Sauna

same here bro! and for the rest of my team…

Type your comment> @VbScrub said:

Machine is working fine for me on EU Freem but so far its really kicking my ■■■ for an easy box lol can’t get an initial foothold at all.

Found plenty of open ports but absolutely nothing useful on any of them other than the domain name. Studied all the source code and HTTP requests on the website and got nothing useful, no anon access to SMB or anything else, and even though I can get some very basic info from L*** I can’t actually get any usernames or anything interesting. Dirbuster didn’t find anything on the website either and its all just plain HTML with no javascript to look at or anything like that, so I’m pretty stumped and might have to resort to just throwing random impacket scripts at it lol

I am in a very similar situation lol

Is the user H… S… the good path?

Type your comment> @gverre said:

Is the user H… S… the good path?

That’s the only user I’ve found so I assume so, but trouble is I can’t get anything more than his full name. Can’t get username or anything like that

Found only one user and every tool related to the attack hinted in the website are not working…

LOL…I just started it, it hasn’t been up for more than an hour and half, and the two bloods were taken already! ■■■■!

Found user s…a, but don’t see a way to utilize it

Rooted ! :slight_smile:

Some hints :

  • For user : google “AD attacks” and try to find valid users
  • For root : basic enum and then check for AD rights

PM if you need more help !

What? They can’t print money? Guess that would be a RICO[h] act violation.
(Inside job, er joke.)

Are you guys using a linux or a Windows attack box?

kali here

found one valid user but no roasting here

I got H*** S**** with an enum, but impossible to find his SID or his username… Any hints ?

Is AD atack is related to IPV6?

just observation… apart loren ipsum stuff there is also a bunch of random letters in tags. any use for them?

Found a valid user but cant find valid pass to go further. Must be missing something simple?

Type your comment> @olsv said:

just observation… apart loren ipsum stuff there is also a bunch of random letters in tags. any use for them?

The Team page is a very common place to get names from which to create some lists of username guesses. But not much in the 'ol lorem ipsum really.

One of the words that cewl gathered is actually a user, but I have no idea where the ■■■■ it came from.

Just do it!

Yes don’t use any tools. It’s overkill !

Note : Still struggle on the root part