Explore >> Select a destination


You are here

ericlathrop.com
| | stefanbohacek.com
13.9 parsecs away

Travel
| | A report on two months into hosting my sites with CapRover.
| | blog.piaw.net
15.3 parsecs away

Travel
| | We visited Yosemite for Veterans Day. It was our first time there in the fall. Photos Mist and Vernal Falls Sentinel Dome, Roosevelt Point,...
| | www.railstips.org
17.1 parsecs away

Travel
| |
| | blog.ikuamike.io
49.9 parsecs away

Travel
| Difficulty Release Date Author Beginner 2 Mar 2020 Zayotic Summary In this box, we first perform ldap injection on the web application to bypass the login page. Then we are able to read local files by abusing a local file inclusion vulnerability with php base64 filter. From one of the php files we get ldap credentials that we used to authenticate to ldap and dump entries. From the entries we get a base64 encoded password that we could use to ssh into the machine.