Zipper

rooted

Ok so this one was really interesting

Initial foothold - Again Enumerate fully, There is a service which will tell you what sort of server this is. Read the documentation about software to get in. Personally i think the hint in here about a “spelling mistake” is a bit of a rabbit hole, unless someone wants to tell me what this so called spelling mistake is ??

Don’t use hydra - just make a note of what you can see once you access the website. As someone mentioned before - its not very security savvy

Some things can be done without a GUI - and it makes life a lot easier. Also look at things that should never be enabled in a production release of this specific system

User :

Reset the box - I’ve had attempts where some fool reset the user password. Then just look at what is in front of you

Root:

I don’t want to string you along here but make sure you are on the right path when you see an interesting file

Admins - if you reckon this contains spoilers please edit / let me know

Feel free to contact for hints. (as per usual, show your enumeration so far and don’t expect walk-through’s)