Access

Hi, any anyone assist me with getting the privesc for the root flag, I have tried do many commands to elevate but seem to have brickwalled on this :frowning:
PM me and I can tell you where I am at, I believe I am close but cannot seem to get the syntax to work.

Spoiler Removed - egre55

As an FYI for those that might make the same mistake as me…there are multiple tables with useful information. Not just one.

Rooted this box yesterday, i liked it! Good box to learn some new tricks on.
My most valuable tip for user.txt was to check how you get your files, if they are corrupted. After that it’s just reading and executing step by step, with a little bit of searching.
For priv esc, just use the command that’s been stated here a lot. It finally worked for me, after i replicated the environment on my own windows box, and then crafted the string until it did what i wanted it to do. When you do it on your own windows box you can check for syntax errors etc. My tip: Just write your command on your windows box until it does what you want, then change the paths and copy it over to your user shell. :slight_smile:
If anyone needs help, feel free to PM me, i don’t spoil, just nudge you in the right direction.

Would really love some help on getting user. I have the 2 files and am sure they are not corrupted. Tried to cat these files for any useful strings but couldn’t find any. Also used m**tools cmds, but couldn’t read the header. Any tips or DMs would be really appreciated!

@SneakyManatee said:
Would really love some help on getting user. I have the 2 files and am sure they are not corrupted. Tried to cat these files for any useful strings but couldn’t find any. Also used m**tools cmds, but couldn’t read the header. Any tips or DMs would be really appreciated!

Tip: Keep trying to use that tool. Check out for every command you can use with it (there’s more than one). Google is your best friend now.

ROOTED after 3 days! that was fucking awesome hard, but learned alot of new things in windows… a HUGE thanks to @franpen for the help, without you i wouldn’t be able to do it buddy!

Just got root too. PM me if you want some help.

@SneakyManatee said:
Would really love some help on getting user. I have the 2 files and am sure they are not corrupted. Tried to cat these files for any useful strings but couldn’t find any. Also used m**tools cmds, but couldn’t read the header. Any tips or DMs would be really appreciated!

Check the type of the files you have, and how to handle them. Google is a big asset here.

@franpen said:

@SneakyManatee said:
Would really love some help on getting user. I have the 2 files and am sure they are not corrupted. Tried to cat these files for any useful strings but couldn’t find any. Also used m**tools cmds, but couldn’t read the header. Any tips or DMs would be really appreciated!

Tip: Keep trying to use that tool. Check out for every command you can use with it (there’s more than one). Google is your best friend now.

Thanks for your reply. I have looked through each part of the tool. I’m able to see the content and export to .c**. Have tried to go through the content but haven’t gotten anywhere sadly. Would like any help (even spoiler level help via PM)…thanks!

@SneakyManatee said:
Thanks for your reply. I have looked through each part of the tool. I’m able to see the content and export to .c**. Have tried to go through the content but haven’t gotten anywhere sadly. Would like any help (even spoiler level help via PM)…thanks!

Just keep looking. Something in there must tell you what to do next. You will find it eventually !

can’t get root. I have admin access, cant seem to get a reverse shell. pm me please.

I am Stuck… I got user before I knew it, but struggling on root. PS not getting me anywhere. Ran the tools in my win box, and I have the stx right where I am not getting any errors, but I can’t seem to get the commands to c* or >> the file anywhere… I hope this is making sense. Any Nudge with the r**** /s****** " *** \ " …(you get the drift I hope) would be appriciated. PM Please !

Hi everybody, I manage to get root maybe too easy and I’d like to check my approach, if anybody is willing we can take it offline, my idea is to use technique that everybody are talking about (r***s) and to run common program on target in order to get reverse shell on my box and it works. Manage to read root.txt without any issue and everybody are complaining about that. So, from my perspective it looks too simple and I did’t get issues that everybody are mentioning… My concern is that my technique maybe works only in certain conditions so I’d be glad to verify my approach if anybody is willing to briefly discus it offline :slight_smile: Cheers!

Tried every possible variation of the ru*** command without any luck. I think that something is messed up with my syntax, but can’t think of any other way anymore, maybe some good soul can help me with some tip?

Yay, finally rooted.
Awesome machine @egre55 - I did learn a lot here. I must admit it was also equally frustrating as well as fun.

Head needs a rest now.

Can someone send me a PM? I’m almost positive my r**** command is correct but I’m turning up nothing.

My first approach for getting root.txt was to play with file permissions and while I was able to give the user account all file privileges (and ownership) of root.txt, I still wasn’t able to read it. I eventually found a way around it and got the information from the file, but could someone point me to a source that would explain why reading was not possible when seemingly one had all the permissions? I thought I had fixed UAC registry entry as well. A later experiment with reverse shell seemed to be bit more straightforward approach for this, though :slight_smile:

finally managed to get root, thanks @joesch for the hint!

Hello everyone I need help, I have the zip and the damaged file in c. someone can give me clues what to do next.
P.S. Excuse me for my bad English.