Nice and relatively easy box - esp. compared to the nightmare of Ghoul I did before.
Stick to the roots of what you find, do some research of the api on the upper port and find the needle in that haystack
for root: There’s no need to change any config! If you do you (and all others!) won’t succeed. Read what you find in that specific dir after getting another user, do some more research and put all together. It’s quite straight forward.
hello all. I am in as k****a I can see a thing that is running and uses input and out files. I have been trying to create my own but no luck. Can someone PM me a nudge?
I got k****a but i don’t know how to escalate any further can someone give me a little nudge
Check if there is any new folders you can read as k****a user and view the processes run by root. See if you can link any of them together and try to root from there
User : Image is important to get a hint, but is not necessary to get into User. Enumeration is the key, try to play with the high port like an API. You can use curl, in my case Burp’s Intruder help me a lot. A little knowledge of Spanish is helpful
Root: After accesing user, try to do a common enumeration, then try to access new resources. There is a common vulnerability, try to exploit different from the PoC (does not work and you will lose quite time), try some other attack vectors of the same vulnerability. After this, reading configuration is important (but you will not find some keys ) you have to understand what is performed and how to take advantage of it.
User:
1- Check out the unsecured port - it is hiding something for you
2- Enumerate the higher port and check what directories are there
3- Dump the garbage using the rubberband and you will get worthy information
4- You know what is the next step
P.S “traduce lo que encontraste al español y encuentra la aguja”
Root:
1- You don’t have enough power to do something with this user, get higher privs. Execute that vulnerability from within
2- Got power? check what you can read with your power!
3- Follow the three musketeers and see where they lead you to
P.S “hay un buen depurador por ahí, úsalo”
I got this long command that I think will trigger l****h but it doesn’t seem to work. Do I have to change something in the command or does my cf file need to be named something specific? Help is much appreciated!