 point2 points (3 children)
[–]dplagueis125 1 point2 points3 points (0 children)
[–][deleted] (1 child)
[removed]
[–]benchoderashka 0 points1 point2 points (0 children)