Mischeif

Rooted, that was fun and tricky :wink:
At least with this box i required to research things that i have never used before so thumps up from me.

Just getting to user took me 2 weeks :smiley: This box is way fun. Some of the comments screwed me over in getting user, went down a few rabbit holes when (like so many have said) the answer was staring me in the face. Thank you @trickster0. Fun Fun Fun

very cool machine. Well done. Definitely a favorite since my short time on this site.

@TazWake said:

@laz4ras said:
still no hope

A snake might help you.

I’ve tried with the snake, but I don’t get my reverse shell and the site becomes unavailable for some minutes. I get “Command is not allowed” with the other alternatives. Any hints what I might be doing wrong?

Edit: Thanks @TazWake for the hint, I tamed the snake!

Edit2: Rooted!

where hack the box is the second login page? I’m stuck with two pairs of credentials in my hand :expressionless: I’m also aware of dead beef thing but no idea how to use it…

@clarkkent said:
where hack the box is the second login page? I’m stuck with two pairs of credentials in my hand :expressionless: I’m also aware of dead beef thing but no idea how to use it…

Don’t be a vegetarian keep the beef

@Kruq said:

@smjogi said:
I have problem with s**o
My I please a hint? or better discuss…

enumerate more :slight_smile:
There is a linux command that will help you a lot to figure out what is going on.

Hi,
could you PM me to discuss those things?

Amazing box, loved it. Thanks so much to Trickster for taking the time to make it.

I worked on this one for a couple weeks back in September, then walked away. I’m back now, and still stuck in priv esc. I’ve found the things I’m not allowed to do, and why. I’ve found some things that I’ve apparently done in the past. I just can’t figure out what to do with that information. If anyone can PM me with a nudge, I would really appreciate it.

Great box, full of twists and surprises. As previously stated keep your eyes open and check that your r-shell is working properly. Thanks putting the box together Trickster, I sharpened my enumeration game with this mischief!

For peeps stuck on second login page … look at secLists. Feel free to report if its a spoiler !

im unable to find the second login page… HELP Please!
im walk on smnp but didnt got any thing for the second login page

Where is the second login page?

initial help plz

What is the trick to bypass 2nd login page? Please PM me for any hints.

EDIT: got it

@gokuKaioKen said:
For peeps stuck on second login page … look at secLists. Feel free to report if its a spoiler !

Is bruteforce going to work? I tried but no luck. Any specific list in seclists to use?

EDIT: got it

@brohlm said:
Where is the second login page?

+1 cant seem to locate it

g0t u$er , so curious how everybody got it to spit , loki is not g0d g0d is n00kie

Found the second login page, but cant seem to find the credentials for it, even tried the ones I’m currently aware of

@r518 said:
Found the second login page, but cant seem to find the credentials for it, even tried the ones I’m currently aware of

You have all the info you need if you done the first. Just try a combination of what you got and other adminy type usernames