Official Backdoor Discussion

I did manage to get a rev shell at first try, no connection issues.

Hello everyone,
I managed to pwn user but now Iā€™m stuck, there no much hints for this privesc, can someone drop a small one?

Tryed sudo -l and suid/guid executables, nothing found :frowning:

There are some **** binaries which donā€™t have an exploit payload on gtf****, but there may still be ways to exploit them under some circumstances.

**edited because i wasnā€™t sure if i was giving too much information

Solved, thanks.
But htb does not accept my flag, it seems like something is not working, I canā€™t rejoin the machine

same for me, i think the machine is going from lab arena to ā€œnormalā€ at this timeā€¦

It works now but you have to replay the steps / shellcodes etc because of the ip and moreover, the flag changed !

Seems like when a user is using the ā€œbackdoorā€ no other user can connect (that --once flag :frowning: ), do you confirm?

1 Like

that is exactly what the --once flag does.

particular VM , interesting , new think

Smooth easy machines learn something new on the root part feel free to DM if you need nudge

2 Likes

ā€¦ and rooted :slight_smile:
There are enough hints so I donā€™t add ^^
Root was pretty straight forward, foothold also, but not so easy between foothold and user :wink:
PM if stucked

Found M**** credentials, but canā€™t figure on how i can use it to get the foothold. Any tips?

1 Like

you got the right start now looking for something else to get info about proc
The cred is useless
DM open :wink:

1 Like

I Managed to achieve user but Iā€™m completely stuck at getting root. Iā€™ve observed a certain ā€œuselessā€ operation being executed on the machine and I strongly believe itā€™s the main vector to getting root. However I do not seem to be able to exploit it; Iā€™ve also researched the topic online and this lead me to believe that such process can not be exploited the way it is builtā€¦ Am I missing something?

Edit: Done. For other people struggling with this last part, i have a couple of suggestions:

  1. Trust your guts. Thereā€™s a misconfiguration in place and you cannot completely check its nature before exploiting it.
  2. Be sure of using the right command.

Finally rooted this machine, as everyone agreed ā€œfrom initial foothold to userā€ is a pain for non-experts :frowning: :slight_smile: there are lots of good tips above so i will not add more. At root part, I have checked lots of spaces and spent lots of time to look previous service again and again, then i realized that, sometimes its not so hard, just read man pages or google it fluentlyā€¦ :open_mouth:

1 Like

This was a fun box. There were definitely some more challenging aspects, when considering this is an easy box. That being said, once you get past the hard part, its pretty straight forward.

Feel free to PM me for hints!

Great box!

Can someone message me a hint about the command for root? I think I understand whatā€™s happening but no dice.

I have managed to get upto user. Still got stuck to move forward from here.
Any tips ?

Can someone give me a hint? After enumerating the plug-ins, I donā€™t know the entry point.

Can anyone give me a hint? I have enumerated the plugins and checked all the files please tell.