Access

just GOT ROOT!
■■■■ this was cool, I learned something new!
PM me for hints! no spoiler!!

Alright, I’ve tried hundreds of variations of the r***s command. Can someone help me out?

EDIT: nvm the 101 combo worked!

rooted

@TazWake said:

@iainpbsec said:
i’ve managed to get the root flag copied into another file by using ru*** and a quick script, but i can’t read file that either or change its permissions.

Copying it might not be the best approach.

I’ve just popped root, but I’m not happy with it because I don’t follow this.

Can anyone elaborate on why this is the case? I can copy the file to my own user desktop directory and run takeown.exe and still can’t access the file. I can’t replicate that on any of my own servers. If it’s in a directory you own, I’ve always been able to do this.

There has to be something special on this server, you’ll probably need to PM to avoid spoilers.

Trying to exec r**** command like “blind” within a telnet session, without knowing the behaviour first, it’s a pain in the a**
So…

Finally got root. Big thanks to @3poke and especially @TazWake for their useful hints and advice.

Finally got root, thanks to @14NC3107 for your very useful hints

I enjoyed the ride on this box, didn’t need to go through this thread for a change. But skipping through it, I think the thread contains a lot, or even too much, info to get yourself to the flags.

can’t make r***s work in any way
I ried many many different forms
none of them worked
This is annoying I have been trying for 3 days

@Ahm3dH3sham said:
can’t make r***s work in any way
I ried many many different forms
none of them worked
This is annoying I have been trying for 3 days

tried*

rooted ! that box was insane I spent three days struggling with one command !
thanks a lot @stanl3yz3ro @Jacker31 @theZer0

thanks @TazWake for the alternative approach !

@blobbo said:
If your file is corrupted, make sure your transfer mode was set to BINARY.

Thx

@technion said:

@TazWake said:

@iainpbsec said:
i’ve managed to get the root flag copied into another file by using ru*** and a quick script, but i can’t read file that either or change its permissions.

Copying it might not be the best approach.

I’ve just popped root, but I’m not happy with it because I don’t follow this.

Can anyone elaborate on why this is the case? I can copy the file to my own user desktop directory and run takeown.exe and still can’t access the file. I can’t replicate that on any of my own servers. If it’s in a directory you own, I’ve always been able to do this.

There has to be something special on this server, you’ll probably need to PM to avoid spoilers.

I believe it has to do with permissions of the file being retained when you copy from/to the same volume in windows. It depends on how you are trying to open it, if you’re just in telnet, your options are limited.

edit: interesting box. By far the easiest, except for the corrupt files (binary or otherwise) that were a real pain. It seemed like a SANS challenge, “download a weird file and figure out the right program to install on your kali box to view it”

Kind of stoked, I was able to get user on this machine in under an hour :slight_smile: Lots of creds, lots of info…now root!

@flexkid said:

@0xlc said:

@flexkid said:

@0xlc said:

@flexkid said:
I have the .pst file any hint for the next step?

open it :sweat_smile:

yes but how xd I tried but nothing I also imported on windows

i am on linux i just imported in Evolution

same I installed in evolution and but did not load the file

Anyone not familiar with PST, there are utilities in linux that allow you to parse these right from the shell, fyi. WAY easier than screwing around with a mail client.

I can run the r**s command, formatted similarly to the example so I don’t get prompted for credentials. I have a few pages of commands I have tried, but I can’t seem to find the right approach. Any help would be appreciated, this is my first active box I got access (lol) on, but I can’t make the leap to privesc. I think I need some help to knock some ideas loose. NOT looking for an answer, would prefer someone ask me the right question.

I need help can someone pm me with some hints, Im stuck with run__ command to get to the root.

Finally got root.txt. Thx for @Tree and @Ahm3dH3sham help!!!

@sayyeah said:
Finally got root.txt. Thx for @Tree and @Ahm3dH3sham help!!!

You’re welcome :wink: