Finally user and root. The biggest problem with this machine is the noise caused by other testers :(. I spent like an hour trying to exploit a /shell.php thinking that this was the backdoor…
Rooted, nice and easy. Didn’t get a shell - no need. Always open to help, as per usual
Type your comment> @TazWake said:
@Thanos17 said:
when trying to SSH to 10.10.10.181 I am getting a password prompt. I didn’t configure any password while regenerating the ssh keys . Does anyone getting the same message , for a password prompt ?
If it is a password prompt from the server, your keys have been overwritten by someone else or haven’t been installed correctly.
If its a password to unlock the key, then either you messed up and did set a password or something really weird is going on.
If you are using key based authentication (and I assume you’ve used
-i
correctly), the only password requests come from your machine, not the server.
TazWake thanks I will remove all the existing keys and regenerate !!
PLEASE STOP RESETTING THE F*** MACHINE
PM me for help on this one i enjoyed it, finished doing my re write this morning
Could someone help me on this?
- I initially did OSINT and used the forum to Internetzzz the webpage and able to login.
- I checked that a programming language should be used which I had no idea but managed to get it from the history.
- Now as defined by sudo -l, I tried to swich user and run the command sudo -* s*** /home/sysadmin/luvit *.lua
- I performed the above command through the console of the backdoor
I don’t see anything after that.
Please help me here to move further
@PChan said:
Please help me here to move further
There are a few ways you can do this. You can either create a script in the language which does things to grant you access or you can get the fck out of the shell.
Type your comment> @TazWake said:
@PChan said:
Please help me here to move further
There are a few ways you can do this. You can either create a script in the language which does things to grant you access or you can get the fck out of the shell.
I stayed and did it. Thank you
Rooted, thanks for this machine. I don’t really understand the moaning about resets, didn’t disturb me at all. Foothold was quite unique, user was rather simple, a lot of useful hints on the forum. Root was a lot of fun, timing is important but I managed to get it on the first try.
Wasted a lot of time on not setting the correct permissions on a specific file. Nice machine learned a lot.
ROOTED!
Type your comment> @squirrelpizza said:
So far I found the 2 ports open after doing an all ports scan. Directory busting got me nothing, I saw the clue on the web server. But I do not see anywhere to upload the web shell. Can someone give me a nudge as how to get to a spot to upload?
Did you get where to upload?
Rooted, finally…after sooooooooo many attempts.
Hint, don’t overthink it…(like I did for the last 4 hours).
thanks Xh4h, great box! it was a pain that sometimes it would crash after getting first shell but learned a thing about ssh and a new programming language
pm for hints. pleased to help!
Hi guys, i need help with this machine.
i am trying to connect with SSH but get an error message of “access denied, please try later” i do not want to write all steps here because maybe other people did not reach this step yet… but any suggestions? i gave the right permissions to the relevant files, edited the sshd.config as needed and still get the same error.
any suggestions?
Already spawned a shell…Now having trouble escalating privileges…any hints??
@RomeosCyber there is a way of escalating using certain files in certain folders within your initial shell
@Karthik0x00 said:
Type your comment> @squirrelpizza said:So far I found the 2 ports open after doing an all ports scan. Directory busting got me nothing, I saw the clue on the web server. But I do not see anywhere to upload the web shell. Can someone give me a nudge as how to get to a spot to upload?
Did you get where to upload?
you found the hint have you tried looking up that hint?
@> @callmevader said:
@Karthik0x00 said:
Type your comment> @squirrelpizza said:So far I found the 2 ports open after doing an all ports scan. Directory busting got me nothing, I saw the clue on the web server. But I do not see anywhere to upload the web shell. Can someone give me a nudge as how to get to a spot to upload?
Did you get where to upload?
you found the hint have you tried looking up that hint?
yeah
i already have the sn and wn ssh shells, still struggling with priv esc
so what can you find in their directories?