type
status
date
slug
summary
tags
category
icon
password
Catagory
Materials
Retired
Retired
Due date
Jan 16, 2024 05:31 AM
Status
Belong in

Progress

Recon

Scan the machine

notion image
notion image

How many ports are open with a port number under 1000?

4

What is this machine vulnerable to

notion image

Gain Access

gain a foothold

notion image
notion image
notion image
gain the initial foothold
notion image

gain a foothold with the normal shell

步驟與前面一樣,只是為了後續要示範將一般的shell轉成 meterpreter shell設定一下payload
notion image
notion image
notion image
notion image

Escalate

privileges escalation - upgrade normal shell to meterpreter shell

shell_to_meterpreter
notion image
notion image
notion image
notion image

Cracking

crack the hash using john

notion image
notion image

login the user

notion image

Find flags

notion image
notion image

Flag1? This flag can be found at the system root.

notion image

Flag2? This flag can be found at the location where passwords are stored within Windows.

notion image

flag3? This flag can be found in an excellent location to loot. After all, Administrators usually have pretty interesting things saved.

notion image

Reference

 
Tools - Burp SuiteBFS&DFS Searching the outlook folder