Can anyone give me a nudge or check my k*e ec code, pretty sure I am super close to root but getting no input file specified, and whenever I actually get one working nothing is returned in the shell I have. Must be missing something very small here.
Nevermind, used a different exploit to get a more stable shell and k*e ec code worked perfectly fine. Guess I just needed to try a different approach.
Box rooted and was actually quite fun for an easy box.
Fun and easy. I read about the incident by the time it occurred so I quickly spotted the vuln as soon as I saw the software version. Root was even easier. Just use a subcommand and run a command to get your root shell
Has Anyone else had the 408 request timeout issue on gaining the foothold? I know I’m doing it correctly, I just don’t know what is going on with the timing.
Rooted. Feel free to hit me up if you need a nudge.
My biggest hurdle for foothold (like many others have said) was not using a tool which gives more info about what services are running on the server during the initial enum phase.
The biggest hurdle to root was the dumb shell I had access to once inside. It was obvious what I needed to do to get root, however my shell didn’t quite… cut it.
What methods did others use to upgrade their shells?
I have run Nmap against it and I know the web server version. I google that version but I didn’t find anything that helps. Am I on the right track? Or somebody could give a some hint on getting a foothold on this machine. Thank you.
Fun little box. Echo what @7ailwind said about nmap. That’s usually my goto. Another scanner provided the key piece of info on this. After that, a quick Google search gives you what you need.
root was fairly straightforward. PM me for a nudge.
Just got user on this - Not sure whether the Chinese clue is right, didn’t come across any myself. However, definitely worth reading the scanning tool output fully. One bit might stand out and it’s worth a Google!
Mine sat doing nothing for a little, while exploiting, so don’t give up too quickly!