Heist

Spoiler Removed

I used r**c****t for that and manually enumerated after finding some known users, probably not the most elegant way, probably missing a tool that auto does it!

@sazouki did you use the credz you already have?

there is a pretty sweet perl script that enums users from the service you all want to access so much

Type your comment> @badman89 said:

@sazouki did you use the credz you already have?

i got it after install all the requirement from that github repo

Stupid question but do i need to be cracking the $1$ I have decrypted the other 2 passwords but can’t seem to crack the other!

Type your comment> @Dreadless said:

Stupid question but do i need to be cracking the $1$ I have decrypted the other 2 passwords but can’t seem to crack the other!

Yes

Type your comment> @DameDrewby said:

Type your comment> @Dreadless said:

Stupid question but do i need to be cracking the $1$ I have decrypted the other 2 passwords but can’t seem to crack the other!

Yes

Thank you, I will keep hunting for a way :slight_smile:

Fun box, helped me to get some much needed enumeration practice on Windows :slight_smile:

Type your comment> @Dreadless said:

Type your comment> @DameDrewby said:

Type your comment> @Dreadless said:

Stupid question but do i need to be cracking the $1$ I have decrypted the other 2 passwords but can’t seem to crack the other!

Yes

Thank you, I will keep hunting for a way :slight_smile:

check my previous post, I shared the script to decrypt that pwd

Can anyone drop me a hint on where/how to use the 3 creds I found. I’ve tried all user/pass combinations on every service I could find but nothing is working

Hi guys… just after a little nudge please? I have 3 passwords… I can authenticate on 445 with a username and password… but can’t seem to use the winrm shell etc to progress… I think I may be missing something…

Hey, got user but stuck hard at root, and not able to use powerup.ps1 on this box is this by design or I am doing some shitty mistake somewhere any nudges please…

I’ve got user as well. Couldn’t get powerup to work. Sherlock returns nothing useful. Trying jaws-enum now.

Does the attachment attached give any hint for passwords?And also is the port 5***,the right way to go? Guys?

I have user now guys… don’t need a nudge… now for root…

is the admin pwd in www**** a rabbit hole ?

Ok, this box is weird. I have the new username and all passwords. According to one of the aux scanners, one login combination works fine but it fails while using any winrm shells.

Am i missing something obvious here?

anyone give a hint on root, i cant seem to run any enum scripts. the user doesnt seem to have much privs cant even access the public folder weirdly

is there something in I*C$? or am i going the wrong way?