[FORTRESS] Context

Type your comment> @idevilkz said:

stuck on ZIP file if anyone has any nudge ?

check the code inside the zip, you will spot the vulnerability

Stuck on flag 5, can anyone give me a nudge? After establishing foothold, I feel as if Iā€™ve extorted all attempts of enum and canā€™t find anything to get to flag 5.

Can we please vote a reset, there is so much garbage in the C directory that I question if its been removed

Can anyone give a nudge on flag 5? Canā€™t seem to do anything after finding karls creds

I started this Fortress months ago, and got stuck on Flag 5 and the zip file. Been reviewing it and canā€™t seem to find something concrete. Could someone PM me with a nudge?

I have done this fortress yesterday, and it is really amazing. 6th and 7th flags , take much time for me to know they correct attack vector for each.

Anyway, its really worthy to spend time on it.

1 Like

hi, i am stuck in the 6th flag i have mssql creds and entered mssqlserver but i have an error when i use this query to get the flag: select content from [WEB\CLIENTS].clients.sys.assembly_files where name like ā€˜%clientsbackup.dll%ā€™ but i got the following error: dsp_desc_bind: Memory allocation failure for column #1 NOTE: i used sqsh cli to connect to mssql server anyone help me please!

Am I suppose to get the flags in order? Because I got the first and second flags and then got ā€œnt authority\systemā€ and the last flagā€¦

Give me any nudge for fourth flag of contextā€¦ PM me on discord my discord - Nimoo#9980

any nudge for 4th flag?

.

click around in the UI that you find/found - click on every button

Any hints for Flag 5? I have the username for mssql but brute-force did not work - did I miss something?

Hello there everyone.

After completing this Fortress, here are some pointers for those who are still struggling:

  1. Thereā€™s the intended way and, of course, the faster and boring unintended one.
  2. The SQL-i does not need to take ages to complete if you know what to do (you do not even need s****p for that).
  3. No reversing needed, at least I wouldnā€™t call it that.

Good luck!

2 Likes

Hey can anyone nudge me for the ā€œHave we met before?ā€ flag? Not sure what Iā€™m missing. Iā€™ve logged in as the user to their email and looked around and canā€™t find anything. I see emails from other pentesters so tried requesting a reset but no dice.

Update: Figured it out

Anyone here for flag6, i got the last one but somehow missed flag6? thank you

I found the credentials to login to the database but i am not able to execute any queries.

Can someone help me ?

nvm got it

Just missing ā€œItā€™s not a backdoor, itā€™s a featureā€. Not yet sure what to look for.

Can someone give a hint for the 3rd flag apart from "Click everythingā€™? I have logged in the Mail!

Found it !

Any nudge on how to get the 6th flag?

Any nudge for the 6th flag?