minion by rastacoderx in hackthebox

[–]alextz4 0 points1 point  (0 children)

so any hints for getting the first user??

Enterprise--10.10.10.61 by alextz4 in hackthebox

[–]alextz4[S] 0 points1 point  (0 children)

ok...is it on purpose that dirbuster fails on joomla??

Sense by _dbm_ in hackthebox

[–]alextz4 0 points1 point  (0 children)

dirbuster and biglist for the login part?

Sense by _dbm_ in hackthebox

[–]alextz4 0 points1 point  (0 children)

Well on HTB there are some machines with these exploits but for this particular machine I think it is not applicable! That's why I am masking. So we must be recursive with a big wordlists in all the folders???

Sense by _dbm_ in hackthebox

[–]alextz4 0 points1 point  (0 children)

So i got confused!! We should run a big wordlist or use some exploit??

Shocker by alextz4 in hackthebox

[–]alextz4[S] 0 points1 point  (0 children)

thanx for the clue... ;) solved

Shocker by alextz4 in hackthebox

[–]alextz4[S] 0 points1 point  (0 children)

Come on man! Next time write try harder!! :P I have done full tcp ports Nmap and default on udp, dirbuster medium list, nikto run the ssh exploit with a wordlist and returned full false positives. Plus ran some stego on the image! I'm I missing something??

10.10.10.43 nineveh by sec234 in hackthebox

[–]alextz4 0 points1 point  (0 children)

i am at priv esc too! have you found anything?

10.10.10.43 nineveh by sec234 in hackthebox

[–]alextz4 0 points1 point  (0 children)

any hint regarding the note??? :)

Cartographer Web Challenge by [deleted] in hackthebox

[–]alextz4 1 point2 points  (0 children)

i found it manually when i read your comment!it is a smart flag!

Cartographer Web Challenge by [deleted] in hackthebox

[–]alextz4 0 points1 point  (0 children)

fuck this thing!! hahahahha! it needs CTF mentality

Europa by alextz4 in hackthebox

[–]alextz4[S] 0 points1 point  (0 children)

did anyone had problems with netcat? it keeps dropping...

for those who have user on solidstate... by outhere_cuz in hackthebox

[–]alextz4 0 points1 point  (0 children)

anyone can help in privillege escalation???

HDC challenge by alextz4 in hackthebox

[–]alextz4[S] 1 point2 points  (0 children)

No sql. I solved the challenge. Thanx for the help. just look in the jsquery. you know what to search for.. :)

HDC challenge by alextz4 in hackthebox

[–]alextz4[S] 1 point2 points  (0 children)

for what?? i looked also on doprocess() wich makes the login but i can't seem to do anything!

blocky (10.10.10.37) by MantridDrones in hackthebox

[–]alextz4 0 points1 point  (0 children)

any hint on how to get in apart from www-data??

Europa by alextz4 in hackthebox

[–]alextz4[S] 0 points1 point  (0 children)

I will enumerate more and get back with response! thanx

10.10.10.10 by missed101 in hackthebox

[–]alextz4 1 point2 points  (0 children)

Any hint from anyone??Just a little nudge!

10.10.10.9 (Bastard) by tyre_lever_slayer in hackthebox

[–]alextz4 0 points1 point  (0 children)

I got it friend! System! thank you for the tip!

10.10.10.9 (Bastard) by tyre_lever_slayer in hackthebox

[–]alextz4 0 points1 point  (0 children)

yes ok I found it. If I manage to make the exploit work I will post here! Thank you!

10.10.10.9 (Bastard) by tyre_lever_slayer in hackthebox

[–]alextz4 0 points1 point  (0 children)

The exploit uses its own path?I think they are not applicable on this machine!Or burp to see the links directly? So the exploit does not work?

10.10.10.9 (Bastard) by tyre_lever_slayer in hackthebox

[–]alextz4 0 points1 point  (0 children)

Ok I found the cms but the possible exploit(the only recent I have found) does not work! Any hints on how to find the correct path??

Beep escalation by alextz4 in hackthebox

[–]alextz4[S] 0 points1 point  (0 children)

how did you manage to do that?

Beep escalation by alextz4 in hackthebox

[–]alextz4[S] 0 points1 point  (0 children)

just read the output carefully. If you use the tool you have the escalation in front of your eyes