Hint for TartarSauce!

As much as I hated this for the time it took, the clock watching element is probably pretty realistic :slight_smile: Good lab to learn, and work fast :+1:

That machine taught me a lot.
Specialy getting a root shellā€¦ Awesome.

Getting shell was not too realistic, changing some info to confuse scanners is something clever but strange. Getting root was fun, had a chance to practise python skills.

can someone pm me for initial steps ?

CAn someone PM for final priv esc, so close yet so far

nvm root

Very nice machine. Root was very interesting. Thanks to @wirepigeon for hint

Any hints on initial foot hold for user.txt

I found two web-services the first MONSTER doesnt let me do anything the other one which has WORDS that are PRESSED onto the screen has some funky redirecting going on but i cant login to that serviceā€¦ am i missing something?

why the ā– ā– ā– ā–  is integrity check not working for me? I manually changed a file in web dir to create a difference but when I run that binary, no comparison is found :frowning:
Difference was detected only once in like 1000 tries and this just doesnā€™t make any sense. I kept repeating same process, files are different but still it isnā€™t detecting :confused:
What am I doing wrong here?

nvm got the root flag without shell
This machine reminds me exactly of an OSCP exam machine. Just keep enumerating till end. I am happy that I didnā€™t stop enumeration during exam.
Priv esc is so much mind f***

Would be grateful if anyone could DM me with a hint on how to proceed (even reference to reading material). I have identified the the 2 apps and I am currently enumerating the no to obvious one. But seems I am not heading anywhere

@smit2300 said:
Rooted! Wow that was a tough priv esc but so cleverly put together! Mad props to the makers even if @3mrgnc3 is an absolute troll lol. PM me if anyone needs a hint at any stage of the box.

??

1 week out from OSCP retest & would love some privesc pointers, not spoilers
Got O* shell; might understand retartar (grp) but canā€™t find diff/script talked. found 3 diff files but at a lossā€¦

Hey guys please PM me I need help on this box Iā€™ve been trying to get user for like 2 weeks now

@imag1ne said:
1 week out from OSCP retest & would love some privesc pointers, not spoilers
Got O* shell; might understand retartar (grp) but canā€™t find diff/script talked. found 3 diff files but at a lossā€¦

do enumeration steps as taught in oscpā€¦
try not to follow advice in the forums. There are many many wrong suggestions in here.

Do your own enum and you will find it.

Good luck :wink:

lol, I know right? I actually found a script via enumeration but didnā€™t realize it, just not sure what to do with it.
My first guess was a local service I enumā€™d, (very OSCP) but couldnā€™t figure out the password to access.

Completely lostā€¦ Iā€™ve done an extensive amount of enumeration and still canā€™t find the initial foothold. Any help via pm would be greatly appreciated.

Would anyone please PM me about privesc process? Iā€™ve found the script, but canā€™t write to it. I tried linking the root file in order to break the certain process. Iā€™ve tried a metric ā– ā– ā– ā– -ton of stuff and no of it has worked. Any assistance would be appreciated.

EDIT: This box privesc is all about timing. Finally got it.

Troll machineā€¦ :slight_smile:

@3mrgnc3 I love the image that you have created :slight_smile:

Curse the day I decided ā€œlooks pretty doableā€. Iā€™m in the same boat as @Rayvenhawk and could use some help. Might not survive the night if I canā€™t get a hint thatā€™s not trolling me.

Trolls everywhere, send backup. Over.