Forest

Finally rooted. No way in ■■■■ this is an “easy” box, but what a ride! ^^

Can someone PM me to help me with root? I been stuck for about a week or so. I have a graph from the dog and believe I know the path to get where I need to be. I’m assuming I am stuck at trying to add another user?

Took me 8 days after user to get root and the hints in the forum are enough to get you there. I think there might be multiple paths on this one, but I suggest you not get bogged down in powershell.

Should I be using a password or a hash to create my user?

The dog is hungry and needs to be fed but the readily available instructions on getting the food to feed the dog don’t work. Any help is appreciated!

this box was amazing! Thank you very much! more of that please. P.M. me if you need a nudge but study the graph, learn about what it actually means and google!

Can someone message me for some help? I’m stuck after making a new user…

Finally rooted, was a lot of fun and learning with Active Directory. Thanks to @NewViking and @instasec!

Is the ex*****e server a part of this?

Hey can somebody please give me a hint about the root part?
Thanks

Well GD - Finally Rooted, millions of thanks to @FatPotato, @instasec and @Tiyeuse.

This was my first box here and what a box! Took me about 5 days…thoughts:

  1. Tool for Enumeration: nmap and SPARTA!
  2. The imp can Get Users if you ask, then I’d feed those users to the cat!
  3. You’ll need a way to get the hound on the right path. I found two ways - either a Sploit of Power or the evil win.
  4. Once you’ve found the path with the hound, you’ll need a way to pwn his over ACLimated ■■■.
  5. Then his secrets can be dumped and he will be no more!

I spent way to much time doing that and it’s probably not even clever…give me a break my eyes are crossed from staring at this screen for so long.

PM me if you need help.

root tips> @HeXN0P said:

Can anyone please help about this error ?
KRB_AP_ERR_SKEW(Clock skew too great)
I’m currently using Manjaro distro. I can’t find a way to set the time to match the server and the nmap take such a long time to run.

@emptyArray said:
Well GD - Finally Rooted, millions of thanks to @FatPotato, @instasec and @Tiyeuse.

This was my first box here and what a box! Took me about 5 days…thoughts:

  1. Tool for Enumeration: nmap and SPARTA!
  2. The imp can Get Users if you ask, then I’d feed those users to the cat!
  3. You’ll need a way to get the hound on the right path. I found two ways - either a Sploit of Power or the evil win.
  4. Once you’ve found the path with the hound, you’ll need a way to pwn his over ACLimated ■■■.
  5. Then his secrets can be dumped and he will be no more!

I spent way to much time doing that and it’s probably not even clever…give me a break my eyes are crossed from staring at this screen for so long.

PM me if you need help.

help whit root please

Hey Guys, need a bit of help. Got users know which tool to use from previous boxes but for some odd reason when specifying domain and n*-*s argument I get this weird error:

RemoteOperations failed: [Errno Connection error (FOREST:88)] [Errno 111] Connection refuse

Did this for all enumerated users. Any ideas?

Can someone please help, stuck with Kerberos SessionError: KDC_ERR_WRONG_REALM(Reserved for future use)

Need some help… I found user and the password but i need to get the SID of the user can someone tell me what tool I need for this. And maybe which service for the shell ?

Type your comment> @ghostuser835 said:

Need some help… I found user and the password but i need to get the SID of the user can someone tell me what tool I need for this. And maybe which service for the shell ?

What do you need the SID for? :slight_smile: I think it’s time to take the dog for a walk.

Type your comment> @cassn94 said:

Can someone please help, stuck with Kerberos SessionError: KDC_ERR_WRONG_REALM(Reserved for future use)

Try and focus on 445 more. First, try to get a list of users then get a hashed password.

Spoiler Removed

Type your comment> @sta1ker said:

Can anyone help how to get
Replicating Directory Changes,
Replicating Directory Changes All
permissions?

There is a MS command line tool - d****s - that can display and set permissions on AD objects.

Hey I am stuck on bloodhound. I have uploaded it tried different syntaxes but it either throws or does not do anything. Any hints?