Posts: 16
Threads: 1
Joined: Aug 2023
(Sep 04, 2023, 04:05 AM)exer Wrote: (Sep 04, 2023, 12:52 AM)hackxor Wrote: (Sep 04, 2023, 12:51 AM)creativethinking2111 Wrote: (Sep 04, 2023, 12:49 AM)hackxor Wrote: (Sep 04, 2023, 12:49 AM)creativethinking2111 Wrote: Need help on getting user. I am currently in a shell as app. No clue what to do next. Thank you!
looks for postgresql
I have been doing just that. Was able to find kanderson creds that are useless but nothing else
inside the app folder has a .jar file, you gotta reverse this file and get the creds for postgre
How do i extract or decompile the jar file?
you can use the jd-gui
Posts: 9
Threads: 0
Joined: Sep 2023
this machine is very hard i think
Posts: 41
Threads: 2
Joined: Aug 2023
Root is easy just gtfobins
Posts: 5
Threads: 0
Joined: Sep 2023
I got connection back to my vm but after I type command it doesn't display anything back
I try all command to spawn shell but still not work any suggestion?
https://sushant747.gitbooks.io/total-osc...hells.html
Posts: 75
Threads: 1
Joined: Jul 2023
(Sep 04, 2023, 12:35 AM)guacadmin Wrote: (Sep 04, 2023, 12:00 AM)monkeythefirst Wrote: Hi everybody. I can not get /admin page; i got Cookie (JSESSIONID) of user kanderson, reloads some pages with it - no result. PLS any hint. Thanks advance.
you just need to edit your current cookie and refresh the webpage. (your cookie should now be the kanderson cookie that you found on that endpoint.)
hay...as you said edit my current cookie....i dont have one when i send a request the /admin page it generates a new cookie but the thing is that the cookie olny shows un the the response and dosent reflect on the redirect to /login This forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Leeching | https://breachforums.ai/Forum-Ban-Appeals if you feel this is incorrect.
Posts: 25
Threads: 2
Joined: Aug 2023
(Sep 04, 2023, 02:07 PM)hacker1353 Wrote: (Sep 04, 2023, 12:35 AM)guacadmin Wrote: (Sep 04, 2023, 12:00 AM)monkeythefirst Wrote: Hi everybody. I can not get /admin page; i got Cookie (JSESSIONID) of user kanderson, reloads some pages with it - no result. PLS any hint. Thanks advance.
you just need to edit your current cookie and refresh the webpage. (your cookie should now be the kanderson cookie that you found on that endpoint.)
hay...as you said edit my current cookie....i dont have one when i send a request the /admin page it generates a new cookie but the thing is that the cookie olny shows un the the response and dosent reflect on the redirect to /login
go to homepage, replace the default JSESSIONID with the new one from sessions and visit /admin
Posts: 3
Threads: 0
Joined: Sep 2023
(Sep 04, 2023, 02:07 PM)hacker1353 Wrote: (Sep 04, 2023, 12:35 AM)guacadmin Wrote: (Sep 04, 2023, 12:00 AM)monkeythefirst Wrote: Hi everybody. I can not get /admin page; i got Cookie (JSESSIONID) of user kanderson, reloads some pages with it - no result. PLS any hint. Thanks advance.
you just need to edit your current cookie and refresh the webpage. (your cookie should now be the kanderson cookie that you found on that endpoint.)
hay...as you said edit my current cookie....i dont have one when i send a request the /admin page it generates a new cookie but the thing is that the cookie olny shows un the the response and dosent reflect on the redirect to /login
in this case Replace the same cookies of kanderson
Posts: 37
Threads: 1
Joined: Jul 2023
(Sep 04, 2023, 04:05 AM)exer Wrote: (Sep 04, 2023, 12:52 AM)hackxor Wrote: (Sep 04, 2023, 12:51 AM)creativethinking2111 Wrote: (Sep 04, 2023, 12:49 AM)hackxor Wrote: (Sep 04, 2023, 12:49 AM)creativethinking2111 Wrote: Need help on getting user. I am currently in a shell as app. No clue what to do next. Thank you!
looks for postgresql
I have been doing just that. Was able to find kanderson creds that are useless but nothing else
inside the app folder has a .jar file, you gotta reverse this file and get the creds for postgre
How do i extract or decompile the jar file?
just do: unzip filename.jar
Posts: 3
Threads: 0
Joined: Sep 2023
Sep 04, 2023, 05:30 PM
(This post was last modified: Sep 04, 2023, 05:31 PM by exer.)
(Sep 04, 2023, 04:09 PM)4ip0k Wrote: (Sep 04, 2023, 04:05 AM)exer Wrote: (Sep 04, 2023, 12:52 AM)hackxor Wrote: (Sep 04, 2023, 12:51 AM)creativethinking2111 Wrote: (Sep 04, 2023, 12:49 AM)hackxor Wrote: looks for postgresql
I have been doing just that. Was able to find kanderson creds that are useless but nothing else
inside the app folder has a .jar file, you gotta reverse this file and get the creds for postgre
How do i extract or decompile the jar file?
just do: unzip filename.jar
It doesn't let me do it, i get permission denied every time.
Posts: 29
Threads: 5
Joined: Sep 2023
Sep 04, 2023, 06:58 PM
(This post was last modified: Sep 04, 2023, 06:59 PM by tiredhacker.)
pm me if you want the dump report This forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Reselling another users exam.
|