Official Zipping Discussion

could someone help me with user im not sure what to do rlly

For user: Enumerate the target, read known exploits for potential footholds. One good resource that has pretty much all you need for user is HackTricks - HackTricks .

1 Like

Could you please give me a hint about root? I already have the password but I’m stuck

Feel free to DM for nudges but please do tell where you are and what you did. :slight_smile:

1 Like

Not a bad box overall learned some new things! First medium box pwnd!

1 Like

Okay, I take it back - don’t DM me for user unless you have no doubt you tried everything you know. Sorry, fellas, but I was NOT expecting my inbox to get this flooded. You can DM me freely about root, though.

In either case, make sure to give me all the details of what you tried and what the outcome was. I can’t help you if you don’t tell me what you tried.

3 Likes

this was a difficult one for me but still owned and fun…

I don’t really understand how they classify these machines. I guess i’m still a noob after all these years lol.

initial- look around the site, you’ll find the attack vector pretty easy if you wanna work with them
user-this was the hardest part to me, finding the path was easy getting it to work… oh man…if you chew on it you’ll eventually find the magic…
root- all about your options and the stuff at the library…typical sudo checks will get you started

pm me if you want assistance, i’m around to help.

5 Likes

samee :frowning:

Search for vulnerability related to Shared library misconfiguration :slight_smile:

2 Likes

rooted the intended way! thanks to the guys keeping me in the right path! good machine and learned alot! great box!

To those who are struggling with ā€œNot Foundā€. Try to zip the file using the command line.

1 Like

help regarding user, is uploading the right path? i tried so many ways

some one always delete file when I want to gcc the exp
I tried many times to write the exp file

Summary

people I met on the machine even start **

hey give me a dm let me know what you have tried , i can try and give you a nudge.

1 Like

Fun machine overall! hmu if you need a nudge! I’ll do my best to respond!

Not gonna lie I’m really struggling here. Spent the whole day trying to get user, but can’t get the uploaded file to get executed. Tried every relevant trick I found on https://book.hacktricks.xyz, but I just can’t get it to work. Would really appreciate some guidance here, if someone could DM me.

Rooted. If anyone needs some help getting root feel free to dm me.

finallyyyy roottteeedddd ::)), box which is quite stressful, but I got a lot of new lessons, feel free to DM :slight_smile:

2 Likes

think about how the upload system works, when you do a zip upload, the system requires that there is a pdf file in it, maybe you can insert something in the zip???

1 Like

samee here :((