Traverxec

Thanks for the box! New and learning all I can! Got User and Root. No way I would have gotten Root without some of the hints here. I just spent forever reading the wrong manuals.

User: Not sure how it worked for others, but for me, the leap I needed actually came from reading the manual of common software that worked similarly to what I was attacking.

Root: This was a good review of the need to understand how options we might rarely use from commands we might use a lot can have serious security implications. Once you get it, it really does seem so simple.

Rooted, Big thanks @BugZ , @AzAxIaL , @kkbear for your help.
This box should be named magic or copperfield. The way we got into hidden folder or elevate priviledges to root looks like magic trick.
Learned something new about ssh

Finally got root. Felt super silly when I realized how close I was for awhile but missed one final step.

Type your comment> @casey said:

Type your comment> @stoffern said:

Can someone pm me how to crack creds. I know how to use them…

search for john or hashcat

thanks for the help and comments here

rooted just go small as you can for root part
now what’s the result of 40 * 5 ;D

I need some help for root.
I get back the same user shell when i do the G******s thing.

Finally figured out how to use John to crack the first password. Is it possible to break the other one?

Edit: Broke Both with John

i am new to htb. i got au*******_ys file and i***.p*b file but i am not getting a way to use it. can some one help ?

Hi,

i was trying to get user. i got the hidden stuff (the thing to crack and the thing required to crack). when i try to use op****l to crack it, keeps throwing errors. After playing around i was able to make it output, but the file comes in an incorrect format. Im usung 1.1.1 ver. Any nudges?

Could anyone pm me? just need that smaaaall nugde on the c*** file

I know what I’m supposed to do I just can’t seem to do it ■■■■

this was my first box on htb. got to learn a lot. Special thanks to @bumika and @kavishgr

Hi i need some help, can some one PM im stuck on priv escalation for user! cheers

Apparently I was overthinking same as everybody else

You can do the box just by reading all the forum posts, root was much easier than expected.

hmu if you need help

Could someone nudge me in the right direction for user? i have limited priv shell, unhashed creds and unsure of the significance of a certain conf file

Root took me ages to figure out, I guess it’s a well known trick, but if you don’t know it like I didn’t then you’ll spend a long time researching and trying to break the wrong bit of the command. The solution is very simple (no complex commands or guessing needed) and clearly a “must know” in the linux world.

Heya, im stuck at User privesc from www-data. I find some backup things with ssh creds any hinds? please PM me :slight_smile:

Another fun box. Spent way too much time trying to get root. Definitely just read and understand how to use GTFOBins.

Reach out to Valor in discord if you’re stuck.

Needing some help, I’ve tried a lot and followed several tips left in the forum, but I can’t identify what I’m doing wrong to be root.
I’ve used several GTFO commands.
Who can help, thank you.

root: simpler than it sounds.