The initial foothold is what everyone does, don’t make it complicated. Just do those tests when you see a form.
User:
Look at pages source codes. You find something which you can use it to go further and get the user.
Root:
The enumeration part is easy. but you may need a little nudge to get the root.
other users already talked about the tools.
All in all, it is not a good idea to work on this box after Quick box , you make think complex.
Let me know if you need any help.