Official Laboratory Discussion

@aimforthehead said:

ok so got user. and I want to mention couple of things here -

  1. There is more then one way to get user.
  2. I’ve noticed an issue with the id_*** file. i was getting “bad format” when trying ssh with our friend de**** via ssh. what’s worked for me was
    https://forum.hackthebox.eu/discussion/3166/starting-point-markup-ssh-key-invalid-stuck-trying-to-get-user-txt/p1 (the 3rd post).

Moving onto root.

Regarding the file: Just add a newline at the end, and you’re good to go. “Newer” versions of the tool seem to choke on it, when there’s no line-break at the end ^^

getting 502 error on G****** from last 1 hr

@pagal said:

getting 502 error on G****** from last 1 hr

Check if the machine has been restarted. The service (and all the other services it depends on) takes its time to start. Otherwise, try resetting the box, and wait ~5-10 minutes.

Hello All

Got a Register interface
but error with email domains :confused:

=> “Email domain is not authorized for sign-up”
?

@D4rm1 said:
Hello All

Got a Register interface
but error with email domains :confused:

=> “Email domain is not authorized for sign-up”
?

EDIT it’s ok :wink:

this box was so hard, I am saying as beginner… thanks to @mrg3ntl3m4n for helping me. I dont know how I can thank you, I learned alot it wouldnt be possible without you.

OK rooted. wow what an incorrect rating. definitely a MEDIUM box not easy. So many steps just to get user flag, but root is simple if you enumerate then take a deeper look.

this box was so hard, I am saying as beginner… thanks to @mrg3ntl3m4n for helping me. I dont know how I can thank you, I learned alot it wouldnt be ossible without you.

I can’t see the main homepage, is it a machine problem? I can browse websites but not https://laboratory.htb

@4nt05 said:

I can’t see the main homepage, is it a machine problem? I can browse websites but not https://laboratory.htb

Have you added it to your hosts file?

Yes I did, if I ping the hots i have ping back but i cannot see the webpage with firefox

@4nt05 said:

Yes I did

What response do you get from the browser? Is it the same response if you use the IP address?

well I have the same response, since it redirects me to that address

"The connection has timed out

The server at laboratory.htb is taking too long to respond."

that the response for both, if I ping the wbsite I have the ping back, I am not using any proxy and I have updated kali and rebooted my virtual machine.

Sounds like the server has died. The IP shouldn’t redirect you though, but it should point to the same page.

Remember ping sends an ICMP echo request which just checks if the target machine will respond. Your browser is going to a HTTP server over TCP/IP. If the httpd dies, ping still works.

I have contacted the support, many thanks for your help

@TazWake said:
Sounds like the server has died. The IP shouldn’t redirect you though, but it should point to the same page.

Remember ping sends an ICMP echo request which just checks if the target machine will respond. Your browser is going to a HTTP server over TCP/IP. If the httpd dies, ping still works.

I have fixed the issue reinstalling the vpn

Hi,

Can someone give me a little tips,
I try some interesting facts, but i can’t find the way to get a R** on the machine to go future in the box.

I made the environment but still doesn’t work.
I’m not familiar to g*****-r****.
I’ve check Bu******* and other tools but i’m stuck maybe I miss something or did I surely make something wrong.

Thanks for the advice.

rooted!!! Thanks a lot to @HomeSen and @waza for the hint.
A good box and not really “easy”.
Initial foothold is the most difficult part. Need a CVE and escalate the CVE into something more dangerous.

user part is tricky. Don’t limit your brain in the foothold.

root part is obvious but need some background knowledge. I ran into some rabbit hole of myself and make things complex. But still learned some useful trick, just not applying to this box.

I am having hard time with this machine, probably i don’t have the right background around it. Even if technically it’s not easy I am lost, I have tried to find some articles that would explain, and I know how the cve works, but i dunno what to do with it, or probably i am considering a wrong CVE

Hi guys, I was able to get a shell, but I’m completely stuck. I know I’m missing a detail somewhere, but can’t figure out what. If anyone can give me any nudge on that, I’d really appreciate.

edit: Rooted - Although everything makes sense after you get root, I don’t think this was an easy box, but it was a great machine in terms of the knowledge you get.