Traverxec

Type your comment> @D3Fix said:

I also need to crack the *ht*****d, but my friend john keeps guessing the format of the file to crack and in the end, it stops because it canā€™t guess the format.

Can anyone please PM me to get on the right track?

hashcat is your friend

Type your comment> @D3Fix said:

I also need to crack the *ht*****d, but my friend john keeps guessing the format of the file to crack and in the end, it stops because it canā€™t guess the format.

Can anyone please PM me to get on the right track?

use hash-identifier to identify and specify when u do john

hint for root pls(

The user is very simple!, now I work on the root. :smiley:

user is simple just read file

Type your comment> @rholas said:

user is simple just read file

What file? :slight_smile:

@idomino said:
Type your comment> @rholas said:

user is simple just read file

What file? :slight_smile:

Iā€™m guessing the .ht******** file
Not sure what to do with cracked creds either :frowning:

Type your comment> @samdahacker said:

@idomino said:
Type your comment> @rholas said:

user is simple just read file

What file? :slight_smile:

Iā€™m guessing the .ht******** file
Not sure what to do with cracked creds either :frowning:

I have that and the creds. But must be missing something super simple again.

I hate when I am missing super simple stuff.

d**** doesnā€™t reuse passwords obviously. me has a mā€¦-shell as www-data.

Still no ideas how to use creds, neither ssh or su works

Do you think creds could be a rabbit hole?

Donā€™t get too much stuck on the creds you find, look for ā€œbetterā€.
Currently stuck on root, Iā€™m pretty sure it has to do with all those logs but not sure how.

thank you for the nudge, and now I feel stupid.
user hint: read that interesting file you found very carefully and make sure you know what each line does.

Type your comment> @idomino said:

thank you for the nudge, and now I feel stupid.
user hint: read that interesting file you found very carefully and make sure you know what each line does.

you mean at nā€¦o folder?

Type your comment> @protei300 said:

Type your comment> @idomino said:

thank you for the nudge, and now I feel stupid.
user hint: read that interesting file you found very carefully and make sure you know what each line does.

you mean at nā€¦o folder?

yeah

Rooted ! :slight_smile:

root@traverxec:~# ls
nostromo_1.9.6-1.deb  root.txt
root@traverxec:~# 

Rooted!

Root is really simple.

Hint: Just look at the file you will find as userā€¦and you may see a very suspicious command.

Still cannot see anything under restricted shell

Correct me, if i am wrong, but smth interesting in hā€¦f file???

Type your comment> @MasterSplinter said:

Donā€™t get too much stuck on the creds you find, look for ā€œbetterā€.
Currently stuck on root, Iā€™m pretty sure it has to do with all those logs but not sure how.

iā€™m stuck on root too, i think iā€™ll need to symplink stuff with other stuff to get the job donn

ok, that was straightforward :slight_smile:

# id
uid=0(root) gid=0(root) groups=0(root)