Traceback

Just rooted the box! User was quite fun and easy. Root was challenging for me, but thanks to some nudges from @ChefByzen I was finally able to get root! Learned a lot of new things doing this machine!

  • Foothold: Enumerate everything you see and don’t only rely on tools, but also follow some hints manually.
  • User: Once you’re on the machine, there’s a tool available on the machine that you might want to use. Hints for that can be found were you’ll probaly look anyway to own user.
  • Root: Enumerate the machine and try to understand the processes that run on it. Great tools for that have already been named here in the thread. Find a way to exploit these processes - to do that, you should find a way to go into the box from the front door, instead of the back door.

finally rooted, thanks a lot for pointing to the right direction @HomeSen !!! Nice box , root needs to play with the sleeping time for system

I just redid the machine after the patches and still so funny how everyone tries to upload his own rshell xD

little hint because a lot are stuck at the part with the new language:

you can use gtfo for more than only root…
… and if the first command doesnt work maybe you didn’t try hard enough!

So many people uploading shells, and deleting files. :smiley:

EDIT - Got user - cheers @h3105 . Working on root. :wink:

My tip for user… some processes don’t work so well running non-interactive

A short & enjoyable box. - Nice one Xh4H

Easy but funny box, thanks @Xh4H

Got root. Box needed to be reset as someone messed with the files again…

Cheers to @nyckelharpa for the pointers

got syin user, ran py , aware of 00-h*, and have no idea how yo advance from here.

need help pls :frowning:

Rooted, fun box !

Anyone can give me a hint on root privilege escalation?

I’m open and online atm if you need pointers.
PM me with where you are up to and we can chat!

Type your comment> @sakas4 said:

Type your comment> @Big7asty said:

@DrayAgha @sakas4
On the right path, sudo --help is all you need to get there.
Thank you @Ursa

I rly tried everything.

It doesnt work.
try sudo -l

Having how to own user change after coming back after a couple days break was SUPER annoying; I thought some asshole kept removing the necessary file after resets. So if you were working on this a few days back and are thinking people are deleting things, they might be, but they also may have moved things around on you.

Otherwise it was a fun box and I learned a good bit. Thanks!

Type your comment> @53c0nd2473 said:

Having how to own user change after coming back after a couple days break was SUPER annoying; I thought some asshole kept removing the necessary file after resets. So if you were working on this a few days back and are thinking people are deleting things, they might be, but they also may have moved things around on you.

Otherwise it was a fun box and I learned a good bit. Thanks!

Well this doesn‘t really matter. U actually always can see where this certain file is located, otherwise you wouldnt be able to run it as you do.

@h3105 said:

@53c0nd2473 said:
Having how to own user change after coming back after a couple days break was SUPER annoying; I thought some asshole kept removing the necessary file after resets. So if you were working on this a few days back and are thinking people are deleting things, they might be, but they also may have moved things around on you.

Otherwise it was a fun box and I learned a good bit. Thanks!

Well this doesn‘t really matter. U actually always can see where this certain file is located, otherwise you wouldnt be able to run it as you do.

Well, the problem is that, due to the constant resets, people tend to script their way through the initial foothold. And those scripts will now always fail :wink:

Rooted.
Great and fun box for beginners. Learn about two new things; a new programming language and how welcome messages are configured and being displayed when user logs into ssh service.

Just feel free to PM me if you get stuck and want some hints !!!
Happy to help :slight_smile:
Hack The Box

I hate this, people are resetting and removing stuff all the time, it is very anoyying, i literally can’t take 2 minutes to setup for something and I see that somebody removed the file that i uploaded. I can literally see the command from bash, holy s**t.

Rooted it yesterday. It was a fun and refreshing box :smile:.
If anyone need help on user or root, I’ll be happy to provide some tips!

rooted!! ok thanks again for eviltor13 for the clues!!!
okay now here here’s what i can say about the box and maybe some clue?
foothold: remember everything you see is the truth!
User:the things you see is also the truth! Try to look for it!
Root: again the answers is in front of you! Remember don’t overwrite it!
…ehem
And thanks again for eviltor13

Type your comment> @chiakheewei said:

Anyone can give me a hint on root privilege escalation?

The answere is in front of you! Just look for it!