Traverxec

so, i found where i need to be for all the good good user info, but i can’t seem to liberate them from their current directory… any help?

User was very easy and intuitive to retrieve.

Root took some work but I’m definitely laughing at myself after getting it.

User: I won’t provide any hints for the user as it’s that obvious.

Root: You’re probably like me and are already on the right track. Many users here have suggested the correct exploitative method (golf tango foxtrot oscar). Really think about how to use it. You’ll figure it out and probably laugh about it too once you get it.

Overall, this was a really fun box for a novice such as myself. Thanks to jkr for creating it and to the numerous users who posted nudges here.

Type your comment> @OddRabbit said:

That last part was kind of weird in order to trigger the command right. I still have a question as to the permissions in the last part though; why do I have to copy the *.sh file in order to actually write to it even though it is owned by the user david and writable for that owner?

My thinking is that if you edited the original sl s*t, it would mess up the box for any other users working on it at the same time as you.

Curious to see if the way I achieved root was the intended method or I missed out on a learning experience. Was the “size” route the end-game?

root@traverxec:~#
Rooted in 1 hour and 10 minutes! Id say that’s pretty good considering it’s my second box!

Just rooted my first box…

Thank you @jkr for such an amazing puzzle…

Easier than i thought, but what a nice mind spin!

hi guys! So, I’ve got my meterpreter shell which was easy enough. John showed me the way to david and user flag but now I’m stuck at getting priv esc to root. Looking at the sh file and there’s something here…I think
Started pentesting a week ago for the first time and it is exhilarating, but my knowledge is not quite there yet to get root on this box…please help.

So I’ve rooted the box now…but someone absolutely NEEDS to tell me how this works. The sizing thing is something new to me. Can’t wrap my head around it yet… DM please :slight_smile:

hello everyone!
This is my first box, and im stuck when i try to take download tgz file. any suggestion?

Hey all, so I was just able to get root, finally. Wooo

That being said, I did not have to resize my window like a lot of people mentioned here. Could someone PM me and let me know how resizing your window was a means to get root? Or was it used in conjunction with the other hints posted here? I get how I got root but I’d like to know if there was an additional trick to be used.

Anyways, I’d appreciate any insight into that!

Rooted. Root takes a little playing around with to get it. PM if you need help.

Just got root.
Last step is a facepalm, but it took me way longer than I would like to admit.

Just rooted! Relatively simple box, but I really enjoyed it. Root is funny :smiley:

Pm for hints :wink:

Hey, guys how to crack this thing from .ht*****d ? Hashcat says about Token length exception. I’m doing wrong something but I can’t determine what’s wrong. Help me please :slight_smile:

Type your comment> @medfgh said:

Hey, guys how to crack this thing from .ht*****d ? Hashcat says about Token length exception. I’m doing wrong something but I can’t determine what’s wrong. Help me please :slight_smile:

you probably need to clean up your hash file a bit. i ran into the same issue. see here: example_hashes [hashcat wiki]

rooted. Thanks @SamTheSapien

rooted its was fun box and i learn a lot of new think of cracking something and use bash:)

Rooted. I love the root part. So simple and quick solution, yet wasn’t fast at all, as I had to dig in google a lot.

I’ve cracked something hidden in .h******** but can’t seem to use it anywhere? Any hints?

Spoiler Removed

just got root huuh!

This being the second machine to own on HTB. I gotta say the machine was fun but i had nooooo idea what i was doing with these GTFObins stuff. In the though i got it and ,you gussed it, roooooooted!