Celestial hint

@xplo8 said:
having issues figuring out how to serialize the payload. Anyone have a non spoiling tip?

yes, follow that article AND RESET THE BOX

Please help i’m already inside the box. Need some tips for priv esc

@halfluke said:

@xplo8 said:
having issues figuring out how to serialize the payload. Anyone have a non spoiling tip?

yes, follow that article AND RESET THE BOX

Thanks half fluke !

@anikka said:
Please help i’m already inside the box. Need some tips for priv esc

Spoiler Removed - Arrexel

@ice3man said:

@anikka said:
Please help i’m already inside the box. Need some tips for priv esc

Spoiler Removed - Arrexel

Got it :slight_smile: Thanks!

Yeah, I’m a bit suck on this one for priv esc. Tried LinEnum.sh and looked at existing files in the user’s dir. I’m a bit lost and I feel like its so simple but I’m totally missing it

Check the http header, just goole it.

CyDefUnicorn , look for what is odd in the user’s home directory and figure out how it got there :slight_smile:

@ice3man said:

@anikka said:
Please help i’m already inside the box. Need some tips for priv esc

this is the hard way , there is much easier way without priv esc

@Th3R0ck said:
CyDefUnicorn , look for what is odd in the user’s home directory and figure out how it got there :slight_smile:

I see what’s odd, I think, a text file

nvm, figured it out, took me a bit till I noticed the constant time change

done!

can someone PM me pls, i’m stuck. tks

up

Hi there guys, well, another one bites the dust… Easy to p0wn, as with “Poison”. As for the priv esc, it kinds of reminds me of another box I hacked into some months ago. It’s a matter of looking around, seeing what’s odd and then have like 5 minutes of patience…

Hey Guys, I am inside the home directory but I cannot see any users.txt file… Do I have to search for it in the subdirectories too?

Nerver mind, I have found it :wink:

Spoiler Removed - Arrexel

Also stuck payload if anyones around to assist PM me

@shaunak said:
Spoiler Removed - Arrexel

I do not think the payload in the article works as it is… need to edit it a little :slight_smile: