Official Heal Discussion

Can anyone give me some info on what the path from foothold to user was? I have rooted the box from what might be an unintended path. Feel free to DM.

I get the root but not able to get persistence over root account… any help/hint guys.

1 Like

Generate an ssh key. You need to be quick tho :grinning:

Thanks, managed to add my keys into authorized keys… but if i keep my listening open it return the shell again in loop matter…

I had the same issue, but once you have generated and SSH key you can maintain persistence that way

I’ve just taken another look at this. There is a small modification you can make against the script that you are uploading against the web-service. The field you are looking for is quite obvious as it specifies a timeout value…

1 Like

anyone please help i got the www- data shell and find a *****sql in the process . but i am stuck here how to priv esc from this point

Maybe try taking a closer look at the other interesting processes running that we could potentially exploit.

1 Like

something like a port starting with 8***

Looks interesting to me :slight_smile:

can u give a hint :upside_down_face:

Feel free to DM me with what you’ve found out/what you’ve already tried and I’ll be able to help give you some guidance :slight_smile:

I have ssh with the user’s credential but idk where to go from here to get root privilege. i used netstat to identify ports and ps aux but I can’t find a path. I tried doing some port forwarding but it is not working. I read the other comments but I do not get it. What am i doing wrong???

iI’m getting problems accesing the RCE file. It is already uploaded but i cannot find it’s URL. Any help/hints? I’ve tried all the common ones, including the exploit.py but none has worked

Glad to see a box I can finally do on my own :smiling_face_with_tear: Just got user, not too bad but I think I just got lucky with my enum. Do the usual enum and you’ll find what you’re looking for in terms of foothold.

hi, can you help me in invalid token thing, not able to understand whats wrong.

Stuck at api.heal.htb, found api.heal.htb/download, but can’t figure out what to do next. Any hint would be appreciated.

Hi, I am stuck at the foothold can’t find anything to privesc. Any hints or help?

How do you know the app is running on Ruby on Rails ?