LaCasaDePapel

hey guys,
i have generated my .c** using the server’s c*.*** and .c** then converted it to .**2, i have double check both details and both are as close as each other’s, imported it, yet it giving me the same certificate error

can anyone help please !!

@anonymous187 said:
hey guys,
i have generated my .c** using the server’s c*.*** and .c** then converted it to .**2, i have double check both details and both are as close as each other’s, imported it, yet it giving me the same certificate error

can anyone help please !!

NEVERMIND!! had to refresh stuff

I just found a way for user. need some help, can anyone hint what is username for this machine? like after /home , under what name is user flag?

Im on VIP server and my nmap scan has gave up on a port and is 70% through after 14mins…

Is that normal for this box? surely not

Finally able to get root :slight_smile: thanks to @chrisx87 and @AzAxIaL .

Root! Was a long trip.

Thanks @amra13579

Type your comment> @blink3r said:

Finally rooted!
Nice box, learnt a lot on SSL client server certificate mechanisms.
My two cents are the following.

Initial foothold
Opened services are there for something… so focus on what you can grab from each service and find an old open door.

User
Once you find the old door, you are invited to play with OpenSSL…so give it a try. Once you managed to correctly authenticate yourself…basic hacking and user is yours.

Root
Just tell the machine to do what you would like her to do.

Cheers!

thats the worst hint i have ever read in the entire forum.
I dont understand why people write these comments here anyways.

Anyone else have trouble getting p**y running on this box? I’ve got an ssh shell but nothing happens when I run the script. Is this a limitation of ssh? A busybox thing?

managed to nab id_*** via LFI under the user b****, I figured I’d be able to get past the password auth when trying to connect using s** with this file, but no matter what I do, I can’t seem to get around it? i’ve tried to chmod 600 id_*** but no dice

Hey guys, please could someone drop me some advice on where to go after $t******. I imagine it requires me to make an S** cert but i’m not really sure how i’m going to do this on a p** shell

Type your comment> @austin69 said:

managed to nab id_*** via LFI under the user b****, I figured I’d be able to get past the password auth when trying to connect using s** with this file, but no matter what I do, I can’t seem to get around it? i’ve tried to chmod 600 id_*** but no dice

Maybe it is not meant for the same user you are talking about!!??!!??

Rooted. Fun box and a learnt a few things. Thanks to @ghost0437 for a nudge.

Rooted.
hit me up if you need help or hint

Hack The Box

Type your comment> @austin69 said:

managed to nab id_*** via LFI under the user b****, I figured I’d be able to get past the password auth when trying to connect using s** with this file, but no matter what I do, I can’t seem to get around it? i’ve tried to chmod 600 id_*** but no dice

PM me

Type your comment> @Rainerd said:

@Rainerd said:
Hey guys, please could someone drop me some advice on where to go after $t******. I imagine it requires me to make an S** cert but i’m not really sure how i’m going to do this on a p** shell

PM me

Hello all.
I have managed to get into the machine using the “old” door and managed to find the pr***e k** on the c k** file, however the certificate that I have generated seems to not work and I am still getting the certificate error. Apparently, I must be missing something.
Any hints if there is anything else that I should have taken into account? :slight_smile:
Thanks in advance.

Type your comment> @Arrow said:

Hello all.
I have managed to get into the machine using the “old” door and managed to find the pr***e k** on the c k** file, however the certificate that I have generated seems to not work and I am still getting the certificate error. Apparently, I must be missing something.
Any hints if there is anything else that I should have taken into account? :slight_smile:
Thanks in advance.

PMed you

Hello! After many attempts to pass the certificate check I’m definitely stuck with this… I retrieved the c*.*** file and attempted the procedure both on my machine and remotely, both using the server ce*******te and starting from scratch. Is there anyone available to help me review my process and understand where and why I’m doing something wrong? Thank you very much!

@concrete said:
Hello! After many attempts to pass the certificate check I’m definitely stuck with this… I retrieved the c*.*** file and attempted the procedure both on my machine and remotely, both using the server ce*******te and starting from scratch. Is there anyone available to help me review my process and understand where and why I’m doing something wrong? Thank you very much!

The same to me, stuck in https for a lone time, only have a stable shell without permission to execute any command.

I stuck on create ssl cert, any help?