Reddish - Hints and Tips

stuck in this docker with not way out. can someone PM me perhaps?

anyone been able to get an actual shell (reverse) from “It Works!” machine?

I have been trying since the first day, and can’t find out how to escape the container. It’s hard enough to get a file on there without a text editor. any help?

ok, got user…that was…ridiculously good…

I haven’t got user yet, but I’m soon there (I hope). This box is really fun.

Is “Cannot Get /” normal? I’ve identified the service running, but there is supposed to be some sort of page here according to the docs. Not sure if someone messed it up on the free server or if I just need to enum more.

@crisco said:
Is “Cannot Get /” normal? I’ve identified the service running, but there is supposed to be some sort of page here according to the docs. Not sure if someone messed it up on the free server or if I just need to enum more.

Enumerate more

I am really frustrated with the connection lost on this box since there is only one way in. As we go further and further into the box, if someone reset the box or portforwarding or reverse shell break, then we need to build that long way again. I think it might not be a problem for VIP, but it is really bad for free user. I think creator should have created something like a checkpoint (ssh, etc). Just my idea.

that box is not medium at all, who tested it ?

I agreed with that. The initial rating from HTB is very inaccurate.

@KouPreY said:
I am really frustrated with the connection lost on this box since there is only one way in. As we go further and further into the box, if someone reset the box or portforwarding or reverse shell break, then we need to build that long way again. I think it might not be a problem for VIP, but it is really bad for free user. I think creator should have created something like a checkpoint (ssh, etc). Just my idea.

It’s a good idea I believe, but you can actually write a couple of simple scripts (can be one with some extra effort) to automate the entire process of getting to wherever you’ve reached already. And for a box at this level of difficulty, having to do some coding surely is a relatively simpler challenge.

Remember, wherever you can inject a simple whoami you can inject a thousand line bash script.

@saeedhashem said:

@KouPreY said:
I am really frustrated with the connection lost on this box since there is only one way in. As we go further and further into the box, if someone reset the box or portforwarding or reverse shell break, then we need to build that long way again. I think it might not be a problem for VIP, but it is really bad for free user. I think creator should have created something like a checkpoint (ssh, etc). Just my idea.

It’s a good idea I believe, but you can actually write a couple of simple scripts (can be one with some extra effort) to automate the entire process of getting to wherever you’ve reached already. And for a box at this level of difficulty, having to do some coding surely is a relatively simpler challenge.

Remember, wherever you can inject a simple whoami you can inject a thousand line bash script.

hahahaha…“thousand line bash script”…lol…(this guy)

stop watching my screen man…lol…how’d you see that?

#BashBrothers

Any help …regarding other interface … getting all ports closed…??

One of the most anoying boxes ever build in this Platform, no ssh way to have a stable access after some portforward for the next part, you get again in the first line with someones reset and you have to re-do the whole tunneling ■■■■ once again just to reach a point were you have to think for the next step and someoe just re-sets it all over. Ain’t gonna talk about the inaccurate rating i loled hard on the this one. The Node-Red circuits system was one of the best ideas ever kuddos to yuntao for making it, but overall it’s shitty, unstable and garbage box to work with. When i finally get a hold into the root zone the box for sure willget an instant lame. For everyone that is gonna start the box sooner or later take your seat by off VIP just to be sure for the plebs out there with the resets and cross fingers with every single forwarding and tunneling you are doing.

Stuck on the last Docker, anyone can clue me in? Got past user flag.

@peek said:
that box is not medium at all, who tested it ?

@eks did xD

Finally owned!
Best box so far.

Thank you @yuntao, I want more :wink:

r00ted, not my kind of machine unfortunately due to the struggle with containers.

i m stuck on the first container please give some hints

@raouf09 said:
i m stuck on the first container please give some hints

Just enumerate more.
Look at output from LinEnum.sh

You can always check @ippsec videos to learn more.