Teacher

@deviate said:

@m9rcin said:

@Hetraun said:
Got root/shell in a really destructive way.
I’m sure there’s a less destructive way using --c* , but I’ve been unable to get it to work. Is this a red herring?

–c* may not work here (although I may be of course wrong). A really destrctive way did not work for me (could 't have made it work). What worked was "a bit destructive) for a very short period of time -:slight_smile:

I wasn’t able to make --c* work here, however there is another shell globbing trick which does work and can result in a root shell without impacting anything outside of /home/g*******.

This is interesting. I did not use --c* (again I thing it is rather not possible here) but there was another simple trick available in the same area. However I did not impact negatively anything and definitely not /home/g*******
PM me if you want to discuss details.

Has anyone on VIP had problems with false positives while using burp for m*****?
Hydra worked perfectly on the other hand.

Rooted.
I found this box a struggle. Still dont get how I got root… I need to spend more time learning this!! I may go back and do it later or just read some write ups…

PM me and I can give you a few hints if you need it.

I’ve finally got user.txt after a lot of enumeration. But now completely stuck on what to do with root.txt. I have looked in the directory and I think I know what is going on but don’t and not sure how to find out what is causing it.

Any help is very welcome :slight_smile:

Edit: finally got it!

Graduated!

I’m struggling to get user, can someone please give me a nudge, i’d really appreciate it. I hate to ask but i cannot continue alone.
At least perhaps just what tool are you using to enum?. I’m using std ones but found nothing yet. I’m on low priv shell still :frowning:

When i try to connect through mysql it says connection refused… Is this a wrong way?

WEIRD fact, person who already solved the box, 3 weeks ago, pm me and asks for help.

Someone care to Pm me regarding moving from service account to user… Looked at running services but nothing is standing out… Maybe a pointer to some reading material or something?

@whit3sails said:
WEIRD fact, person who already solved the box, 3 weeks ago, pm me and asks for help.

maybe because this box have more than one way to get root shell :D…

@Sinflux said:
Someone care to Pm me regarding moving from service account to user… Looked at running services but nothing is standing out… Maybe a pointer to some reading material or something?

I second that, I’d appreciate any suggestion.

WTF ?

i don’t have permitions to open /home/gio but i can to read the root.txt ??
seriously ?

ignore it !
the server was breaked !

Update: finally, got user.

UPDATEEEE: YEEEEEEEEEEEEEEEEEEEEAAAAAAAAH, I’m ROOOOOOTTTT

jajja sorry by my happiness, this machine did make me insane.

Rooted.
get user flag is spend lots of time, can skip something.

guys. i own teacher. someone wish t socialice it ?

@xterm said:

@whit3sails said:
WEIRD fact, person who already solved the box, 3 weeks ago, pm me and asks for help.

maybe because this box have more than one way to get root shell :D…

:slight_smile:

Rooted :slight_smile: … if need help feel free to PM me … and thanks to all those who helped me all the way through !!

Stuck on the low priv acct trying to get to user. Can’t find anything that stands out after running through the usual enumeration scripts. Any tips would be appreciated.

Hi mates :slight_smile:

I’ve been some time enumerating about how to privesc to user. I’ve found some creds but anything useful.

Any help via PM would be appreciated!
=)

trying to connect via my*** in localhost with a shell, got by rce, show me no output (should show me shell for type s** queries). It does not return me credentials error or any other kind of error but nothing it’s shown…

EDIT: fixed with interactive shell

Got User and Root, great machine

Teacher is awesome machine… Learned a lot… If anyone wants hint… PM me…