Networked

Type your comment> @Ursa said:

I’ve gotten to ‘the page’ and I have a script made, baked well and smelling tasty. The machine won’t bite and I’m wondering which piece of crust is giving me the problem. I can’t find anything worth changing in the headers (the ones I’ve tried changing don’t work out for me). Any help would be appreciated.

Maybe the hint “GIF89a” gives you a clue ?

Got the initial low priv foothold. Been examining all the PHP files and their functions but still stuck on how to escalate from here to user. Someone please PM with help/nudge so I can move forward. I’m sure i’m seeing what is required (i can see what pattern the TOUCH has to be, just not sure how to put pieces together.)

Finally got root after 3 hours of overthinking.

User tip:

  • GIF89a
  • cron
  • touch

Root tip:

  • see what u can run as root with user g***
  • research about network-scripts
  • use basic linux commands

If you need help, PM me. (please be as clear as possible, when message me. Like, what have you done, where are you stuck, etc.)

ROOOTEED!! thanx for help @D3Fix … you are boossss

Type your comment> @Akagami said:

ROOOTEED!! thanx for help @D3Fix … you are boossss

You are very welcome. It was a pleasure to give you the hints, to solve this.

@D3Fix I got it to work with png, I’m at the point where I have to look at a certain file to privesc. I appreciate your help and the pointer though.

Not easy for beginners to obtain r00t without using the forums.

This root is the most stupid root I have ever encountered.lol

Got user thanks to all the helpful hints from @D3Fix

Now onto root :slight_smile:

Edit: got root finally. Right as I was about to go to bed :slight_smile:

Feel free to PM with questions for nudges/help and i’ll do my best to help you along.

Type your comment> @blooch4 said:

Got user thanks to all the helpful hints from @D3Fix

Now onto root :slight_smile:

You’re welcome!

Isn’t user apache?

Rooted!
Getting the initial foothold is fun. There are a bunch of hints here for user. The link to an article posted earlier is the clearest explanation of what you are trying to do.

When I first got user, there was a power outage just as I was going to grab the flag… Great timing!

The advice in this thread to keep things simple for root are spot on. I wasted time over complicating things. Basic enumeration. Basic linux commands.

hey, im stuck as a***** shell, i cant figure out where to touch as everything seems to be denied ive read c****_a*****.*** and think i know which i need to touch but it just says perms denied? any help would be appreciated

EDIT : nvm i got user

If anyone is good at PHP, I’d very much appreciate a PM. I don’t want to put too many details here, but two parts of a certain script are troublesome and I can’t find what they do anywhere online.

I got root, but dont quite understand why it works the way it does… if anyone that understands it could PM me and bestow that knowledge upon me, I’d really appreciate it!

Type your comment> @Ursa said:

If anyone is good at PHP, I’d very much appreciate a PM. I don’t want to put too many details here, but two parts of a certain script are troublesome and I can’t find what they do anywhere online.

You can PM me if you still need help

My first box! Learned a lot from this one. Thanks!

Hello guys,
Please could you help me ? I tried upload .php file but without success pleas could you someone provide right way for me ? :slight_smile:

if anyone needs help with the c***_a***.php code and/or how can do the privesc to user send me a dm

Edit: Rooted.