Root was quite easy if you know how the thing works but I donāt get the full screen reference, maybe I did it in a different way.
User was a bit tricky at first because I was barking at the wrong tree, but than I knew that something was there, so I followed the white rabbit to get there. Also I didnāt use the creds, so there must be two ways in. Letās have a look.
Initial foothold: too much easy
User: donāt try to bruteforce the pass, bruteforce the key
Root: Simple but trickyā¦ one advice: when you read gtfobins, the most important part is the first line, where it talks about a very small editor.
And also, donāt try to get root with terminal in full screen.
Youāll thank me later
Hints:-
User : Enumerate, Read code,get the file and you know what to do with it
And stay away from rabbit holes dont get excited after cracking a credential
Root: GTFOBINS, Read manual and well somethings work when things are smaller.
Everything is right in front of you,open folders,read codes.
if the creds dont work on ssh, there is another option. you should find something in a folder where you can not see anything. maybe the config could help you out?
Howdy all, I have the password for user d, Iāve read nā¦f and I looked at the docs and found something interesting. Iām in /hā¦s and getting a Permission denied error for what Iām trying to touch. Any tips?
Quite straightforward step by step. Thanks. Still took me 2h, spent way too much time enumerating on initial shell. Got initial shell in like 1min. then spent like an hour and a half before i read the whole file with thought. Then it was just doing.
User: Think logically, hard to explain what I mean by this without spoiling. Once youāve read the file everyone is talking about, go back to the home dir, what permissions exist? Something is odd. How can you be in another directory but canāt view contents ? Mess around in there and refer back to the āfileā and keep thinking and experimenting is all I can say. Even this is probs going to be removed might be too much spoils
Root : IDK why people are saying to minimise the screen xD You can keep a full sized screen just understand what is going on exactly on that thing youāve found. Understand it phrase by phrase, command by command, the GTFObin reference will help you understand why people are emphasising the word āLESSā - and from there, keep doing more logical thinking and experiment, youāll get it. I got it by mistake ā ā ā ā it was a test run and ended up being the thing that worked