got user i need hints with root
can anyone give a hint on foothold , The only lead I have is the service running on respective port. I tried looking for xml , but I couldnt succeed .
For everybody struggling finding that file.
All Iāll say is, Google, and a certain package maintainer. That should be more than enough.
rooted
Type your comment> @xer0n said:
rooted
Iāve been around and around trying to get up from user⦠any nudge would be appreciated.
rooted, nice easy box.
foothold: you should find your way quite easily, remember what you found on the higher port and if it doesnāt work, try recreate box condition.
user: sometimes we need to remember where we are from.
root: really fun part, check who you are and some google search will give you the way
pm for nudge
sorry if i spoiled i tried to stay as enigmatic as i can
Just started on thisā¦found an e**l page?
Is this part of the box or someone else?
Much bumbling at the moment
Type your comment> @ferreirasc said:
The foothold is completely clueless. I know there is āsome senseā behind it ⦠but this is another one of those CTF-style steps. I donāt mean that this is all bad, it all depends on what you are looking for when solving a box. For me ⦠this was not āreal lifeā at all.
At first I agreed with this, since it felt like it was wasting my time since the startup files point at completely different locations for the key files you need to progress. It felt like adding red herrings. However if you check the package youāre looking for itās clear where you need to look.
The privesc was neat and I ended up using a technique I hadnāt tried before, so that was nice.
rooted it was pretty obvious once you knew what to do.
a big hint for foothold: i simply used a local installation of the app in the high port which helped me finding stuff way easier. i was really annoyed once i found out what i did wrong all the timeā¦
user: go back where u started
root: pretty obvious, doesnāt need any help i guess
good luck!
rooted. This is also a good box for OSCP learning
for people stuck on the foothold, good enumeration is key. there are two ways that you can find what youāre looking for, one of the ways is using information thatās provided on the box itself, and a little googling. another is trying something locally.
thereās no āCTFā aspect on this box at all and no guessing required, although it may seem this way if you donāt enumerate
stuck on foothold. need a hint
Type your comment> @Sup3rUs3r said:
Can anyone help me with t*t, h-m*****r. How to exploit this. I found credits. Maybe some script? Any hints?
Go back a little bit. Read all information very carefully & thoroughly, donāt be hasty.
Do not disregard anything you might think useless or disadvantageous. The answer is in front of you.
Finally rooted!
Thanks @egre55 for the machine.
If anyone need a nudge, PM
stuck at lx* part for root
getting error
Error: open *******.tar.gz: no such file or directory
any hints
Rooted! Straightforward box, just need to enumerate a bit more for foothold.
Type your comment> @liquidrage said:
stuck at lx* part for root
getting error
Error: open *******.tar.gz: no such file or directory
any hints
It doesnt like the format of a file within
Need nudge ā have creds / playing with VH but not sure how to exploit. PM appreciated.
Edit: thanks @EvilT0r13 and @sm4sh0ps ⦠I was hoping it was the traditional vector but need to accept it would be old school.
finally rooted nice box with learning stuff in TOMCAT part
i think on the free servers someone ācleverā deleted the usr files periodically. i can access web.xml and context.xml but 2 important files, no access at all. same directory.