ServMon

Got user, will share hints offline. Donā€™t ask about root though, Iā€™m at a loss there!

Finally rooted. A very nice box, straight forward. The only down side is that it is quite unstable. I couldnā€™t do it the day it came out as the box was getting hammered.
Also somebody was changing my b## file

I got user.txt hash, for Nad*** but site wont accept it ?
Is it aiming for user key of Nat*** ?

Directory of C:\Users\Nad***\Desktop

08/04/2020 22:28 .
08/04/2020 22:28 ā€¦
14/01/2020 19:08 32 user.txt

if not meant to be this, then why user.txt ??

Type your comment> @kurutta said:

Type your comment> @olsv said:

Type your comment> @kurutta said:

Hey, i got the cve for User, just struggling on how to use it, anyone available for a quick nudge?

you have text file laying somewhere in the well known structure . do the math

yep, i was pretty certain i had the right path, but i just get document not found whenever i run anything

Iā€™m in the same situation as you

finally rooted. The root is real Patience test. Thanks @D3vil01 For root helpā€¦

Type your comment> @GibParadox said:

For Root: It is easier than what you found online. Just look at a certain file you found. Understand how it works, and then using the gui/webapp will make much more sense.

Oh, in this case, in the battle between Mozilla and Google, the blue icon wins :wink:

Happy to assist if needed.

Canā€™t get it to work, and the service keeps crashing, plus all the resetsā€¦
I guess Iā€™ll try again down the week.

I found w**.ini but Iā€™m not entirely sure how to use that information or where to go from here. Drawing a blankā€¦

Box is easy, but the root part is exceedingly painful. The best tips I can give are:

  • Use Google Chrome (Not chromium or firefox)
  • Donā€™t overthink the ā€˜accessā€™
  • Donā€™t rely on what youā€™ve found completely (itā€™s not written very well)

Type your comment> @obi0ne said:

I got user.txt hash, for Nad*** but site wont accept it ?
Is it aiming for user key of Nat*** ?

Directory of C:\Users\Nad***\Desktop

08/04/2020 22:28 .
08/04/2020 22:28 ā€¦
14/01/2020 19:08 32 user.txt

if not meant to be this, then why user.txt ??

Some one is probably being silly again, I had the same, the key changed three times had to reset and get it quick, probably best to come back for it later.

Type your comment> @Fidget said:

Type your comment> @obi0ne said:

I got user.txt hash, for Nad*** but site wont accept it ?
Is it aiming for user key of Nat*** ?

Directory of C:\Users\Nad***\Desktop

08/04/2020 22:28 .
08/04/2020 22:28 ā€¦
14/01/2020 19:08 32 user.txt

if not meant to be this, then why user.txt ??

Some one is probably being silly again, I had the same, the key changed three times had to reset and get it quick, probably best to come back for it later.

you are right, reset the box, now hash accepted.

Is Pass***s.txt where the file says it is? I canā€™t retrieve it using the LFā€¦ Iā€™ve reset the box and tried imediately after, still no luck.

Type your comment> @Mapperist said:

I found w**.ini but Iā€™m not entirely sure how to use that information or where to go from here. Drawing a blankā€¦

Oh, thatā€™s just how to test the PoC.
Think about what would be helpful to read instead of that file

@Lycist said:
Is Pass***s.txt where the file says it is? I canā€™t retrieve it using the LFā€¦ Iā€™ve reset the box and tried imediately after, still no luck.

It is where the clues say it is

Type your comment

Hello all, im stuck at user, i got 2 .txt from the lowest service, i suppose there is the first step to know what user i need.
After that im stucked because all other services dont let me do anything ( i meain i dont know what to do with them)

Please give me some help, i need a little push to go ahead

Thanks to all, this is a really nice place to learn

Type your comment> @Mapperist said:

I found w**.ini but Iā€™m not entirely sure how to use that information or where to go from here. Drawing a blankā€¦

same

Type your comment> @japimil said:

Hello all, im stuck at user, i got 2 .txt from the lowest service, i suppose there is the first step to know what user i need.
After that im stucked because all other services dont let me do anything ( i meain i dont know what to do with them)

Please give me some help, i need a little push to go ahead

Thanks to all, this is a really nice place to learn

Ask searchsploit for help :wink:

Iā€™m stuck in the d******* *****l part which I can view some files, for example, w.i but I think it just PoC as I see someone just said in the forum also it basically doesnā€™t have much useful information inside and I found something like sym.i can even found the ns-***0.**e itself but I think its probably not the thing I need. I try to enumerate many ā€œusefulā€ files locations but it just keeps giving me tons of 404.

Hey everyone, I asked a few of you for nudges, and so far it has gotten me to the part where I use my browser and SSH. I keep getting a ā€œConnection was resetā€ error on firefox and a ā€œThis page isnot working, l****h**t didnā€™t send any data; ERR_EMPTY_RESPOSEā€ on a blink based browser as I saw recommended above. I have double checked my SSH statement with others but I cannot seem to proceed further. (I am using the Free version for now)

Is there a reason why i cannot even curl N*******++ locally, logged in as N*****? All i get is failed to connect. Also tunneling to port 80 works fine but when i switch to 8*** i get nothing. I saw some people had similar problems, was this a connection problem or am i missing something?