Resolute

Getting this shell is a pain, to me I’m doing it correctly but not much happening, anyone give me a Sanity check please.

found the users and found juice but nomather which user i put with the juice
can not login with e***-w****

Type your comment> @madhack said:

found the users and found juice but nomather which user i put with the juice
can not login with e***-w****

Just looped it in bash and I’m in.

Type your comment> @m4rc1n said:

Type your comment> @madhack said:

found the users and found juice but nomather which user i put with the juice
can not login with e***-w****

Just looped it in bash and I’m in.

ok thx for the advice i will keep on trying!

So far so good, got the user. Any pointers to root?

Type your comment> @ssumkin said:

So far so good, got the user. Any pointers to root?

same here… User was pretty simple but I have no clue how to proceed. I have only an idea how it will goes…

whoami /all
check groups

It looks like somebody changes “juicy stuff” intentionally. Why there always has be an i***t who think this is funny? It would be a nice feature to have some monitoring in HTB and kicking out those who abuse the rules.

Type your comment> @m4rc1n said:

Type your comment> @madhack said:

found the users and found juice but nomather which user i put with the juice
can not login with e***-w****

Just looped it in bash and I’m in.

thanks for the advice :slight_smile: got it

@m4rc1n said:

It looks like somebody changes “juicy stuff” intentionally. Why there always has be an i***t who think this is funny? It would be a nice feature to have some monitoring in HTB and kicking out those who abuse the rules.

That’s not someone changing it, it’s part of the box. Try harder.

Type your comment> @clubby789 said:

@m9rcin said:

It looks like somebody changes “juicy stuff” intentionally. Why there always has be an i***t who think this is funny? It would be a nice feature to have some monitoring in HTB and kicking out those who abuse the rules.

That’s not someone changing it, it’s part of the box. Try harder.

I know that this is part of the box, but there was a change. Sometimes I can log in and sometimes not.

Type your comment> @rholas said:

whoami /all
check groups

ok - I don’t get it. Can someone send me an pm to push me in the right direction pls?

Any hints for root would be appreciated. User was pretty easy but root not so much lol (I’m not great with Windows boxes)

Check groups. Research what they can do

I know exactly what u mean and I have the juicy thing as well…
I do not know what to do with it coz evry i****t script denies access :frowning:

use something evil instead…

Got Root, I test my payload locally by build it and register the D*L with wine.

Hack The Box

Ok So i have got pass for user m**** and I am trying to use taht creds in tolls like E4** and other S** protocol tools unfortunatelly it shows me an logon failure alert. Also I have scan all ports for that server and I have found that service WR is working on some other port so I have use this port number an creds in some au***** module in M*********. Unfortunatelly still wrong creds :frowning: , any clues?

search second user(r***) creds

Second user which shows in what tool?

Type your comment> @rholas said:

search second user(r***) creds

@rholas said:
search second user(r***) creds

When you realize what are you actually looking for it becomes actually quite simple.
Now its root time -:slight_smile: