Traverxec

whoami

root

id

uid=0(root) gid=0(root) groups=0(root)

it was easier for me than others. We also learn a lot here.

Stuck on user


I’ve founded in bp-s**-ity-fs.tgz. I’ve copied it to some directory (in this directory I have all privileges to write any files), then I need to extract this archive
 There is some files such as "a*****d_ks" and etc.

I need any nudge, PM me.

Spoiler Removed

Got the shell and User1. If you need help or any hints just pm me.
Hint for the shell: Enumerate
Hint for User1: Check all the folders

Goot ROOT. It was very easy.
Hint: Check the script and gtfobins is your friend.
Let me know if you need any help or hint.

Can anybody help me get the initial shell? I know how to do it, it just isn’t working. 100% confident I have the right exploit
 It always completes the exploit but no session was created. Tried every URI path I could see in Dirbuster just for the heck of it, but pretty sure all I need is the basic IP name

This box made me feel like such a dope
thanks for the many face palms @jkr

to those still battling their way through


initial: google

user: Do the obvious, and if after doing so you find yourself stuck - play bandit on overthewire dot org
major thanks to whoever it was that mentioned it several pages back! Never would have figured that out otherwise :wink:

root: just read what so many others have already posted, to say anything more would be to spoil it.

Type your comment> @zgordon96 said:

Can anybody help me get the initial shell? I know how to do it, it just isn’t working. 100% confident I have the right exploit
 It always completes the exploit but no session was created. Tried every URI path I could see in Dirbuster just for the heck of it, but pretty sure all I need is the basic IP name

PM me if u still need help

Type your comment> @zgordon96 said:

Can anybody help me get the initial shell? I know how to do it, it just isn’t working. 100% confident I have the right exploit
 It always completes the exploit but no session was created. Tried every URI path I could see in Dirbuster just for the heck of it, but pretty sure all I need is the basic IP name

if you cant touch her, let you make her to touch you


Got in using the rce.
Cracked the pass for dd using john from htpxxx.Ran a dirbuster to find any panel to use the creds found none. Read the config files of n***o but couldnt find anything helpful. Please could someone give me a nude.
Thank you

Got stuck on user, only thing that clicked was reading the man page.

Hope it helps!

@d3kum1d0r1y4 said:

Got in using the rce.
Cracked the pass for dd using john from htpxxx.Ran a dirbuster to find any panel to use the creds found none. Read the config files of n***o but couldnt find anything helpful. Please could someone give me a nude.
Thank you

The config files point to where you need to look next. Read them carefully and try to understand what they allude to.

Remember, if a webserver is serving files from a location, it needs access and just because you cant access a parent folder, that doesn’t mean you cant directly access the child folder.

If you want to look at it in a webserver, have a look at how webservers traditionally serve user directories.

Got my first ROOT. Really enjoy the box. Learn many new things, thanks to the Author. Thanks to @LMAY75 and @IamKsNoob for the nudges to get User. Root was mindblowing lol

rooted great machine i learn something new in linux navigate
thanks for the box!!
pm free for hint???

get user
good for beginner like me :slight_smile:
send pm if u need any hint

Rooted
 Thank you to @farbs for the advice. Total head slapper!

Rooted
root@traverxec:/# whoami
root

The root challenge is spécial

wow, the window-size is real

Rooted from the clues on here. Can’t even imagine how one would go about patching that.

Really struggling with root. Could someone please PM me for help. I don’t know what else to try.