Postman

fun box! there were definitely some red herrings. I also got root before user.

Based on what I am reading here…looks like there might be different paths to get to the loot. I felt kind of hamstrung during enumeration, so I’d definitely would be interested in knowing what some of you have done.

if you need help, feel free to ping me

user:
there is a lot of material on the internet (and hints on this forum) about what to do. There is a service that simply lets you waltz in. Through trial and error I found out where I could and could not write to. The local enumerate once you have a foothold.

root:
business as usual once I picked up versions of what’s running within as root and looked up exploits for it. i used some tool that I dont normally like using but it got the job done. I will actually retry this with something else as I feel there are other paths to root.