Poison

First time enumerating I got the services a little down the way that i will not mention by name but now I cant seem to find them. If anyone has some advice or pointers, please feel free DM me.

Iā€™ve got the file from the zip and I know what service to use. I just canā€™t figure out what to do with the file. I tried to SSH using this service but always get rejected. Anyone a tip on this matter? Would really appreciate it!

@elyst said:
Iā€™ve got the file from the zip and I know what service to use. I just canā€™t figure out what to do with the file. I tried to SSH using this service but always get rejected. Anyone a tip on this matter? Would really appreciate it!

You have to analyze the whole sentence from enumerating the box. That should be a crucial key in helping you! Also, make sure you read and bear in mind the possible options that you will need to use in the future!

Stuck on priv esc as well. Figured out the service(s) that I need to take a look at. Canā€™t seem to find the link between them and the file though.

if somebody needs any help pm me

Got root. My advice for this box is to listen harder once you have a basic user. Feel free to PM me as well if you need any help

Sorry guys I canā€™t figured out to root this machineā€¦ I have secret extracted I know the service but Iā€™m stuckā€¦ Can I pm to someone for help?

Read this thread in full. It contains enough hints to get root.

Think about how the user uses this service. Then think how you can connect to that service. Draw it out if it helps.

Iā€™m completely angry on myself, because 2 days canā€™t figure out how this service works and what I need to do. Anybody, PM please! I need rooted it.

This was very cool. I did not know you can do this.

RTFM again and rooted! ^^

@cExplr said:

@elyst said:
Iā€™ve got the file from the zip and I know what service to use. I just canā€™t figure out what to do with the file. I tried to SSH using this service but always get rejected. Anyone a tip on this matter? Would really appreciate it!

You have to analyze the whole sentence from enumerating the box. That should be a crucial key in helping you! Also, make sure you read and bear in mind the possible options that you will need to use in the future!

Got it, Thanks! Your comment really inspired me.

Okay so Iā€™m connected via ssh and a Iā€™ve tried the LinEnum script.
I have also ā€œstrings secret.zipā€, I donā€™t know if the result contains a passwordā€¦
I have nmap and discovered some ports but ā€œFile not foundā€ā€¦ Can I have some hints pls?

if someone needs any help pm me

Anyone need hits (not answer), just PM me. :lol:

Iā€™m stuck. Anyone there to help me? PM me please

Got usr, and im able to get eyes on the machineā€¦ however still as usr. Any hint on how to get root. I did read the article provided in the hints but it doesnt get me much further

I think I owe it to the community here to offer my 2 cents

The first part is all about KISS

The second part is all about enumeration and ā€œDIGGINGā€ deeper

Research is crucial (or at least for me it was)

I hope this helps and not too much of a spoiler.

Just got root, can relax now :smiley:

How can I PM Charix (the creator of the box) in this forum? itā€™s urgent
EDIT: not so urgent, the box had an unintended way of getting root which was in some kind of history file

Can someone PM me, I need help with root, Unziped file, have xyz service password, know about ssh tunnel, but something doesnā€™t work