Official Delivery Discussion

Great box, thanks @ippsec

Type your comment> @Raskul82 said:

User was annoying, took a while to figure it out. HMU is you need help.
Spoiler removed

Well, this is a big hint :lol: :lol:

So so finally root. Special thanks to @phl3ee & @666reda for their help and guidance suggestions.

In all honesty I have been bothering myself.

In retrospect, the steps are not difficult or complicated, in fact not at all.

But what a lesson I had in assumptions.

So my biggest tip all the others have already been mentioned in this thread if something is not working that should work in logic, look further everything is clearly present. Don’t get lost :wink:

root@Delivery:~# whoami;id
root
uid=0(root) gid=0(root) groups=0(root)

Can somebody give me a nudge for root. Do we need to create a list with ht and b f****

yes, but use the hint that was given to you.

Fun box, Thanks Ippsec

Type your comment> @Sk1ppy said:

Can somebody give me a nudge for root. Do we need to create a list with ht and b f****

Yes, as @HcKy mentioned as well, the hints are provided to you from @ippsec :wink:

I can’t get the verification to come through. I have tried firefox, chromium and three different email servers as well as resetting the box. Is there a trick or specific email provider I need to use? Thank you in advance.

@byd3fault said:

I can’t get the verification to come through. I have tried firefox, chromium and three different email servers as well as resetting the box.

In general, HTB boxes have no internet access. They cant send traffic to internet resources.

Is there a trick or specific email provider I need to use?

Yes

Thank you in advance.
Look closely at the options you have and what happens when you try them.

Type your comment> @byd3fault said:

. Is there a trick or specific email provider I need to use? Thank you in advance.

If you have already raised something than you already have something that is required.

Leveled up!! pro hacker now!
I didn’t find the foothold as straight forward as some other people did when trying to verify email address.

Foothold:

  • make the thing, view the thing
  • you can’t talk to them, make them talk to each other
  • make sure you’re still viewing the thing when they talk, maybe try editing it too

User

  • go chat with some friends

Root

  • look internally
  • then, use what you found in user

Struggling with root, try the cat and been enumerating but nothing has stuck out to me. Can anyone dm me for some hints?

Any help on Initial access would be greatly appreciated. I believe I can create/view the thing. But still not sure what the next steps are, I believe I have tried all I can think of and can go more into detail on a DM. I feel like I have “read everything” multiple times, but i’m clearly missing something. :frowning:

Type your comment> @S4co said:

cant connect to http://helpdesk.delivery.htb/ or http://www.delivery.htb/

should it be this way?

Same problem! Did u find a solution?

I can’t wait to see the ippsec youtube walkthrough on his own box, falling on his own rabbitholes… :smile: I’ll finally know if the famous “let’s see” is real or not :smile:

Jesus user really was easy… Tried registering an account and was stuck because I couldn’t view the ticket without verifying it ( 。_。)

Got user a while ago thanks @TazWake. Now I’m stuck on root. I have tried H****** and keep looking I can DM with more details on what I have tried but just need a nudge in the right direction.

@byd3fault said:

Got user a while ago thanks @TazWake. Now I’m stuck on root. I have tried H****** and keep looking I can DM with more details on what I have tried but just need a nudge in the right direction.

Its enumeration at its core. Find something, use it. Get stuff from the new thing. Turn the stuff into something you can read. Use it. Pay attention to all the hints you might have picked up along the way to build your own wordlist when you need it.

Could someone dm and give me a hint? Internal enumeration has always been my shortcoming. Finished user quickly but cannot for the life of me find the h**h for root, I know exactly what to do once I get it, but I can’t seem to find where it is.

root@Delivery:~# whoami; id
root
uid=0(root) gid=0(root) groups=0(root)
nice to see an easier box :slight_smile:

Great box! Thx! Rooted. PM me for nudge