ServMon

1246730

Comments

  • This box has been such a headache for root, just so unstable.

  • Hello, the "PLUS PLUS" is intended, I found a way to privesc. Can anyone confirm please?

  • edited April 2020

    no bruteforce needed, stop it please.
    After ROOT please remove all changes before to go away

    no hints needed, this machine is really OSCP like. Read carefully all files you can get

    C:\Users\Administrator\Desktop>ipconfig | findstr IPv4
    IPv4 Address. . . . . . . . . . . : 10.10.10.184

    C:\Users\Administrator\Desktop>whoami
    nt authority\system

    foxlox
    feel free to ask to foxlox#1089 only on discord

  • I'm starting to feel like it's not brute forcing that's causing issues. I'm VIP, there's literally me and one other guy on this box and no web traffic that I can see. The Web UI is still trash.

    virtualgoth
    OSCP | Cert II IT

  • This is quite a straightforward machine which I would recommend to anyone preparing for OSCP. I got user but not root yet because the machine is just so unstable and unresponsive.

  • Machine is not unstable, you need to read ini++ file and all will be clear.

  • Type your comment> @foxlox said:

    Machine is not unstable, you need to read ini++ file and all will be clear.

    Is there a setting in the INI file that makes the WEB UI run like a piece of a crap or something?

    virtualgoth
    OSCP | Cert II IT

  • Type your comment> @StanleyJobson said:

    Type your comment> @foxlox said:

    Machine is not unstable, you need to read ini++ file and all will be clear.

    Is there a setting in the INI file that makes the WEB UI run like a piece of a crap or something?

    If you mean UI not loaded properly, try a different browser. I had issues with firefox rendering it properly one time out of 20, but didn't have any issues with chromium.

  • Hm, I just reset the box and now it is working perfect even through Firefox. Not sure what was going on there..

    virtualgoth
    OSCP | Cert II IT

  • Hey can anyone help me i am getting 403 during login ?

    s1lv3rst4r

  • Okay, so got user. And yes, the box is unstable, had to try the same thing like 20-30 times to get the output.

  • stuck on the final step... not sure how to do this without the restart... could use a nudge can't find any documentation to work around it.

  • gave up with privesc. Obtained pass for ++ but unable to access the webpage...

    HootHoot

  • Type your comment> @HootHoot said:

    gave up with privesc. Obtained pass for ++ but unable to access the webpage...

    You're probably missing something there... why do you think you can't access it? What way could you change that?

  • edited April 2020

    Once access to that page, the CPU usage goes up dramatically.

    The last message I can get is 403 but the pw is extracted as stated.

    Gosh wt happened to the box?

    It turns out that I was lazy.

    CISSP
    Hack The Box
    ++Repect If you think I help =]

  • So, oddly enough, I had access to the page. I took a break, the server was reset (because of course it was) - I then proceeded to follow the exact same steps I took to set up the method of access to the Web UI, and it no longer works! As such, I am just not going to come back to this for a while, there's just too much crap that's unstable or doesn't work consistently and it's too frustrating to complete.

    virtualgoth
    OSCP | Cert II IT

  • edited April 2020

    Managed to get the login page after many tries. Does in fact work better in chrome.

    badge

  • I am not getting any login forms its very buggy

    s1lv3rst4r

  • Rooted. Easy box but very unstable especially during priv esc part.

    alt text

  • can somone hints me for foothold please??

  • Hi guys, I have found 2 users and vulnerability enables to search through files but I couldnt find any credentials. Any hints?

  • is it me or is the access page loading very slow ?

  • Struggling to get a script to run.
    Could someone PM me about this.
    I know I don't need to restart to get it up.
    It's just if I call on it all I get are errors about commands I can run blah blah.

  • Type your comment> @PrivacyMonk3y said:

    Struggling to get a script to run.
    Could someone PM me about this.
    I know I don't need to restart to get it up.
    It's just if I call on it all I get are errors about commands I can run blah blah.

    I am also in the same situation bro

    Ja4V8s28Ck
    Nothing is an Accident, It's Just a part of Destiny

  • edited April 2020

    Sorry to the creator, but this box is definitively the worse box I've ever done on HackTheBox, it could be interesting if the final web application wasn't that much unstable even in VIP.

    Really bad choice.

    I don't know if it can help, but don't use FireFox or FireFox forks for Web Panel, use something based on Blink/webkit instead (Chrome / Opera etc...) it seems to be less prone to errors...

    OSCP, OSWP, GCIH, CEH, Security+, VHL Advanced+

    https://www.phrozen.io/

    Hack The Box

  • Dude i can't even load the login page It's freaking

    s1lv3rst4r

  • Trying to access the web UI, all I get is connection was reset.

  • It is horrible with the performance of this box :smile:

    I have followed the steps of exploitation but no rev.shell...

  • Can anyone PM me about the t****l setup? I keep getting a 403 on the webapp even when it seems to work.

  • Type your comment> @roelvb said:

    It is horrible with the performance of this box :smile:

    I have followed the steps of exploitation but no rev.shell...

    HIFI broo

    Ja4V8s28Ck
    Nothing is an Accident, It's Just a part of Destiny

Sign In to comment.