ServMon

why restarting the machine for exploit again and again. what are you up toā€¦ it will restore to the snapshot. I bored for the part root. i ll do it later when the guys sleep who do the exploit exp. lines one by one and keep resets the machine.

Im on root, I am trying to follow the steps of a certain exploit but the box is crazy slow at the moment. Can someone give me a message so i can make sure im on the right track. I am trying to get around the 403 error and its difficult to know if my setup is wrong or the box is not responding.

Just wanted to share a message:
10.10.14.23 : Stop reseting that box plz.

LOL think hard would a reset be the solution on a shared boxā€¦i think that would be an easy one to pick up on

Easy, free server is nightmare for root, its easy and obvious will root it later

Rooted.

Hints:
For user: just enumerate, enumerate and then enumerate some more. Because enumerating will also put you in the path to root.

For Root: It is easier than what you found online. Just look at a certain file you found. Understand how it works, and then using the gui/webapp will make much more sense.

Oh, in this case, in the battle between Mozilla and Google, the blue icon wins :wink:

Happy to assist if needed.

Got user, will share hints offline. Donā€™t ask about root though, Iā€™m at a loss there!

Finally rooted. A very nice box, straight forward. The only down side is that it is quite unstable. I couldnā€™t do it the day it came out as the box was getting hammered.
Also somebody was changing my b## file

I got user.txt hash, for Nad*** but site wont accept it ?
Is it aiming for user key of Nat*** ?

Directory of C:\Users\Nad***\Desktop

08/04/2020 22:28 .
08/04/2020 22:28 ā€¦
14/01/2020 19:08 32 user.txt

if not meant to be this, then why user.txt ??

Type your comment> @kurutta said:

Type your comment> @olsv said:

Type your comment> @kurutta said:

Hey, i got the cve for User, just struggling on how to use it, anyone available for a quick nudge?

you have text file laying somewhere in the well known structure . do the math

yep, i was pretty certain i had the right path, but i just get document not found whenever i run anything

Iā€™m in the same situation as you

finally rooted. The root is real Patience test. Thanks @D3vil01 For root helpā€¦

Type your comment> @GibParadox said:

For Root: It is easier than what you found online. Just look at a certain file you found. Understand how it works, and then using the gui/webapp will make much more sense.

Oh, in this case, in the battle between Mozilla and Google, the blue icon wins :wink:

Happy to assist if needed.

Canā€™t get it to work, and the service keeps crashing, plus all the resetsā€¦
I guess Iā€™ll try again down the week.

I found w**.ini but Iā€™m not entirely sure how to use that information or where to go from here. Drawing a blankā€¦

Box is easy, but the root part is exceedingly painful. The best tips I can give are:

  • Use Google Chrome (Not chromium or firefox)
  • Donā€™t overthink the ā€˜accessā€™
  • Donā€™t rely on what youā€™ve found completely (itā€™s not written very well)

Type your comment> @obi0ne said:

I got user.txt hash, for Nad*** but site wont accept it ?
Is it aiming for user key of Nat*** ?

Directory of C:\Users\Nad***\Desktop

08/04/2020 22:28 .
08/04/2020 22:28 ā€¦
14/01/2020 19:08 32 user.txt

if not meant to be this, then why user.txt ??

Some one is probably being silly again, I had the same, the key changed three times had to reset and get it quick, probably best to come back for it later.

Type your comment> @Fidget said:

Type your comment> @obi0ne said:

I got user.txt hash, for Nad*** but site wont accept it ?
Is it aiming for user key of Nat*** ?

Directory of C:\Users\Nad***\Desktop

08/04/2020 22:28 .
08/04/2020 22:28 ā€¦
14/01/2020 19:08 32 user.txt

if not meant to be this, then why user.txt ??

Some one is probably being silly again, I had the same, the key changed three times had to reset and get it quick, probably best to come back for it later.

you are right, reset the box, now hash accepted.

Is Pass***s.txt where the file says it is? I canā€™t retrieve it using the LFā€¦ Iā€™ve reset the box and tried imediately after, still no luck.

Type your comment> @Mapperist said:

I found w**.ini but Iā€™m not entirely sure how to use that information or where to go from here. Drawing a blankā€¦

Oh, thatā€™s just how to test the PoC.
Think about what would be helpful to read instead of that file

@Lycist said:
Is Pass***s.txt where the file says it is? I canā€™t retrieve it using the LFā€¦ Iā€™ve reset the box and tried imediately after, still no luck.

It is where the clues say it is

Type your comment