Curling

Got root flag about a week ago, but I just HAD to get root shell. Having only been on Linux for a few weeks now, this was quite a learning experience.

Special thanks to @deviate for getting my head straight and finally getting the root shell.

Got root flag, interesting choice of a name for a box :wink: Learned a lot.

Anyone could PM me how to get the root, struggling with curlā€¦ but no result.

I am trying c*** on r**tr**t.txt but getting error Can any body let me know am I moving in right direction

Got a shell via upload, and the pass file. However have no idea what to do with it. The thread give a good clue but not really sure how use itā€¦ Any hints or PMs welcome!

UPDATE: Followed the steps from a hint in this thread, dont understand what I did, or how i did it, but I have userā€¦

Overthinking as usual :slight_smile:

Got root.txt but stuck at getting root shell. Please PM for hints

Hi Guys, I got user, but iā€™m pretty new at priveesc. All hints super appreciated :+1:

Finally completed the box. Thank you @L4mpje :+1: learned a lots of basic stuff to complete the box, never used those command like this before :slight_smile:

Got root!!! hostname is key to get root. :wink:

Obtained the root flag finally. Thanks to @iphkvm for the help!

I have also rooted Irked, what box if recommended next for a beginner?

I got user but Iā€™m stuck on root. I see that the key itā€™s either c*** or w**** but nothing I try works. Can I get a hint from anyone?

Hi guys, can someone hint me?
I found the pb file but iā€™m stuck deciphering, someone can PM me ?

I got User. Thank you Marvin for you hint !

Hey guys,

Trying to solve my first machine here. Managed o get a shell as www-data. Found three files user.txt, a***-a***, p*******_b*****. No clue how to move ahead from here. cant read user.txt. Could someone help or give and hint on how work on p*******_b*****.
P.S : newbie here.
Thanks.

@WickSec said:
I got user but Iā€™m stuck on root. I see that the key itā€™s either c*** or w**** but nothing I try works. Can I get a hint from anyone?

try looking at the enumeration result carefully ā€¦
anything out of the ordinary ā€¦check it out
Also there is a reason why the box is named CURLing

Hi guys, so this is my second box in HTB. Iā€™ve got user, and i see two files in the a****-area, but i am not sure how to check which program is updating them, can anyone give me a hint please? Thanks!

Edit: got root txt, thanks everyone for the hint!

Read the comment above yours

got root.txt ,
but stilll dont know how to get root shell, please PM me if someone get root shell already.

EDITED: now got the root shell, thank you.

feel free to PM me if need a hand

Tried scanning with joomscan, joomlavs, nmapā€¦ browsed directories as a result of joomscanā€¦ got the username too on blog i.e. F***** ,saw s*****.*** on the page source at the bottom of page. tried many combinations of usernames and password but unable to access. first time trying on joomlaā€¦ also people commenting overthewire level 12, i have completed it upto level 20 or something so that would be easy then. please help , message me.

Hey all, I have a reverse shell as w**-d***. I see the p*******_b***** file. I ran ā€œfileā€ on it, looked up the magic bytes. File says it is a**i, and the magic bytes says b2. Iā€™m stuck at figuring this file out. Can someone PM me with a hint or point me in the right direction? Thanks!