LaCasaDePapel

Hello guys, it’s been 2 days trying to get root, and i guess i don’t even get close… any hint? Should i have to get a remote session with the ny account, rather than p***r ?, I know it’s all about file permissions but i don’t see it… :neutral:

Edit: Done! Rooted…

If anyone it’s stuck, and need help… just let me know, PM me.

Type your comment> @thegoatreich said:

Could do with a nudge on the S*H login if anyone’s around?

Maybe its not for that user? :wink:

Oops late response. I backread thats why

Got root. Thanks to @TigaxMT for the assist. Feel free to PM me if you need help.

Thanks a lot to @p4ncontomat3 , @EthicalHCOP , @Itri3d and @AzAxIaL this machine has a lot of fun things to learn… pwn3d!!

Got the b***r shell over 6 but not sure how to exfiltrate the right file and the commands to do so using PHP. DM me.

I managed to get the certificate working after a few tweaks.
Got to the private area but found no LF*. However I can’t use any dirbusting tools due to the fact the box checks the cert for every request. a nudge in the right direction is appreciated.

I’d really love somebody to dm me a hint for how I can push forward from user? Got access to 443 and the old door. I am losin my mind over this machine haha

@mimo said:
I managed to get the certificate working after a few tweaks.
Got to the private area but found no LF*. However I can’t use any dirbusting tools due to the fact the box checks the cert for every request. a nudge in the right direction is appreciated.

Just play a little bit with the address bar, and keep an eye on the responses… even in every link.

I’m having a problem with f** - I was kicked out due to time out and after that the port won’t open anymore. Is this normal? Do I need to wait until it works again? Any help would be appreciated. Thanks.

rooted

What machine! I learned a lot, even what I should not to finish this box. :slight_smile:

Finally rooted! This machine in particular was a very difficult one for me, getting that shell took me longer than I’d like to admit! Feel free to dm for help if anyone needs a hint!

Box was pretty tedious but learned alot. Root was a bit meh imo. Would like it if someone could link to something that explains the reasons behind rooting

Type your comment> @ShadowsDays said:

Hello guys, it’s been 2 days trying to get root, and i guess i don’t even get close… any hint? Should i have to get a remote session with the ny account, rather than p***r ?, I know it’s all about file permissions but i don’t see it… :neutral:

Edit: Done! Rooted…

If anyone it’s stuck, and need help… just let me know, PM me.

I am in that exact same situation where I know it’s all about file permissions but I don’t see it. Can you help me , please??

bash-4.4# whoami
whoami
root

Cheers @thek for forcing me to learn oxxxxxl . All the hint are already mentioned here. PM if your still stuck.

stuck root. Any hint will appreciate。

Got user (thanks @el3ctr0 :smile: ) and then managed to kill the https server twice in 5 minutes :blush:

Hey everybody
I created the right certificate for the https website put when I import it on firefox the website still indicate that I need to provide a client certificate…

restart firefox.

I’ve done it already @bbdog firefox tells me that the certificate still expires in 2029 however my new certificate expires in 2020 normally

Can someone help me with the p**.sl please? I have managed to work out how to change directory but cant for the life of me read it. Just can’t do it, i can navigate, glob etc but im stuck. I’m literally staring at user.txt but…can’t read. Also wtf with $t*

Even if you want to PM me a webpage with a list of commands that will do what i need. ty