Fun Box with a lot to learn.
Initial to user was a bit tricky but also a nice learning process.
Root was a pretty straigt forward.
Thanks @jkr for this box!
DM me for some hints if you are stuck.
Initial Foothole was really hard for me, never worked with r***s, but learned a lot.
After that initial foothole to root in 30min.
Used the metasploit way, maybe someone can let me know how to do it without it.
Overall fun box.
Joined the juicy "froot" club finaly.
Thanks to @MrR3boot for the nice Box, learned alot about Fruits.
My advice would be not to download the new modern warfare or anything, while trying
to get into User. Make sure you get a smooth connec…
Can someone help me a bit?
I got the shell as p*****r via s*****r but no wan't echo any output.
If i type ls, it just shows ls but not the folders.
But I still can use cd, i just have no output for the commands.
Maybe I did something wrong with the…
I enumerated all ports, found 2 creds and some login pages.
Trying to get the A*** T**** via C***, im just getting "parse error: Invalid numeric literal at EOF at line 1, column 9"...Can I PM someone for a little hint?
Can I PM someone the B****4 encoded *W of the Admin account from m*******g?
I think i'm on the right track but i don't no if some encoding is screwing me.
Nice box, thanks to @L4mpje
My hint for Root:
To think to complica…
Got root shell!
Awesome box, learned a lot about Windows enumeration & priv esc.
Also learned new tricks with I******t and M*-**L.
Thanks to @DarkNight2019 for some hints with initial shell.
Feel to PM me if you need help with the box.
nmap shows there is a a****e T*** W***s page, but I cant reach it with my browser or curl, it just keeps connecting and then timeout...But I can reach the page at port *000, seems strange to me. I am on VIP btw.
Somebody else got this …
It's my first box which I try. Found f** got m** and A*****.z** via b***** mode, so they dont get corrupted. Found some credentials inside m**, but they don't seem to work.
Can I DM someone to get a little hint and see if the credentials are the cor…