Official Reel2 Discussion

@HcKy said:

got user. took probably longer than it should have. spent more time social networking than i probably should have. tried to do some enumeration for privesc but a break is much needed. I assume it’s something with the files of the current user.

Enumeration is the key. Finding files used to record information is helpful. Also getting a good idea as to why the command options are so limited opens the door to work out an attack. (This seems vague but it is hard to explain without explaining, when you get root you will understand)

i have valid creds on a service but struggling to use them. Someone want to give me a sanity check? My normal go-to is not working…

Shout out to @acidbat for getting me back on track!!

Type your comment> @rootshooter said:

Shout out to @acidbat for getting me back on track!!

No worries mate :slight_smile: -

Managed to get the user h**h using r******r … accessed the box remotely using pwsh … but got stuck with JA :smirk: tried many ways to breakout but nothing seems to work… a nudge towards right direction will really be appreciated.

Thnx

@sicario1337 said:

Managed to get the user h**h using r******r … accessed the box remotely using pwsh … but got stuck with JA :smirk: tried many ways to breakout but nothing seems to work… a nudge towards right direction will really be appreciated.

Abuse the service you are stuck with. Look at how it is configured, this will give some good ideas on what you can do to make it work for you.

@TazWake said:
@sicario1337 said:

Managed to get the user h**h using r******r … accessed the box remotely using pwsh … but got stuck with JA :smirk: tried many ways to breakout but nothing seems to work… a nudge towards right direction will really be appreciated.

Abuse the service you are stuck with. Look at how it is configured, this will give some good ideas on what you can do to make it work for you.

Thanks for the response… mmh… didn’t look at it in that perspective, all this time I’ve been trying to break out of it… any link you can share that I can have a look at? Please DM if you have one or share it here if that’s not considered as a spoiler so that it can help anyone else in the same boat as me :smile:

@sicario1337 said:

Thanks for the response… mmh… didn’t look at it in that perspective, all this time I’ve been trying to break out of it… any link you can share that I can have a look at? Please DM if you have one or share it here if that’s not considered as a spoiler so that it can help anyone else in the same boat as me :smile:

I cant really think of anything specific - the Microsoft documentation on this is quite useful though.

@TazWake Much appreciated with the guidance and knowledge shared…
Learnt something that never knew existed

Got user and now off to root :wink:

Anyone willing to sanity check my list of names? I somehow can’t get any connections from the machine, after messaging “everyone”?

@HomeSen said:

Anyone willing to sanity check my list of names? I somehow can’t get any connections from the machine, after messaging “everyone”?

Feel free to DM me! This can be a frustrating box because it seems to quite often fall over.

After finally reaching out, and even get a response via PM, it all of a sudden decided to ping back :confused:
Thank you @acidbat and @TazWake for offering to help. It’s, as always, much appreciated :slight_smile:

@HomeSen said:

After finally reaching out, and even get a response via PM, it all of a sudden decided to ping back :confused:
Thank you @acidbat and @TazWake for offering to help. It’s, as always, much appreciated :slight_smile:

Nice one - the box is a touch unstable to say the least.

Type your comment> @HomeSen said:

After finally reaching out, and even get a response via PM, it all of a sudden decided to ping back :confused:
Thank you @acidbat and @TazWake for offering to help. It’s, as always, much appreciated :slight_smile:

Anytime mate :slight_smile:

Anyone can give me a little bit of nudge? I think I’m on a right path I just need to have the right file for me to get in.

Type your comment> @device said:

Anyone can give me a little bit of nudge? I think I’m on a right path I just need to have the right file for me to get in.

Send me a message :slight_smile:

Fun box! Got stuck for ages on the O** service erroring on me, even with numerous resets and VPN server changes. Sent in a JIRA ticket and @felamos fixed it for me. Decided to stick with the box a bit longer after grabbing the root flag and managed to grab a System shell

Thanks for the challenging box @cube0x0

Nice box, I thought that medium boxes was hard but boy I was wrong. Rooted with help of @acidbat and poped shell with @jamesa. But I’m trying to understand why on user powershell is behaving like this. Anyone knows? I would appreciate dm or something!

@cube0x0 thx for the great box :slight_smile:

Also thanks to @TazWake who is always willing to help, saved me some time on the User Part, had some trouble getting a replay…

Can i please have a tiny nudge in the right direction.
I’m stuck at the very beginning. Been messing with high port for a bit, but found nothing useful. fuzzed all ports, didnt see anything helpful either.