Heist

Nice and easy box. Thank you @MinatoTW for the quick solve – I’ve enjoyed almost all of your boxes so far (except for Ghoul, I’m sorry :disappointed:)… This was a great way of introducing a Windows box to newer users with less environmental familiarity, so I applaud you for that.

Per usual, my hints:

user:

Standard web enumeration isn’t quite enough. Check out what other ports are open and enumerate a bit further. Once you’ve collected everything you need, you can use a common Windows protocol to get your shell. The previous comments in this thread should already be enough to figure out what I’m referring to here (though, I’ve heard some people on free servers have had a bit of trouble with it).

root:

Check what processes are running. There’s one in particular that’s interesting. Can you get anything from it? Maybe see what it can give you and go from there.