HelpLine

Good morning! I'm rlfonseca, what can I help you with?

«134

Comments

  • Anybody got through the "Help Desk" login?

    lduros

  • Hello could anyone take advantage of the Explot-DB trick?

  • I tried to upload the file in the panel, but when I try to open it says file not found!

  • Ic32k are you trying this using a more "privileged user" ?

    lduros

  • I'm in but it's not so interesting yet...

    lduros

  • I hasn't able yet to find a more privileged user... you had found it?

  • well I found a way to find "who" has elevated privilege through an "API" but that's it.

    lduros

  • I can login with 3 users, one of which has API access. I'm getting the same file not found error.

  • edited March 24

    I know what I need to do with the API, found a script to run against it, but no dice for over an hour now. Any tips?

  • One of the notes after logging in gives F*P creds. Has anyone seen that service running?

  • edited March 24

    F**ck windows and bill gates, im stuck as nt authority/system for 5 hours and cant read users txt files.

  • Nice box so far!

    RY4ND

  • Can anyone give me a nudge on getting logged in? I can't find creds anywhere. Thanks in advance

  • Type your comment> @FlameOfIgnis said:

    F**ck windows and bill gates, im stuck as nt authority/system for 5 hours and cant read users txt files.

    ahhahahahahahahaha

  • edited March 24

    @Yamaha32088 search vulnerabilities of that system in google

  • to get creds do we need bruteforce ?

  • edited March 25

    Spoiler Removed

  • Any joy with the *P* vuln? I'm having a crack with Burp Repeater but its sooooo slow. Any alternatives?

    Arrexel

  • Ignore me. Found the obvious alternative :)

    Arrexel

  • hmm... well that didn't work! Back to the drawing board.

    Presumably @egre55 is chuffed that still no blood has been spilt yet! Tough box...

    Arrexel

  • Hats off to @xct for first blood! I thought I had this thing twice only to end up at deadends. I have to take a break from this one before I go crazy.

  • @incubus said:
    Hats off to @xct for first blood! I thought I had this thing twice only to end up at deadends. I have to take a break from this one before I go crazy.

    I'm right there with you; I had a few breaks, only to be met with a roadblock.

  • F**ck windows and bill gates, im stuck as nt authority/system for 5 hours and cant read
    users txt files.

    Okay, i found out why that is. Im sorry bill gates, you are cool.

  • Finally got both flags, what a ride... Congrats to @jkr and @xct you guys are beast. Thanks to @egre55 for the amazing box.

  • Never thought i would say it, but here it goes..
    Got root flag, working on user now.

  • I have logged in to the service, but not seeing any way to proceed!

    Magavolt

  • I was wondering if this reading user.txt is same with root.txt if so, how ? Seems pretty impossible for me .

    morph3

  • Just rooted it. What an amazing box, I learned a ton. I never got super into learning Windows in depth, but this kept me on edge throughout the entirety of the box. I'm not sure the way I took was intended and I am super curious what the write-ups will report on.

    Awesome box all around, and as of now it's one of my favorites ever.

    RedRaven

  • N0PN0P
    edited March 25

    And just make sure you think OutsideTheBox

    RedRaven

  • jkrjkr
    edited March 28
    .
Sign In to comment.