Postman

Rooted my mf was not working properly now fixed with the sl and got root

Rooted, thanks whoever helped me

Can anyone give me a hint about getting a user for the postman

Rooted :slight_smile: good box, and the classification is valid. Thanks @TheCyberGeek !

Rooted! Fun box. For user i had to reset the box in order to get the default directory for r****, so make sure you know where you are.

I think I’m using the correct exploit but when I try to run it only i see “receive data” two times and that’s it, but I’m not sure what I’m doing wrong.

Rooting is always an adrenaline rush :stuck_out_tongue:

Awesome box! User was fun! After that, root was fairly straight forward. Thx @TheCyberGeek !

PM for Nuggets

Hack The Box

hint for root: if mf doesn’t work but c**k says ‘vulnerable’, then this → try harder =)

rooted

PM me for help.

Pretty easy box. When i was waiting for user, i eventually got root lol.

User (or initial shell): do you see something new in your scan? A pretty nice time to google about it, isn’t it? Hint: as mentioned above, don’t change the dir

Root: simpler than 2, 3, 5, 7 and 11. I even didn’t use LinEnum. Connection closed? Maybe you are not welcome to come through this door? But every house has windows


PM if you completely lost :wink:

can someone please tell me where i can read up on using ssh2john.py
never mind found it!

Hi all! I am stuck in ris. i noticed that here is no MO*E command, so exploits didnt work, drop some key file in some directory isnt work for me (idk, is it working at all). i think i can do something with LUA scripting here, but no luck. Help, i need somebody, help
 :smiley:

This is my first attempt to hack the box after 2 weeks of learning.
The box is rooted thanks to a great community, you are the best guys!

Rooted! Fun box. Learn a lot through user!! PM if you need some help!

I am root! :stuck_out_tongue: Certainly an enjoyable box. I found the initial foothold to be a very good learning experience. :slight_smile:

My hints.

User:

1Âș The obvious exploit is not going to work.

2Âș Read articles about the vulnerability, and you will find an alternative approach. There are tons of articles about it.

3Âș Once you do your research, remember that not all home directories fall under home.

4Âș Play with a client tool to get additional information.

5Âș Prepare your attack, and get in.

Root:

1Âș Go back to your initial enumeration.

2Âș Don’t overthink. Root is easy.

@TheCyberGeek , thank you for the box.

Rooted! thanks people from HTB for all the hints!
fun box for beginners
 like me ?

Just got root!

Thanks to @TheCyberGeek for the box.

PM if you’re stuck.

i found the i*_**.**k and i try to john with rockyou and no luck, did i miss somthing ?