Official Worker Discussion

1235789

Comments

  • Rooted! Spent more time fighting with the lag than actually doing the box though.

    DM for nudges.

  • edited August 18

    For those who are getting an unstable shell for the root part, there are so many ways to get a perfect shell as admin :P I literally did it in 3-4 ways :D

  • Rooted!!!.
    User: Check everything in the machine.
    Root: documentation will help u.

  • edited August 18

    Very funny box!
    If anyone needs a help, contact me :)
    Hack The Box

  • edited August 18

    d.... page login

    same as yesterday

    Connection timed out

    So I think dev....... site is only a rabbit hole.

  • Type your comment> @rholas said:

    d.... page login

    same as yesterday

    Connection timed out

    So I think dev....... site is only a rabbit hole.

    Try to change VPN servers, it was very slow for me on EU, but I changed it for AU.
    No major rabbit holes on this box. ;)

  • [email protected]:~/htb/boxes/worker# nc -nvlp 9001
    listening on [any] 9001 ...                                                                
    connect to [10.10.16.7] from (UNKNOWN) [10.10.10.203] 50577                                
    
    PS [REDACTED]> whoami                                                     
    nt authority\system    
    

    Great box, learnt a lot. PM for hints

  • Found the login page but cant find the password. I guess n****n is the username? Any nudges on password?

  • edited August 18
    Type your comment> @gs4l said:
    > Found the login page but cant find the password. I guess n****n is the username? Any nudges on password?

    Oh! If you enumerated correctly, the password would be in the next line after username.

    A Chemist doing Penetration Testing - Check the Story here: BinaryBiceps

  • It is impossible to move forward with this box. page load times are between 2 and 5 minutes each time, so the automated process will already delete my branch before all necessary steps can be completed.

  • Type your comment> @d3adb33f said:

    It is impossible to move forward with this box. page load times are between 2 and 5 minutes each time, so the automated process will already delete my branch before all necessary steps can be completed.

    You can try another server. Hit or miss. Or come back to it later. Sometimes it's ungodly slow, and sometimes it flies.

    ori0nx3

  • Type your comment> @d3adb33f said:

    It is impossible to move forward with this box. page load times are between 2 and 5 minutes each time, so the automated process will already delete my branch before all necessary steps can be completed.

    start process and approve

  • Type your comment> @solid5n4k3 said:

    Type your comment> @rholas said:

    d.... page login

    same as yesterday

    Connection timed out

    So I think dev....... site is only a rabbit hole.

    Try to change VPN servers, it was very slow for me on EU, but I changed it for AU.
    No major rabbit holes on this box. ;)

    Thanks, worked

  • Type your comment> @rholas said:
    > I found creds for de....s.......htb page, but I get only an empty page.
    > This is a rabbit hole?

    That is not a rabbit hole> @offs3cg33k said:
    > ROOTED!!!!! Finally
    >
    > Thank you @Demethius for all nudges
    >
    > @ekenas The box was good, slow though. And I really felt the
    > ndasecureidontknowthisisgettingrediculousiagreetosomepointisthisenoughdummyuserscanyouseewhichonesare

    Ha ha, thanks, yeah my imagination wasn't at its best when creating that part :)

  • For info we are doing some research to why one big part of worker is running "kinda" slow.

    Again kudos to all of you that pushed through that part and sorry if it caused you some extra hours!

    • All things come to him who waits - provided he knows what he is waiting for -

    /ekenas (or "mr loading")

  • edited August 19

    Argghhh! This box makes me crazy...The root part is a HELL for me! 🤦‍♂️ The box is slow, very slow, very very slow.... and at the end I have the same message:

    Prepare job - Failed 🙄

    I am going mad 🤪

    Edit: Same thing yesterday night after resetting...But this morning it's functionning (Canada, EST) and it's very fast... I don't understand. 🤤

    Thanks for your "loading" box @ekenas ;)

    Fr0Ggi3sOnTour

  • Spoiler Removed

    Hack The Box

  • Rooted! Thank you @ekenas for the box. The whole thing turned out to be a learning event. Please PM if you need a nudge. Also, thanks to @iampachinko for the nudge.

  • have a username and password that worked this morning, now not so much. someone changing passwords on us?

    Arrexel

  • suddenly back to normal? wierd. i probably did something screwy

    Arrexel

  • Apart from the lag, this was a really interesting box! Thanks to @SanderZ31 for the hints :)

  • Spoiler Removed

  • Rooted!!!

  • Found user. Any tips for system/admin?

  • Type your comment> @m3chmania said:

    Found user. Any tips for system/admin?

    hint: do that which you did b4

  • edited August 20

    The box is down?

  • edited August 21

    @Pb22 said:

    @m3chmania said:
    Found user. Any tips for system/admin?

    hint: do that which you did b4

    Do I need to use another set of credentials from that user file?

    Edit: Got it. Fun box!

  • edited August 20
    Type your comment> @S98 said:
    > I don't understand. What am I doing wrong?
    > Some guys said that the creds is used in plain text.
    > I tried it over and over again, without proxy, even used
    > curl -v "http://d.w.h" --ntlm -u d.w.h/user:pass --noproxy "*".
    > For now, still no luck.

    It is possible to use curl to access the page, but you will be better off using a gui based browser.

    For you that got proxy problems, there is an issue with burpsuite and NTLM auth.

  • PM for help

  • Rooted ! :)

Sign In to comment.