Official Omni Discussion

Rooted.

I enjoyed this box, although I had to do my enumeration twice. Once I fixed that it was plain sailing with a tiny bit of Googlefu.

My only hint is, if you feel like you’re fighting it (which feels like every box at the moment…) you’re doing it wrong. Backup, enumerate again and research anything you see that you don’t understand.

The script will work only if you’re connected to internet with a Ethernet cable?

Hi,

Could someone shoot me a nudge? I’ve got a shell onto the box now and I understand how the flags are obfuscated, but I get a crypto error for all three. Have tried with both accessible users, no luck. Can’t find any other files to try.

Thanks in advance.

Type your comment> @M1sha said:

Hi,

Could someone shoot me a nudge? I’ve got a shell onto the box now and I understand how the flags are obfuscated, but I get a crypto error for all three. Have tried with both accessible users, no luck. Can’t find any other files to try.

Thanks in advance.

Enum enum enum and PrivEsc, then go back to the files

Type your comment> @HASHme said:

The script will work only if you’re connected to internet with a Ethernet cable?

No… you can connect to the internet any way you want. haha.

It’s just that you have to be connected to the I*T C**e device with a physical ethernet cable, which the HTB VPN already emulates.

Type your comment> @ricepancakes said:

Type your comment> @HASHme said:

The script will work only if you’re connected to internet with a Ethernet cable?

No… you can connect to the internet any way you want. haha.

It’s just that you have to be connected to the I*T C**e device with a physical ethernet cable, which the HTB VPN already emulates.

Thanks!

Type your comment> @cybeR0ot said:

Having trouble in uploading the file or reverse shell. Any nudges?

Do not use script builtin function because it has problem with large/binary files. Use normal powershell function to download what you need on the victim machine.

Rooted. I’m a bit confused by the method for obtaining credentials though - it didn’t feel like it was the ‘intended’ process for privesc…

It was fun, thanks to egre55 for this box !

Argh this box is killing me. Managed to get a shell but it dropped almost immediately. Nudges welcome! :wink:

I got a shell (which is stable, sorry for my above neighbor) but I don’t understand where to go. I’m not used to Windows boxes :confused:

Somebody has any nudges left for me ?

Can someone Help me? if i am using the Right Scrip Si****T ? then what next? I am stuck

Type your comment> @Shsuleman said:

Can someone Help me? if i am using the Right Scrip Si****T ? then what next? I am stuck

RTFM !
Joke apart, look what you can do with it. If you can directly do what you want, maybe you can make the box do it :slight_smile:

@sm4sh0ps said:
Type your comment> @watchdog2000 said:

I also have the same issue with the ‘int’ not having property ‘value’ with that script. tried with both python2 and 3 (adapted the print statements of the code for python3, and anything else i could find. I’m guessing some people got this working by the fact that people have rooted the box… not quite sure what is going wrong…

This is caused by the wrong library. Try enum34.

damn!! thank you for the way out, I was stuck using enum as well!

First think this box in my mind “Wow IoT box with unknown OS…” i think this like hacking TV, freezer or something like this ? but when i first enumerating this is just windows IoT LMAO

Good machine! Very original OS part! A bit hard to be an easy one! Thanks @egre55 !!

PM if anyone need a nudge :wink:

rooted. thanks @yack and @N1D0

PM if anyone need a nudge

@cmoon finally rooted. Thanks for the nudges. bro

Rooted the machine !!!
PM If anyone need a hints

Type your comment> @sm4sh0ps said:

Type your comment> @watchdog2000 said:

I also have the same issue with the ‘int’ not having property ‘value’ with that script. tried with both python2 and 3 (adapted the print statements of the code for python3, and anything else i could find. I’m guessing some people got this working by the fact that people have rooted the box… not quite sure what is going wrong…

This is caused by the wrong library. Try enum34.

Thank you :slight_smile: