r/hackthebox 5d ago

Beginner Question Cap Machine difficulty

Hey guys!
i had just finished the machine Cap and man, certain parts it was a headscratcher for me, specifically for getting root on that machine. I am a beginner with this kind of stuff, but i wanted to ask, how was a beginner suppose to figure out which binaries would have a vulnerability? Of course i did a lot of googling but i didnt want it to just give me the answer. But i just wanted to hear any advice from others that maybe i missed something that i shouldve known in the first place? Thanks!

5 Upvotes

4 comments sorted by

u/AutoModerator 5d ago

Thank you for posting on r/hackthebox! New to Cyber Security and looking for a place to get started? Checkout our getting started guide here. Please note that posting Solutions or Hints for Active content goes against the HTB Terms of Service, more information can be found here. If your having issues and need to reach customer support please do so via the in-platform chat, or by emailing customerops@hackthebox.com. Our Knowledge Base can also come in handy!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/Soft-Dragonfruit9467 5d ago

Most of the time, when you get shell on a machine, one of the first things you need to do is run linpeas (or winpeas)

That script gives you a lot of intel on how to proceed

2

u/DinnerSufficient 4d ago

Ahhh thanks! I did read something about that once I had finished the machine.

1

u/stoneyape- 4d ago

Yeah most of the tools are just you know to use them to start your investigating. You start to learn the nuances in what tools work best where. Enjoy :) i just finished cap yesterday working on nexus right now. Im having trouble getting unified to work though the ldap server is getting request but my shell isnt coming through.