Using 0-day to pop root?

Have you used one (or would you)? Is it considered poor form/bad taste, etc.?

I did, and now I feel slimy. The worst part is that I didn’t learn anything, which, for me, is the whole point of this site. (I’m going back to the challenge to do it “the right way”)

Depends if you discovered the 0-day and if you know how it works.
Word up for making it “the right way” :slight_smile:

i mean you could let the admins know and see if they wanna patch it? some of these boxes to have unintended routes that you can find / fall into, root is root in my book

@fhlipZero said:
i mean you could let the admins know and see if they wanna patch it? some of these boxes to have unintended routes that you can find / fall into, root is root in my book

:+1: :+1: :+1:

If you just used a 0 day and didn’t learn a thing you beat the goal of HTB

yes but if you wrote the 0-day (I don’t know if this is the case though) then in my opinion you already know enough or at least more than the challenge/box will offer you (to write a 0-day most of the time means that you already know how the system operates in great detail) :wink:

I also agree with @fhlipZero - if you found a 0-day by any means you better mention it to the admins !

Anything is fair game. That being said if there’s a kernel exploit that came out after the box was released and you use it, you’re doing yourself a disservice by stopping there. If you ever think you did anything an unintended way feel free to pm me the details and I’ll let you know. If you just PM me fishing for hints, I probably won’t respond.

Yes, it was a kernel exploit, and no, I definitely didn’t write it (but I am trying to understand how/why it works).

I will let the admins know just in case they want to patch.
Thanks for everone’s input!