Poison

@Ethic said:

@gm0 said:
Done and glad for it!

  1. Once you have the zip unzipped then the contents purpose will become obvious once you have have worked out the priv esc.

The thing is I know how perform the priv. esc. At least, I think. I found the vulnerable service and which protocol to use to reach it. And I’m stuck here. How use the zip file at this point ? I have read a lot the manual of clients for this protocol, but I can’t find the particular option. Please, give me a hint.

I did it ! Finally ! I tried to use the wrong secret file, so it didn’t work well. I am a stupid guy.

@xdaem00n said:
I don’t know if I’m on the right road. I’ve successfully gained a normal shell and unzipped the file. I checked for services and I think I found the one I need to use, I might be wrong though. However, it tells me that its unable to open display. Help?

Think like a sysadmin. What a sysadmin, with security knowledge, would to do ?