Official Explore Discussion

Thanks @bertolis for creating an Android box. It’s a change from the usual Windows and Linux machines.

im getting a 500 error while trying to enumerate a certain port, im not sure if this is expected behavior for the endpoint or if i have to just expand on this path

Hey, Can someone give me a nudge on root?

Why when i try to S** into this machine it just keeps saying Permission denied (password,keyboard-interactive).?? I found the creds and yet it still doesn’t work? Also been stuck at foothold for 2 ■■■■ hours just because i kept getting Serve() error so i had to restart the machine to fix it -_ -

Type your comment> @thisisgloom said:

im getting a 500 error while trying to enumerate a certain port, im not sure if this is expected behavior for the endpoint or if i have to just expand on this path

Restart machine until it’s gone i had this too and wasted 2 hours on such a stupid issue

Type your comment> @Anciety said:

Type your comment> @thisisgloom said:

im getting a 500 error while trying to enumerate a certain port, im not sure if this is expected behavior for the endpoint or if i have to just expand on this path

Restart machine until it’s gone i had this too and wasted 2 hours on such a stupid issue

I’m getting the same thing. Thanks for the tip - will restart a few times and see if it lets up.

@Anciety said:
Type your comment> @thisisgloom said:

im getting a 500 error while trying to enumerate a certain port, im not sure if this is expected behavior for the endpoint or if i have to just expand on this path

Restart machine until it’s gone i had this too and wasted 2 hours on such a stupid issue

I wasted too much time yesterday wondering why this box was rated as easy only to find out today that nothing worked because the box was hosed. Even resetting it yesterday yielded no difference. Sigh.

Once I started it up and tried the same thing again and it worked this time, I rooted the box in about 30 minutes. Pretty neat regardless.

Just rooted this one.

Initial Foothold:
Enum everything, make sure your getting a FULL picture, after you find the right info it should lead straight into user.

User:
If you found the foothold you should have this.

Root:
Took some research and a nudge from a friend, sometimes when you hit a wall you just gotta dig under. Take a look at the at the information you have and search for the hole.

Type your comment> @Anciety said:

Type your comment> @thisisgloom said:

im getting a 500 error while trying to enumerate a certain port, im not sure if this is expected behavior for the endpoint or if i have to just expand on this path

Restart machine until it’s gone i had this too and wasted 2 hours on such a stupid issue

im glad i asked haha. thank you!

Type your comment> @Anciety said:

Type your comment> @thisisgloom said:

im getting a 500 error while trying to enumerate a certain port, im not sure if this is expected behavior for the endpoint or if i have to just expand on this path

Restart machine until it’s gone i had this too and wasted 2 hours on such a stupid issue

■■■, I WASTE A MORNING ON THIS!

ROOTED
FOOTHOLD: If you got Serve() error, restart until it work, then google it.
ROOT: Google ports

Spoiler Removed

Hmm, don’t work with a** for me… timed out !

PS: Rooted

I way overthought root and wasted a lot of time on attempting a kernel exploit I didn’t need to bother with.

Google with the right terms will literally hand you the path to both user and root for this box.

User: Pay attention to the results of your initial scanning for foothold, and do thorough enumeration.
Root: As with everything in offensive security, enumeration is cyclical. Do thorough enumeration of what may be running or listening on the system that you might have missed at the first look. Don’t overthink it, it’s an easy box. Once I stopped trying to be fancy with it I had root in about 4 minutes.

Finally managed to spawn the machine again and got root straight away. Thanks @bertolis for the fun box and for creating an android box.

Type your comment> @openwan said:

Hmm, don’t work with ad* for me… timed out !

Times out consistently for me too. Not sure if I’m doing something wrong.

Type your comment> @vramchar said:

Type your comment> @openwan said:

Hmm, don’t work with ad* for me… timed out !

Times out consistently for me too. Not sure if I’m doing something wrong.

Maybe you guys need a t****l stuff

Type your comment> @Zerox9137 said:

Type your comment> @vramchar said:

Type your comment> @openwan said:

Hmm, don’t work with ad* for me… timed out !

Times out consistently for me too. Not sure if I’m doing something wrong.

Maybe you guys need a t****l stuff

Ah! I didn’t think of that since it somehow worked for me once and then every other time it timed out. Thanks!!

Rooted :smiley:

holy ■■■■, I keep knocking this server over when I fuzz certain ports.
EDIT1: Ok fuzz slower you FOOL! :wink: got user on to root.
EDIT2: Got root, was definitely harder than user. Learned alot thanks!

PM me if u need a nudge.

New style of machines, I like it