Official Compiled Discussion

I feel incredibly stupid. Read through what I was doing last night carefully and apparently I needed sleep, made a stupid mistake. UGH. Finally got foothold only wasted about 3 hrs.

anyone who rooted the box can give any hint on privesc? already got user flag

Anyone rooted this yet with linux?

Hey there! :blush:

Iā€™m having a bit of trouble getting that initial foothold. I feel like Iā€™m doing well and getting close, but itā€™s been hours and I havenā€™t made much progress. :thinking:

Could someone DM me to help me a bit? Iā€™d really appreciate it! :pray:

Thank you, and happy hacking! :computer::sparkles:

can I get a slight hint on root? is the attack vector related to visual studio/building projects?

Can someone DM me, have an idea of what to do for foothold but doesnā€™t seem to be working. Guessing that iā€™m missing something crucial.

Yeah Im very lost, I dont know where to find this CVE im supposed to use apparently.

stuck on user. Canā€™t find any vectors for root honestly. Hashes seem uncrackable, well except one

1 Like

Can someone dm me on the foothold. I am stuck on this for quite a while now :cry:
I found the CVE but canā€™t seem to get it to work.

Question for foothold: Do I need to create a docker to push to the repo?

You do not, can be pushed locally from your attack box cli

Got foothold but canā€™t find these hashed everyone is talking about. Can someone nudge me where to look. I suck when it comes to windows :upside_down_face:

Seems like impossible without access to windows build machine. If we are talking about hte same CVE

Finally got a foothold but not user! Learned a whole of git in the process!!

You can ask chatgpt to convert that format for you to the destination one you can use in hashcat examples, or just 2 cyberchef recipesā€¦
If you correctly identify the source and destination formats, using cyberchef would be easier.
PM if more info needed.

The hash is crackable. You can DM me if you still need help wiht this.

this is the way to go

finally, learned a ton from this box, my hint for root is that if you are sure it should be working and it just isnā€™t, it is probably your shell. wasted hours and it was my stupid shell.