Ypuffy

anyone can help me with s******t syntax. cant connect to the box with creds i’ve got. thanks

never mind I am stupid and was over complicating things!

This was an awesome box, and I really enjoyed cracking it… I don’t want this to be too massive a hint for root, but it was the piece of the puzzle I was missing, and I think it could really help someone!

Don’t assume that a certain service will return the same thing when looked at from outside as inside.

If that’s not vague enough, please delete!

I can;t download file from samba. Can I view it there without download?

I got user. Somebody must have messed up the machine. I reset it and was able to get in. Thanks @kmap for help

Ok, I got root, but not the intended way. I would love to figure out the way to do it via ss* si*** of ke** I read that FB article mentioned in the comments.
please DM me if you are willing to give hints. Thank you

Can anyone please dm me on trying to find the right SMB share? i cant seem to find a way to list them so struggling to connect

Can anyone please dm me on how to use lda****rch.please DM me if you are willing to give hints. Thank you

Got the root with the easy method, want to know the intended way to get it. Could anyone please help me, many thanks.

Root was simple to get due to a recently disclosed vulnerability that affects this box (work smarter not harder). Definitely an interesting way of getting an initial foothold though. I guess p***--* isn’t just for Windows environments.

got stuck!!! i have found two user’s and hash what to do next no clues anyone help me out

Hello HTB Lovers!!

I have a question with this machine, I try to convert to format a OPENSSH but I see the error.

root@xxxxx:~/Desktop# ssh-keygen -i -e -f axxxe_key_2
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: UNPROTECTED PRIVATE KEY FILE! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0777 for ‘axxxe_key_2’ are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key “axxxe_key_2”: bad permissions

any idea for this output?

thanks you

@p3p1n04s3s1n0 said:
Hello HTB Lovers!!

I have a question with this machine, I try to convert to format a OPENSSH but I see the error.

root@xxxxx:~/Desktop# ssh-keygen -i -e -f axxxe_key_2
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: UNPROTECTED PRIVATE KEY FILE! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0777 for ‘axxxe_key_2’ are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key “axxxe_key_2”: bad permissions

any idea for this output?

thanks you

you should give 0400 permission

@farid007 said:

@p3p1n04s3s1n0 said:
Hello HTB Lovers!!

I have a question with this machine, I try to convert to format a OPENSSH but I see the error.

root@xxxxx:~/Desktop# ssh-keygen -i -e -f axxxe_key_2
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: UNPROTECTED PRIVATE KEY FILE! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0777 for ‘axxxe_key_2’ are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key “axxxe_key_2”: bad permissions

any idea for this output?

thanks you

you should give 0400 permission

@farid007 said:

@farid007 said:

@p3p1n04s3s1n0 said:
Hello HTB Lovers!!

I have a question with this machine, I try to convert to format a OPENSSH but I see the error.

root@xxxxx:~/Desktop# ssh-keygen -i -e -f axxxe_key_2
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: UNPROTECTED PRIVATE KEY FILE! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0777 for ‘axxxe_key_2’ are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key “axxxe_key_2”: bad permissions

any idea for this output?

thanks you

you should give 0400 permission

got a id a***** and a hash , i’m using s******t to connect it wont

session setup failed: NT_STATUS_LOGON_FAILURE

i’m i on the right way??

please help :slight_smile:

Just rooted it after pwning the user a while ago. Wanted to do it before it retires. :slight_smile:

That priv esc was really cool, great box!

Thanks to @keresh for helping me with some vague syntaxey stuff. :slight_smile:

anyone can help me with s******t syntax. cant connect to the box with creds i’ve got. thanks

anyone want to drop a hint on privesc?? I’m at the principals office for stealing keys…

nice box , i don’t know root was really easy or i just choosen the easy way , special thanks to @clmtn