TryHackMe - Red Stone One Carat - Writeup!
Red Stone One Carat - Starting the box can take some time
Set IP
New starting point set IP
to be environment variable
Now open new Terminl window and $ip
is set. Ready to go
SSH
Not a typical kind of CTF. Credentials provided right a way noraj
, but password contians bu
in it.
So the hydra
has less work.
User is rzsh-ed
But is was way too restricted at least for me.
After some research found the way to get irb
on the machine
User Flag
It’s was easy one, but before created function to read file.
It’s better way to print files, in this case, then on the picture.
Priv Esc
Let’s see if there are any files for crontabs
.
Now let’s see what is in dummy.sh
Finding Roots
The hard stuff is starting here, connecting to the port 31547
has not gave me much.
So I’ve tried coping dash
to privilege escalation… nothing… user noraj
was coping the file adding sticky bit wouldn’t help.
And then after couple hours later… connecting to the port… after much time reading about delimiters of ruby
At least copy was successful…