Official Agile Discussion

Rooted … Fun Box, the root was epic and fresh!

You need to edit /etc/host to include the ip and url

1 Like

Hi, I’ve gotten the user flag, but to get to the page that contains the ssh credentials , I had to manually try every number starting from 0. Is there a tool that could automate this? I tried wfuzz, but it gave me 302 for everything. Maybe BurpSuite?

so I was able to get the User flag but I have no clue what I should be doing next (any hint would be great)

I don’t understand why the machine keep blocking. Every 1 or 2 minute even if I’m inside with SSH session the session freeze or crash… Why is that?

Very hard to work like that. I even reset the machine, nothing changed. Am I the only one facing this problem?

PS: I’m using linpeas.sh but somehow the result change everytime i execute it… This machine driving me crazy

Intruder or ffuf would help you

1 Like

Did it yesterday, it was very cool ! Foothold and user was pretty easy, final PE was unexpected ! There is a lot of things to do, but nothing very hard, I would say max Medium :slight_smile:

Hi everyone,

Is anyone willing to teach me a thing or two about this machine or maybe give me a push in the right direction? I dont want to spoil anything, i can give you my thoughts and findings so far, in a dm.

Ive also gotten up to LFI now Im stuck

I’ve also gotten up to LFI, now I’m stuck

Rooted! Ty to @Paradise_R for letting me know I was chasing down a rabbithole on foothold. Rest of the box wasn’t too bad and root was pretty cool and hadn’t seen that before. Feel free to reach out for hints but let me know what you’ve tried!

1 Like

Any PM would be appreciated I am unsure what I should do next…

How did u find LFI?

Try exporting some passwords and use Burp to intercept.

This is a good resource for general LFI exploitation. But as Paradise_R said, look for the error log.

thank u so much ,u made my day

I tried to fuzz the box with all default kali wordlists and I can’t find any directory or file since yesterday. Has anyone an advice or a special wordlist recommandation ? Thx

Pls need a hint which is to be foothold for me please,
give a proper hint but i am stuck with the login page

Can i get help with getting foothold
ive just got secret, but everytime i create the changed cookie i can’t even use it

Rooted! Thanks @cmoon for the point in the right direction. Anyone stuck, feel free to send me a PM :slight_smile:

1 Like