Dropzone

People say :
“It’s easy, but not THAT easy…”

LOL :slight_smile:

20h live and only 9 users have user and root. Quite surprising for 30p. machine …
Interesting box. I’m getting closer, but still not yet there.

i had issues yesterday where the box was hung. scan just sat there hours then completed with nothing. On top of that all the user resets and that is on a vip connection. Can only imagine the free box.

i have good stuff already. Trying figure out how to execute code. Have idea, but need to verify.

A big issues yesterday I was having was that while I was scanning the box got reset & kept messing it up. Keep your eyes open for ppl resetting

I’m VIP and it’s really hard to get something out of nmap on this box !
The big amout of reset is not the only issue over here. Need to figure out how to bypass firewall

@jugulaire said:
I’m VIP and it’s really hard to get something out of nmap on this box !
The big amout of reset is not the only issue over here. Need to figure out how to bypass firewall

Maybe you scan it wrong?

This box drives me crazy. I gave up yesterday cause I was tired. I have exact version of Windows including patch level. List of services present and tones of other info. And still only hitting the wall …

@macw141 said:
This box drives me crazy. I gave up yesterday cause I was tired. I have exact version of Windows including patch level. List of services present and tones of other info. And still only hitting the wall …

Let’s do not forget about administrator hash which I have as well. WTF?!

Finding the needle in the needlestack :wink:

May sound silly, but Is bruteforcing any of the account hashes necessary?

@bagy said:
May sound silly, but Is bruteforcing any of the account hashes necessary?

Tried, not “rockable”, but it does not matter. Both - hash and password seems to be useless in these condition. Earlier comment about needle - I know this is IT, but how?

@eks said:
Finding the needle in the needlestack :wink:

Is there any pragmatic, logical way or just a matter of a “blind shot”.

finished the box ! PM if you need any hint

I’ve find the entry point but i don’t find a way to get into …

@haditux said:
finished the box ! PM if you need any hint

Too soon for hints friend - let them play a bit more :wink:

@rjesh said:
@haditux said:
finished the box ! PM if you need any hint

Too soon for hints friend - let them play a bit more :wink:

True :smiley:

i am afraid that i have to read the registers, is it so :astonished: ?

any direction for “File Not found!!! -241”

Is the intended way to get a shell? or to “iterative” the contents to learn the locations of the txts?