Official Trick Discussion

I got Adm********** access to page. Don’t know what to do now, please dm me with hint.

Not really sure what to look for here and none of the ports seem to yield any useful information.

1 Like

DM bro

Full pwned. The “trick” be sure to find ALL the sub-domains.
It`s a good machine, any question DM.

1 Like

Is the box down? Whenever I go to the preprod-prll.tk.htb it keeps giving me a blank screen. Please help.

You don’t need the write permissions on the .conf file You already have write permission on the directory. Check the official fail2ban documentation to get how to proceed

3 Likes

Hey All, I am a little stuck getting the LXX to work. Can anyone give a nudge?

I have passwords and users and can get some files, but not others

Send DM

Hey guys, having issues with priv esc to root. Trying to replace ipt****-m******t.***f n restart f2b. But my code is not being executed.

Got to admin site, got access to login, got creds to 2 users, found LXX, read every php page I could find w the LXX (used php filter…) but I’m stuck at this point for over a day, tried everything I could think of. Can I get a hint

stuck at admin panel and L** . can anyone give a nudge?

My mistake was to think that this page is the last one. Look at this sumdomain and think.
Are you sure you found all the subdomains ? Maybe something hidden exists.

You don’t have enough rights to overwrite this file, since root owns it.

rooted, nice machine:

fuzz everwhere i will try another path tomorrow.

TIPS: play with DNS and fuzz.

if anyone wanna more help send me a message :stuck_out_tongue:

2 Likes

:crazy_face: I knew it has a big trick, but I couldn’t get out of it.

i just want to know. WHO TE ACTUAL F**K THOUGHT IT WAS A GREAT IDEA TO SCHEDULE A CRONJOB TO FLUSH THE CONFIGURATIONS EVERY MINUTE? can u please give me at least 2m or do i have to be a world champion at typing? also machine is broken. found in 2 minutes the priv-esc but giving u+s to /b*n/***h and executing it doesnt give me the group. HTB free machines without paying has to be the worst experience

1 Like

so i thought, well we know that method is broken, let’s just open a revshell to myself, it doesnt work either. wow i’m tilted

Got list of users on machine, currently struggling to figure out which ones have logins available . Any tips? Feel free to dm.

Rooted

USER: Fuzzing is the way, dont waste time in something thats seems juicy.
ROOT: Google, read carefully about that and just pay attention what you can do as that user.

Nice machine :slight_smile:

This was so fucking annoying =))