I have to agree with @ryan412 here. Getting user took me a lot longer than it should have simply because I didn’t guess the obvious fast enough. I tried a lot of other “obvious” things but not the right one.
Priv esc was surprisingly easy and close to click, click pwn.
I wouldn’t say I disliked this box, but it was a bit disappointing in places.
I managed to get user and root . Very interesting machine.
Hint for user, be lazy, check the very obvious thing first but then dont go storming the same door that allowed you to verify the discovered credentials, use them to poke around.
Hint for root, see what is installed and what is running then find the exploit online. DOnt be a script kiddy though, youre gonna have to find the proper way to use that PS script.
i found a list of users but i cant login with any common passwords. I’ve tried guessing basic ones and some popular wordlists. what am i missing? can someone DM me a hint for the foothold?
i found a list of users but i cant login with any common passwords. I’ve tried guessing basic ones and some popular wordlists. what am i missing? can someone DM me a hint for the foothold?
It is a little bit annoying but when you get this you will kick yourself. You have enough information right now and you even have a password, you just dont realise it yet.
Take all the lists of information you have now and make a wordlist out of it.
user: no major skills are needed and hte overall process is very similar to many other boxes. Indeed, getting the first shell is all about the common admin laziness and the normal enumeration.
root: learned something new. Despite the fact that i’m really potato with ps and s**, eventually I discovered a new way to get the info I need.
Initial foothold was fun and can definitely be liked to a real world scenario. I think I’ve even been guilty of that once when I first started. Think what might not be in a wordlist, but also might be easily guessable!
Really struggling with getting the POC to work for root however! If anyone wants to send me a nudge then you’re more than welcome to
Struggling to get the PoC to work - if anyone can point me in the right direction that would be amazing, been sat on this for a couple of hours now with no luck
Ignore! Worked it out by reading the instructions…
PS C:\Users\Administrator\Desktop> whoami
m…/administrator
PS C:\Users\Administrator\Desktop> ls