Official Trick Discussion

Rooted!

Thanks to NeverHackMe for pointing me in the good way ;-D

1 Like

dm me if you need help

Stuck on the Adi panel as well. Any nudge would be appreciated.

anyone online available to help in DM?

FINALLY got user. I must have been doing something wrong with the L** before I guess. Thanks @JacobE for pointing me in the right direction!

Finally rooted!! This was a fun box :slight_smile: although I found the privesc kinda strange while going through the details.

Hello guys, some quick hint for those who are stuck

Foothold

  • You’ve got creds ? Good, maybe you’ll try those later :wink: You need to fuzz more based on what you have to find another subdomain. Maybe the other way ?

  • Don’t get to technical, remember that is an easy box, so it is, but maybe you need to flip your logic instead of looking for advanced enum

User

  • You probably just did it to get one cred, do it once more. Maybe fuzz it and jump on user

Root

  • Who is you ? Don’t get too fancy, a magician needs no tool, just tricks. If you’re still struggling, go back to the basics, and you will google it easily.

1 Like

Yeah, I did. Now I am with the root and prepod-payroll subdomains ,can’t find if there is another one.

Can I DM someone about the subdomains, and possible files stored on the remote server?

Hi, Send me DM

Hi, I am new to hacking and finding it quite hard to get started on this machine. I have tried enumerating the ports and fuzzing and attempted to retrieve some smtp credentials but I have not found anything too interesting, could you help me get started

Try to enumerate the DNS service.

how can I do that?

HackTricks is your friend.

Ok thanks

1 Like

If you need more help, send me DM.

1 Like

Finally rooted. But HtB does not accept the user and root flags.

For the user: Everybody mentioned about DNS fuzzing. After finding sth meaningful from the DNS, if you find a magical technic to read files, you can check anothers services “default” configuration file.

Btw, learned and remembered lots of things. Special thanks @JacobE and @Nevuer and the author.

Feel free to send me a dm.

1 Like

anybody help me what i do on which port i enumerate

You have to make a complete enumeration of the DNS.

If yo need more help, send me DM.

I found the ma****ing sub-domain, what should I do next? It seems nothing interesting :frowning:

2 Likes