Magic

It’s a Nice Machine. The root part is new. I enjoyed.

what a fun box!

All the hints are here already, but for beginners (like me), you might not realise what the hint is for until you’re actually staring it in the face. The way to root was one of those, “there’s no way this’ll wor…omgosh it worked!!!” moments. :slight_smile:

Root! :blush:

Thanks to @robertwhite98, @Matbe34 who helped out in a moment of confusion!

Rooted.
Very nice box, pm for nudges. :smiley:

Great box. Enjoyable and relatively easy for those familiar with standard concepts. The root priv-esc is one of those; you’re either familiar with it or you’re not, but it is very simple cyber-101 stuff and, for those not familiar, the hints on here are discreet enough to aid you if you look at them carefully. Thanks to @TRX for a solid machine.

yay! rooted!

Enough tips in this thread… very simple once you spot the right file

Great box for me, especially since I am starting, I have learned a lot.

I’ve got user 3 days ago but cannot take root… wtf? can anyone help me, please? I’m totally stuck. Thank you.

@IvanGlinkin said:

I’ve got user 3 days ago but cannot take root… wtf? can anyone help me, please? I’m totally stuck. Thank you.

Find a file which might be useful, look at what it is doing and then exploit the road it takes.

can someone help on how to get user i am as www-data i have some creds from d*.**p5
but then i am stuck

Can someone give me a little nudge for the initial foothole?
From what I’ve read it’s simple, but I have know clue what to do.
I found ln.php and u*d.php but I only can interact with first.

@mava said:

Can someone give me a little nudge for the initial foothole?
From what I’ve read it’s simple, but I have know clue what to do.
I found ln.php and u*d.php but I only can interact with first.

If you google for what you are trying to do, there is a post which should be one of the first results and is full of useful information.

Other than that try uploading various things to confirm what is and isn’t allowed.

@xenofon said:

can someone help on how to get user i am as www-data i have some creds from d*.**p5
but then i am stuck

Try dumping to see if anything useful comes out.

i have uploaded my image but I get a Page not Repsonsive Error when I go to the image

Tried what I thought the box name suggests but didnt work, can I have a little help? DM

@inc0gnit0 said:

i have uploaded my image but I get a Page not Repsonsive Error when I go to the image

If it is a legitimate image, the box might have a problem.

If it is an attack, either your attack hasn’t worked or it needs to be executed in a different manner.

For example, command shells which rely on a GET request need to be requested with a command otherwise it doesn’t really know what to do.

@H0ru5 said:

Tried what I thought the box name suggests but didnt work, can I have a little help? DM

If you google what you are trying to do, the answer is in one of the first hits.

Rooted, fun box, its a great feeling to use magic, pm for nudges.

Great box. After the disgusting ServMon, it is like a breath of fresh mountain air. As usual, if you are stuck - write to me in PM.

Rooted. The foothold was very easy, user needs a bit of enumeration, and then direct way to root…

Awesome box, thanks a lot @TRX !

Pm me if stuck.