@dragonista no not every box is like this. For root, its just a watch, grab and crack …pretty disappointing
Overall
foothold…well that was funny. I liked the beginning
User hat from my point of view nothing to do with reality. It was more like a riddle…extremely ctf style and really frustrating
Well, root was OK, at least not the typical gtfo bin usage ^^
manage to get user the old fashioned way…never managed to solve the crypto…I would really appreciate if someone could send me a PM to explain to me on how to solve it the crypto
manage to get user the old fashioned way…never managed to solve the crypto…I would really appreciate if someone could send me a PM to explain to me on how to solve it the crypto
O M G
I’ve been running on this thing for 3 days and finally rooted.
The hardest part for me was the user and I ended up writing my own code for reversing (read here somewhere that this is not necessary but I’m not sure how).
For root - I wrote some more bad to “steal” the output before it’s gone, and then I used Mr. J to help. Really hope this was the intended way.
Tips:
Foothold - pay close attention to the notes left on the landing page. I didn’t use dirb or anything of that sort… it’s pretty straight forward.
User - well, I’ll repeat someone above with a bit more context: you have f(x)*k = t you have t and f(x). Now you have to reverse the math…
Root - You can do stuff when someone else’s code is asleep
Also, regarding foothold and this box - it very much lives up to its name!!!
All this obscurity led me to chasing ghosts of LFI for hours. Took all that time to figure out is impossible with most file extensions.
Another thingy - did anyone get a shell before the user? is that even possible? I tried for hours and gave up.