Official Jupiter Discussion

I have a ssh session as p******** but that seems like overkill. Taking a break now. Will return to try and get to user.

Rooted. Interesting box. Especially the path to user. What others have said about the emphasis on enumeration holds true.

  • Foothold: Understand how the web server works. What interactions are going on behind-the-scenes? How much control do you have?
  • User: Enumerate. There should be some things that really stand out. Figure out what they are and what they’re for. Good lesson in Google-Fu.
  • Root(first part): You have access to something new. Honestly the path forward from there is pretty straightforward. If you find yourself needing something, just think about what might have saved it. It should be fairly close by.

This was my first time leaving hints. Hopefully I didn’t overstep. If anyone needs any help., don’t be afraid to DM.

Edit: Found out that my root path was invalid. Someone before me left something changed. I thought it was too easy. I’m going to leave my root hint up since it still applies to the first part. When I get time I’ll retackle the box the right way.

2 Likes

after shell how to privsec

how to privsec from p********

just rooted the box… make sure to check the premissions of ā€œthatā€ file carefully so you wouldn’t go down the rabbit hole lol

fun machine… nice work mto…

https://www.hackthebox.com/achievement/machine/1438050/545

I used the —max-retries 2 and the data length and found 2 ports.

Anyone try Nikto or Zap on this?

nikto yeah , but doesn’t help.
As Ippsec said: know your tools and how they work.
When you hit a static website, there must something elsewhere

hi friends i have found subdomain and found the potential db any nudge please.

sure ! DM

stuck on that sh**** sim******* part … any clues ? I can read some files and execute some sandboxed commands but nothing works

Hi can anyone give me a slight hint to what direction to take ive also tried subdomain checks used ffuf wfuzz dirb and gobuster and nothing interesting , thanks in advance for the help!

If you missed the subdomain, you should use another wordlist.

I can’t proceed after finding the subdomain, can you give some hints?

I rooted the box finally !! really really nice machine …
my hint are the followring

enum with the newer -dev version of F*** the other it’s not always working well …

once you are there think every single thing manually you’ll find the answer and the initial access…

I heard some people complaining that the box is not very stable … try append a child :slight_smile:

the privesc i’ts really straighforward! hope this can help and none flag me for too much hint!

any hint for user flag??

I can help get to user. I’m still trying to figure out root.

1 Like

i’m confused where to dig

Hi all, I’m searching for a token in order to enter the j… application. I’ve found a command that can theoretically give me the tokens, but I always get an error. Am I on the right track? Does someone hjave a little hint?
Thanks!

Rooted.

Some good hints here. I think I took a circuitous path from foothold to user.