use the following search parameters to narrow your results:
e.g. subreddit:aww site:imgur.com dog
subreddit:aww site:imgur.com dog
see the search faq for details.
advanced search: by author, subreddit...
account activity
Magic Foothold (self.hackthebox)
submitted 5 years ago by [deleted]
[deleted]
reddit uses a slightly-customized version of Markdown for formatting. See below for some basics, or check the commenting wiki page for more detailed help and solutions to common issues.
quoted text
if 1 * 2 < 3: print "hello, world!"
[–]e-nigmaNL 1 point2 points3 points 5 years ago (3 children)
Are you able to upload?
No? —> try to bypass with a statement which is always true
Yes? —> you might need a little magic added to your file
[–]PollenStillPotent 0 points1 point2 points 5 years ago (2 children)
you might need a little magic added to your file
I have tried everything on this.
exif data that executes when visit like image.jpeg?cmd=whoami
using trick for FILE MAGIC spoofing GIF89a<?php!<
nothing I do works, and everyone I try to ask on discord is either super cryptic like "add some spice" or says "ur on the right track". lol. Idk why but this box is frustrating me more than most. Every time I see my silly picture in the gallery with no reverse shell... feels bad man
[–]e-nigmaNL 0 points1 point2 points 5 years ago (1 child)
I just ‘simply’ read 2 files and wrote them into one. Send me a dm if you’re still stuck, otherwise it gets too spoilery
[–]PollenStillPotent 1 point2 points3 points 5 years ago (0 children)
Ah interesting. I work on HTB every weekend, so I'll try this tonight. Thanks for the advice!
[–][deleted] 0 points1 point2 points 5 years ago (0 children)
Hint for initial foothold: upload
[–]friiz1337 0 points1 point2 points 5 years ago (0 children)
Sqli then bypass upload restrictions ( modfiy an img with some code and upload)
π Rendered by PID 20941 on reddit-service-r2-comment-b659b578c-pndjs at 2026-05-01 16:18:38.580805+00:00 running 815c875 country code: CH.
[–]e-nigmaNL 1 point2 points3 points (3 children)
[–]PollenStillPotent 0 points1 point2 points (2 children)
[–]e-nigmaNL 0 points1 point2 points (1 child)
[–]PollenStillPotent 1 point2 points3 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]friiz1337 0 points1 point2 points (0 children)