Nice man , Have fun
Thanks manā¦any hints on gaining initial access.
Iād appreciate it
Itās an hard box you know. You shouldnāt start with this one if itās one of your first otherwise, youāre almost sure to disgust yourself.
If youāre okay with this box, you should find many clues in this thread about the initial access.
Anyone eager to give some tips about the first RCE?
Keep trying but canāt get it to workā¦
Nudge for the container breakout would be great
Already accomplished RCE, PrivEsc and found the keytab. No luck with portforwarding and winrm
Hint for privec ?
Use chisel for port forwarding
Sure, PM me
firejail
popped root in the nixenv, but am having nothing but issues running traffic through a tunnel. you mind if i PM you for a chisel sanity check? have not gotten any results at all for a portscan.
Sure
is forging ticket from keytab the right path?
looks like no suitable spn for DC in keytab. i tried forge one but failed to authenticate winrm.
No, enumerate the machine more. There is a user on the Linux machine and it exists there for a reason.
Check out configs and dbs used by AD on Linux systems
Any tips for administrator? Already got user flag.
Check out listening ports, use port-forwarding.
Try to login to the app and sniff all requests/responses.
Look for cve, all the parameters for it you should have on hand already.
thanks. iāve seen its log when searching some info.
now investigate more on it.
still have a problem with upload anything using ssh resource form. I donāt know what is wrong. ssh-keygen -t rsa -b 4096 -f ./mykey is in my opinion correct. But the form still has a problem āThe given SSH key is invalidā.
Have anyone any idea what could be wrong with key ?
When i tryed to use payload directly with definitely working crt file usinf file:///filepathā¦ it is also finish with mentioned error. Iām unhappy that i canāt figure out what is wrong more days. Using BurpSuite it is also the same.
I reseted Box and again the sameā¦
Thanx for help
you can generate key not only with ssh-keygen
ou, you are right, opensslā¦ im so stupid. Thanx a lot for kick
jesus, 3 daysā¦ working now. Thanx a lotā¦