Official Love Discussion

Okay, it just happened, I made a decision to ask some help on this box… I got the user flag as user… Now I need to do some privilege escalation. Windows boxes are not my thing (yet). That’s why I want to do this one.

While reading the posts in this thread, I get the idea I took a different path. So let me explain a bit.

I’ve performed a port scan and with those details I’ve decided to check the source code of the logon page. While using my Google-Fu skills I’ve found an S–I bypass which give me access as a-----n on the a-----n-page. Because it’s a Windows box using a particular development language I was thinking about uploading a rev— s—l and a n-.–e because of a known b—ss up---- exploit in this tool. Via this way I got the user P----e and the user flag. While enumerating the directories and files I’ve found the username and password for the user on the a-----n-page, but I don’t need them because of my earlier step… And another one for P----e… but not sure if I can reuse this one and if I need this on as I am this user.

Uploading winpeas.exe and winpeas.bat are working for me, but running them not… that part didn’t give me any clue… So i decided to see if anyone had the same issues. While reading the posts before me I started thinking that I got another user account then others… especially because I saw something about checking privileges, policies and a certain hint about “Windows I*******r is not correctly installed.”…

So I am thinking I walked another path and I am stuck… Can anyone help me back on track again…