Ypuffy

@nodurhead said:
I think I have a username and password but I can’t ssh in. I keep getting permission denied public key. If someone can pm me I can give more details.

Thx

You can PM me

Quite interesting box, thanks to @Frey for the great tips.

Perfect hint for privesc @Frey , I really appreciate links like this as it’s not enough of a hint to be a spoiler but it’s enough that if you’ve done your homework and are stuck (me), you can learn something new without spending hours in a deep, dark rabbit hole. Thanks!

Arg priv esc is hurting my brain. I’m pretty sure I know the areas to be dabbling in, but no luck so far

Hi, I found usernames and a hash, I was able to log in to a service, but cant do anything, I get an error.
Is there some other way of enumerating dirs?

@pkneca said:
Hi, I found usernames and a hash, I was able to log in to a service, but cant do anything, I get an error.
Is there some other way of enumerating dirs?

check man page of that

@z3r0c001 said:

@tolg4yan said:
I am trying to get the ldap page. It was restricted so I changed firefox settings. Now when I try to connect to ldap port, it is saying your connection was reset. I am new on this stuff so can anyone pm me for hints please ???

Hi tolg4yan,
did you try to duckduckgo “ldap enumeration”?

I ve used jx***** for ldap enumeration and find some interesting stuff. But I couldn’t figure how am I gonna use them. When I try to use it with ssh it is saying premission denied (publickey).

I am proceeding but I think I need some hints.

@tolg4yan said:

@z3r0c001 said:

@tolg4yan said:
I am trying to get the ldap page. It was restricted so I changed firefox settings. Now when I try to connect to ldap port, it is saying your connection was reset. I am new on this stuff so can anyone pm me for hints please ???

Hi tolg4yan,
did you try to duckduckgo “ldap enumeration”?

I ve used jx***** for ldap enumeration and find some interesting stuff. But I couldn’t figure how am I gonna use them. When I try to use it with ssh it is saying premission denied (publickey).

I am proceeding but I think I need some hints.

The only thing you need to enumerate ldap is nmap dude.

@Underworld said:
Arg priv esc is hurting my brain. I’m pretty sure I know the areas to be dabbling in, but no luck so far

Snap

can anybody help me with privesc?

I ve used the following script -l-e**.py to enumerate ldap. However, i get the following error “ldap.NO_SUCH_OBJECT: {‘desc’: u’No such object’}”. Any help will be appreciated

@icyDux said:
I ve used the following script -l-e**.py to enumerate ldap. However, i get the following error “ldap.NO_SUCH_OBJECT: {‘desc’: u’No such object’}”. Any help will be appreciated

I answered this question four posts above mate ^^^

@Phr33fall said:
The only thing you need to enumerate ldap is nmap dude.

Never underestimate the power of GUI :slight_smile:

Trying to get root and hitting lots of dead ends. Any pointers?

Hi, could someone message me regarding the last step to the root. I generated what I should, but I am not able to use it. Thx

@AlexanderNagy said:
Hi, could someone message me regarding the last step to the root. I generated what I should, but I am not able to use it. Thx

same here, someone to shed some light into it?

@AlexanderNagy said:
Hi, could someone message me regarding the last step to the root. I generated what I should, but I am not able to use it. Thx

Are you sure that you have generated it the right way?

@hackernovice said:
Trying to get root and hitting lots of dead ends. Any pointers?

Enumerate the services, you wont hit a dead end, understand what every component plays in the process and you will beat it.

hi can someone PM me i have username and hash, but am unable to to use them

I don’t know how to use the ssh key you are mentioning as can’t read the private key too.
Can someone PM me to help with rooting?

@badman89 said:
hi can someone PM me i have username and hash, but am unable to to use them

edit; nevermind just found what i need