Official Cerberus Discussion

Anyone know if there should be a service running on port 9251? Seems like there should be but I don’t see it listed in netstat

Got creds. Trying to get user, trying to build a payload.

Trying to form the payload using this method, but it doesn’t seems to be accepted… I’m clueless :frowning:

i have root on the container.
any hints on breaking out of the container.

Also struggling here. Can obtain an NTLM hash from krb5.keytab, but not sure what to do with it yet.

Also struggling to get the RCE to work. Read the blog post thorougly but still can’t understand where to go from here. Any hints would be appreciated :slight_smile:

1 Like

Why do you need to find one if you can create one?

there should be a service there, yeah

Im not able to find a .pem file to write to. I tried default locations and to no avail. Any help via DM will be greatly appreciated!

Any hints on getting to the admin? I think I’ve found the vulnerability but I’m struggling with triggering it.

i ended up using msf since the POC wasn’t working for me even with all the same parameters. I assume probably a payload issue.

1 Like

wth, metasploit worked fine with the same parameters 0.o

PM me if you need hints for the box. Imo this box is really hard, even if you have a general idea of what to do next you often find yourself struggling with how exactly to do that.
The bad thing is how annoying it is to restore access to the windows after getting user and taking a break or getting some network connection issues (maybe I should have worked more on automation of getting the foothold though).
It was a nice try harder machine overall.

4 Likes

Need help, I’ve added the redirect to my hosts but still don’t get any response from the webserver…

I’m having the same issue… Have you gotten pass it?

icinga.cerberus.local

^^ add it to etc hosts like that, with the ip for your instance before it and tab instead of space between the ip and the domain name

2 Likes

I tried… still not getting response

Have you pinged the RHOST? What browser are you using? BurpSuites default port is 8080, try with that off maby? IN the shell you executed your VPN key . Does it say Initialization Sequence Completed at the bottom? If not, run it with sudo. If still not ? Download new VPN keys !

1 Like

Hello,

I’m trying to escape the container … any tips ?

Thanks finally got t the login page