Official Sau Discussion

google is very generous in this case, no complicated searches
just give a general prompt and you will likely find something useful

Finally figured out the root part

most of you are hammering my inbox without even trying… (already replied to more than 50 messages today)
if you don’t understand the vulnerability at the first glance, take a step back and learn more about it… that’s the whole point of all these boxes…

11 Likes

Rooted:) DM if you need some tips.

I managed to get the user flag without a rev shell, but I can’t get a shell for the root flag.
Any hints?

extremely basic linux enumeration will do the trick

rooted!

thanks @usr1221 to point me how to get out the rabbit hole I was in…

I think that I’m the only person in this community that create his own rabbit holes when there are no ones

`[pwned finally](https://www.hackthebox.com/achievement/machine/1535454/551)`

If you’re stuck or anything, you can DM me?! I’ll try to help where I can.

The box is definitely easy, your brain shouldn’t tell you otherwise when you’re frustrated. Everything is in front of you, for both foothold and priv esc.

4 Likes

Is the normal behaviour.

I think I’ve found the proper exploit but it isn’t working, is someone able to nudge me in the right direction with a hint, I’ve tried to follow the writeup for the exploit a thousand times with no results on nc

1 Like

Try a different payload, I also had problems with nc.

1 Like

Rooted :partying_face:
A very cool and easy machine.
btw: if you get stuck in an endless loop, you’ve gone to far. Turn around, go back a step and think again.

Great easy machine! Weird how easy was to over complicated things, probably because of the last one.
If anyone needing help, feel free to pm me

3 Likes

Rooted! I really enjoyed this box. It’s ā€˜easy’ but you still have to work a little for your foothold. As for root, I definitely overcomplicated it. I’d be happy to share some hints so feel free to message.

User: What web applications is the box running and what versions? Find anything interesting?

Root: sudo -l (This is all the info you need to root)

1 Like

Rooted.
Thank you @liram for the initial guidance.
Everything is in front of you literally, you just have to connect the dots. Once you connect the dots it’s only the execution that takes time.
DM if you are stuck somewhere. :v:

1 Like

my gobuster is keep finding your baskets :rofl: :rofl:

2 Likes

my gobuster found a lot of buskets

2 Likes

2 resets in 10 minutes. cmon guys. Even my autorecon like Nah, dont bother me with this machine dude :sweat_smile:

Hi! I’m a newbie here and I’m stuck with this machine.
I would truly appreciate some help here.
Thanks all :slight_smile: