Official Buff Discussion

I keep getting this error when I run the *****.py
[SSL: WRONG_VERSION_NUMBER] wrong version number (_ssl.c:727)

Root obtained, but the difficulty lied in the fact that a certain service never was actually running making exploiting it pretty damned hard.

Very unreliable box, a good intro for techniques but only ā€œdifficultā€ because of the above issues which are entirely out of our control.

Easy and nice machine. User indeed very easy with ā€œone-clickā€ exploit. Root also, after using correct tool (which is not picked up by dā€¦r) and payload for remote shell. A little bit of playing with pā€¦ts and voila. Quick and nice -:slight_smile:

when I use pli**.e**. I got FATAL ERROR : connection timeout. what is wrong with it? plz help

Getting the same Fatal Error for P***k. Iā€™ve tried turning off ufw, bouncing my machine, bouncing the HTB machine, restarting ssh service. Canā€™t reach my machine. Iā€™ve wasted hours on this.

@He11oW0r1d said:
when I use pli**.e**. I got FATAL ERROR : connection timeout. what is wrong with it? plz help

@ImpalpableOne said:
Getting the same Fatal Error for P***k. Iā€™ve tried turning off ufw, bouncing my machine, bouncing the HTB machine, restarting ssh service. Canā€™t reach my machine. Iā€™ve wasted hours on this.

I consistently had the same issue. Use ch***l instead, it worked first time for me. P***k never worked.

HI, finished the user step, but stuck on root. I found the vulnerable exe. The exeā€™s exploit uses port 8??? but its close on the machine. Any ideas?

Finally rooted!
Although it is indeed an easy machine, there are some delicated steps when rooting the machine.

Feel free to PM for nudges!

@n1tro said:

HI, finished the user step, but stuck on root. I found the vulnerable exe. The exeā€™s exploit uses port 8??? but its close on the machine. Any ideas?

You can make internal ports accessible to external systems.

Type your comment> @TazWake said:

@oohh said:

HI, finished the user step, but stuck on root. I found the vulnerable exe. The exeā€™s exploit uses port 8??? but its close on the machine. Any ideas?

You can make internal ports accessible to external systems.

The port was unavailable internally as well (used w****es to check). After a while they re-opened (maybe a reset to the machineā€¦).

stuck on root, Having issue with port forwarding. I keep getting this ā€˜FATAL ERROR: Network error: Connection timed outā€™ā€¦I had to purge and reinstall ssh still same result anyone experienced same issue?

@SuperRaptor said:

stuck on root, Having issue with port forwarding. I keep getting this ā€˜FATAL ERROR: Network error: Connection timed outā€™ā€¦I had to purge and reinstall ssh still same result anyone experienced same issue?

This wont help you, but lots of people have mentioned this exact issue today. It might be something broken on the box.

Windows is so different from linuxā€¦ very out of my comfort zone

The most frustrating box I have ever done lolā€¦ pl**k bend me over and f*cked me hard in my behind. For some reason I always experience a lot of trouble on machines where I need to ā€˜dig tunnelsā€™.

I downloaded every version of pl**k.exe, x64, x86 etc. nothing worked, kept getting ā€˜connection timed outā€™ error. Debugged everything, no results. Chisel worked immediately for me.

Also, other people were resetting the machine while I was working on it and crashing the service. Strangely the service was still listening and running even though the payload didnā€™t work. After a reset the exact same payload did work.

Lastly, big thank you to @TazWake, dudeā€™s a f*cking legend and has saved me a migraine.

@SuperRaptor Save yourself the trouble and use Ch***l instead, I couldnā€™t get it to work either.

I am looking forward to the writeups when this box retires. The issues around the privesc step make it interesting to see how other people resolve it.

I genuinely have no idea why some people are getting a complete block with Tool A and others get it working first time, when the command line and set up appears identical.

my word, finally got root, it was a task, thank you to TazWake for his incredible tutelageā€¦ this was not as easy as it sounds, but I do these not to just CTF but to learn and understand the processā€¦whewā€¦ BUFF is completed. wohoooo!!!

Man root is killing me lol. Iā€™m getting the FATAL ERROR: Network error: Connection timed out as well. Also canā€™t seem to actually get C****.*** to listen for connections either.

I canā€™t figure out how to upload the binaries. Can someone give me a nudge, nothing Iā€™ve tried has worked.

@LMAY75 said:

I canā€™t figure out how to upload the binaries. Can someone give me a nudge, nothing Iā€™ve tried has worked.

The RCE allows you to issue commands which make the system reach out and get them from you.