Got root (shell and file). I found the privesc method a few hours ago, but it took me a while to figure out how to use it. I just kept getting denied over and over again.
Good stuff. PM me if you need hints, though you won’t get a response tonight. I’m going to bed.
I just got root, but I think someone left a file there that helped me a lot. Haha. Anyway… don’t really know if it was there when I was enumerating before. If not, I want to learn how to do it properly. PM anyone?
Easy if you have a bit of experience. If you don’t, this will be a good box to work out the basic approach. User slaps you in the face and root is basic recon plus looking at your results carefully. If you don’t think you have the tools for recon or exfil, then go get them (it’s just a google and an apt-get away).
@Skunkfoot I meant the output of the system enumeration, that I didn’t read carefully. I was expecting something that will stick out with a crazy name. Instead, I was looking at that file like 3 times, and dismissed it like “nah, that’s not it, that’s probably some htb process”. Oh boy, how was I wrong.
I wish the box creator didn’t log hackers actions. I rooted the box before getting user because the steps were logged in an obvious file… I always give a reset before i try a new box, but i guess someone was faster then me and spoiled the box.
Just owned the machine. User was pretty straightforward with a little ‘CTF challenge’. I found root to be a bit harder. After speaking to someone else about it, I found there was a much easier way than mine though.
For anyone still stuck: as someone said before ‘knock on all the doors’. When you can’t get to the user.txt, look closely at the files you’re presented.
@nawaronin said: @Skunkfoot I meant the output of the system enumeration, that I didn’t read carefully. I was expecting something that will stick out with a crazy name. Instead, I was looking at that file like 3 times, and dismissed it like “nah, that’s not it, that’s probably some htb process”. Oh boy, how was I wrong.
Ah yeah I did the exact same thing haha.
@Phrenesis2k said:
I always give a reset before i try a new box, but i guess someone was faster then me and spoiled the box.
This should be standard practice by everyone, if not an outright rule or something. I always reset a box when I finish it. (Although to be fair, on a free server with a new, easier box like this, there would be constant resets and people would be pissed).
@rbit said:
Just owned the machine. User was pretty straightforward with a little ‘CTF challenge’. I found root to be a bit harder. After speaking to someone else about it, I found there was a much easier way than mine though.
For anyone still stuck: as someone said before ‘knock on all the doors’. When you can’t get to the user.txt, look closely at the files you’re presented.
That knock statement threw me off for a bit. I started looking into port knocking and all sorts of crazy stuff. Obviously I was way overthinking things.
That knock statement threw me off for a bit. I started looking into port knocking and all sorts of crazy stuff. Obviously I was way overthinking things.