#interceptor
1 messages Β· Page 1 of 1 (latest)
Please be mindful as a general guideline to not ask for/provide hints in the first 72 hours after a challenge is released. This also covers streaming. π
Ignoring this rule will result in being muted until the hint embargo has been lifted. 
During the 72 hours after a challenge is released, you will receive 50% more regular points per question!
Examples:
- Scoring 80 points (30 regular points + 50 blood points): becomes 45 + 50 = 95 points
- Scoring 30 points (30 regular points): becomes 45 points
Good luck! Unfortunately I'm not home :[
127.0.0.1 βοΈ
Same condition π
GL all, won't claim a spot in the top 10 I think, pretty exhausted and need some rest. For now it seems like the rating is properly set this time π
ghost town today - where is everyone?
Celebrating 
Or probably still cracking the machine
what are they celebrating? I only know of Cinco de Mayo - on the 5th
1st of May is International Workers day for example
But probably people have something to do
i guess i need to get a lifeπ
I feel like I'm missing a crucial thing to solve this coom
Nahh, rooting THM boxes it better
Trust me
i've been grinding so hard - i missed Intl' Workers Day -lol
So you celebrated it working 
the irony;)
I'm trying but cannot see the missing angle. Will need to come back. Congratz on the blood!
Man, I should really stick to blue team
What am i missing π
nah- gotta switch it up sometimes, if anything just to appreciate what these goblins do just to break in;)
@pallid vapor congrats on first blood π
ty! sun shines on every dog now and then;)
Gave +1 Rep to @unborn talon (current: #1106 - 6)
Btw, a little sanity check. Did you also have to restart this machine every 10 minutes or is it something I'm only experiencing
Uhm, no need to restart
hailing fron us-east-1 no issues there;)
Alr, then it's either issue with me, EU-Frankfurt server or this new VPN app from THM

I really disliked this one, not only because of the misleading scenario description. What is this!?
what's the other reasons?
might discuss this after hint embargo is lifted
sure, i'm curious to hear your opinion
π
i hear ya, it needed to be doneπ
these old type of rooms and PHP, last week and this week, like some 1990 archive was open or something
description should be more on Burp / intercept on second step not first step to remove confusion
so the burp suite wasnt the first step? God i was going insane
Just approach it like every other machine and ignore the scenario description π
That's what I decided to do lol
mee too bro me too
I was on it since i woke up lmao
i will start now xD
i couldnt figure it out yesterday maybe new day new luck lol
yes treat it as AI room. ignore previous instruction and .....
Now i got a root shell π
root people are you testing Copy Fail vulnerability or something else
Iβll dm you
i tested copy-fail but they have neutered it (taken os.splice()) away and my workaround from that tipped over the box;). turns out root is much simpler (old school linux privesc)
i tried attempting this right when it came out and got stuck right there, and i am still stuck idk what to do. can someone help?
I am try 12 vuln all those failed , dont know which is the fu**** trick
I used this one today https://github.com/tgies/copy-fail-c
I actually got the copy fail working π π
shhhhhhhhhhhhhhhhhhhhhit
The detection script I used: https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
should rename it burp-fail for this labπ
well, does this has anything to do with||psl|| ?
Copy Fail is the latest Linux privesc CVE, and it's a relatively simply exploit that overwrites files in the in-memory cache. The exploit will abuse this by overwriting the cahce for a SetUID binary and then running it. In this video I'll walk though the author's POC, show my own deobfuscated POC, and show how the vulnerability works. To close, ...
shit tackeove room
Amazing - I am in π
ok .. learned a new technique .. however root was so easy.. hehe good room
Copy fail is like "Hurry up, the patching department is hiring" at this time the machine is still vulnerable....
way make it more complicated then it has to be xD
hii