Magic

Rooted Finally! Big thanks to @TazWake and @roumy for helping in the final step! Feel free to ping for any help!

Anyone had this error when trying to SSH @10.10.10.185: Permission denied (publickey).

@wooly13 said:

Anyone had this error when trying to SSH @10.10.10.185: Permission denied (publickey).

Looking at it, it seems to imply you haven’t used the correct public key to correct and key based authentication is enforced.

Type your comment> @wooly13 said:

Anyone had this error when trying to SSH @10.10.10.185: Permission denied (publickey).

That’s not an error (if you don’t have your key on this machine already). Try another way to log in.

Just rooted. It was a really good and fun one. It wasn’t hard, but I’ve learned a bit, and spent lots of time in a rabbit hole.

Rooted finally,

Nice box!

Initial foothold:
1- “bypass login page”
2- trick the system

User:
enumerate files, try to login and export data

Root:
Interesting file, how can you execute the commands in another context?

Finally rooted this sucker!

Hint for root : If you can’t find the right path, create your own path with necessary ingredients and then you get shell shelll shell… :wink:

Learned a lot. Thanks @TazWake @FunkyMcBeef and @disastrpc for nudges.

PM me if you need any nudges.

I got the user flag but trying to use the same python script method to get root. seemed like my NC listener not responding. Appreciate if anyone can provide some hints?? thanks

Type your comment> @idonthack said:

Anyone for a nudge?

What is your doubt? PM me, if you want some help

So its been two days i am stuck at root. I read the comments but cant figure it out. I think i never seen this method or i am having a bad time with this machine. Any nudge? :slight_smile:

I figured out! Thanks everyone for there comments.

I was stuck on creating the ■■■■ thing one way and the simplest way worked

I’m stuck at user. Dunno how to play with upload. Please DM me.

Rooted! Feel free to DM me if you need a hint :wink:

I need a small nudge on user. I used enum tools but nothing interesting spotted. Can’t drop my keys anyhow.


NVM - just got user thanks to @xOkami

I’m stuck on root. I’d be gratefull for a nudge.

@Nism0 said:

I’m stuck on root. I’d be gratefull for a nudge.

Enumerate what you can do and then see if there is a road you can change to your advantage.

Great machine!! Took me half a day to finish this. Thanks @TRX for this challenge.

I am glad you guys liked Magic! :smiley:

Owned. Finally. Thx @TRX for greate learning experiance and thanks @TazWake for hint.

ROOTED!

I love this kind of box and this one in particular make me learn something new! Here some hints:

Foothold: do you know an image can hide a lot of information? Maybe you just need the right tool.
User: just look around and you’ll find the first juicy information, that information can be used only in one way so let’s do it.
Root: know how Linux prioritize commands execution is the key, then I suggest you to use some tools like pspy and strings to better understand what’s happening.

Feel free to PM if you need help!

achille