I dont think im doing the correct command for root. Im using net*** to de***** the file in ba***** but its giving me random characters that are not on a keyboard. Can someone PM me a nudge?
@DancinHype said:
I dont think im doing the correct command for root. Im using net*** to de***** the file in ba***** but its giving me random characters that are not on a keyboard. Can someone PM me
you should try something else somewhere
I dont think im doing the correct command for root. Im using net*** to de***** the file in ba***** but its giving me random characters that are not on a keyboard. Can someone PM me a nudge?
@DancinHype said:
I dont think im doing the correct command for root. Im using net*** to de***** the file in ba***** but its giving me random characters that are not on a keyboard. Can someone PM me
you should try something else somewhere
Yeah I figured it out and rooted im just a little slow on figuring out where I can C***** files
Root obtained - thanks to @DancinHype for the pointer on priv esc.
Overall, not an easy box to be honest. Requires some oddly specific steps which didn’t feel very discoverable compared to other easy boxes. Definitely a Medium at least.
Root obtained - thanks to @DancinHype for the pointer on priv esc.
Overall, not an easy box to be honest. Requires some oddly specific steps which didn’t feel very discoverable compared to other easy boxes. Definitely a Medium at least.
Dont worry others recently have been saying that the difficulty seemed off. And my post right above this lol.
Got a shell, but am now drawing a blank, since none of the scripts returned anything useful. Got a few passwords, but they don’t work for the desired user.
Should I hunt for more creds (though I can’t imagine where to find more), or am I on the wrong track?
Never had to deal with such systems (AFAIK), so no idea where to continue hunting.
Got a shell, but am now drawing a blank, since none of the scripts returned anything useful. Got a few passwords, but they don’t work for the desired user.
Should I hunt for more creds (though I can’t imagine where to find more), or am I on the wrong track?
Never had to deal with such systems (AFAIK), so no idea where to continue hunting.
yup, same exact situation, BUT, as our fellow @TazWake always says - try and used the loot in other services.
I’m currently trying to understand the usage of libex** with that 3*** port.
The weather isn’t getting me anywhere. r.**** seems promising but no credentials found yet. Got into the “other” website and found some info. But I am stuck at the moment. Am I going in the right direction? First time trying an active box and it is challenging.
Got root! It was very interesting experience, especially with privilege escalation, it seems pretty straightforward now, but you have to use some os specific commands
A bit CTFy. My 2cents:
Foothold: play around with that parameter
User: enum and pay attention to how the app is run, but it still won’t make much sense at the end
Root: a bit of further enum and a couple of OS-specific tools and you’re done
Also, I see there is yet another discussion about the difficulty. It’s always going to be subjective. I stopped paying attention to that a while ago.
Nice to see a little variety in the OS types on htb.
hints:
Foothold: parameter needs some closure to move on
User: do some local authorized browsing
Root: more common tools you might be used to won’t work - find the safer and simpler os specific tools and you’re done