Official MonitorsTwo Discussion

very nice machine definitely learned a lot

At what stage are you? Seems you have a shellā€¦ but youā€™re probably in the wrong place. Thereā€™s another door, which might seems to lead to the same place, but it leads to a different oneā€¦

I have a ssh session with the m*** user

Then linpeas should give you the answerā€¦ SUID part.

got the root on whale, but unable to find any way to escape itā€¦ can someone give some hintā€¦

work out how to use the file in / to your advantage. where are the commands in that file looking, how could you look for something else, or for everythingā€¦?

1 Like

I got the shell and even i know what next to do. how can i edit the file in shell?

Just got the root flag, actually easy in the end. Just pay attention when you land after the container bit. All, very clear from there.

Hello everybody,
actually Iā€™m a little lostā€¦ Iā€™m pretty sure Iā€™ve discovered a valid Username/Password-Combination. Now Iā€™m trying to ssh into the host via ā€œssh m******@10.10.11.211ā€ after a minute without any reaction, it gives me the simple message ā€œconnection closedby 10.10.11.211 port 22ā€
I also didnā€™t get any chance to enter a password, no further hints about the reason for the closed connection.
Does anybody has an idea what Iā€™m doing wrong?
I can reach the host via ping and nmap is showing port 22 openā€¦

Any help appreciated :wink:


Edit: iā€™ve added ā€œ-B tun0ā€ in the ssh-Arguments to ensure that Iā€™m using the correct interface. Still not workingā€¦

Itā€™s working for me. Does your ssh work with other HTB machines? Is your router/firewall blocking ssh to certain networks/IP ranges? Maybe VPN config?

I have root but there are no flags anywhere?

finally got my initial footholdā€¦ I will say to help some other folks that not all POCs are created equal and the exploitdb version doesnā€™t work out the box I recommend the github version of the poc :face_with_monocle:

Youā€™re in the wrong place thenā€¦

Can anyone dm me for flags, what i am missing pls help.

Can anyone help guide me towards the user flag? Iā€™ve gained a foothold and found the .sh file (and what appears to be useful information), however, I am unclear where to go from here for the USER flag. Any help would be appreciated. Feel free to DM. Thank you!

Thanks for all the tips!

guys im root
but ā€¦ where do i find both flags??

the other posts in the thread should give you enough hints, you are not in the right place even though you are root
do some research about the hosted service and learn about what technologies it uses to run, then look for unusual files in obvious places

1 Like

I think if you think as a matryoshka youā€™ll figure out what happens. Anyway, what you did is not useless.

Owneeeed :slight_smile:

for real privesc you need to follow admin hints