Forest

aha found it! powershell skills very lacking, cool box though. this s**l is still super slow. Is this shell.exe just a trap? haha

Type your comment> @Slxyre said:

Dog isnā€™t taking the .zip
Isnā€™t outputting anything at all

Had same issueā€¦For this box you need to use an older ingester.
2.0.3.1 is the version I used because of earlier posts.

did an entire directory of documents dissapear or am i going crazy?

edit: i now realize what that folder was and what I have to do ha.

Can someone help with root. I got bloodhound to work not really sure where exactly to go from here. I know I should probably do some persistance work or maybe just go into privesc? Either way I donā€™t know exactly how to do that

Is there someone who can help me to find another way to root than the dog? I canā€™t create a dog map because of a reccurent import errorā€¦(bad json file). So Iā€™m stucked to find my way through the forest. Thanks a lot ?

^^ +1 . I see that some have mentioned to get root you need to exploit ceus but I am not sure how to find out which exploit I need to use. I tried for a long while last night, created new domain user but seemed to have the same priv as the svc-*** user.

Do you need to increase privilages somehow for your created us**? Tried to add to admin group but perm denied.

I just need a tiny nudge if anyone has time to pm me. ty.

I didnā€™t experiment with blh yet either, but i see that may be the answer I need. this box is for sure a wake up call not to neglet windows ha.

Blh 's the dog who made me sick ^^

some impacket scripts for code exec didnā€™t workā€¦ but Evil-*m did most of the job for user and root for me (i didnā€™t have to make a shiny expensive ticket)

@h74n i was in last night with ev**-** cruising around for what seemed like hours. My shell was super slowed and delayed, if I typed ā€œpower****lā€ and started that it went a little faster. I tried a bunch of things.

I am researching bloh**** now. just lost my main parrot vm though and hadnā€™t snapshot it in a bit so I lost all my notes for Forest. I canā€™t even rememer what the password was for svc-al*. haha. I had it in a text file.

Four sleepless nights and I finally got root. What took it so long? Well, it looks like I was using outdated? version of Pā€¦Vā€¦ which was throwing errors despite correct commands.

Kudos to creators! It was a nice experience with tons of reading and watching. I wish there were more boxes like this.

Hope I donā€™t spoil anything, because all of this have already been mentioned in this thread. I just want to summarize them in one place and leave some hints for those who struggle with errors .

For user:
There are two impā€¦t scripts and one evil that will help you to get a shell.
For root:

  • Watch @ippsec videos about privilege escalation in AD and learn how to tame a dog. It will significantly simplify your life. There is also a python version that also works, but pay attention to the version youā€™re using(It should be no greater than version of the tool you have) and output of the command (it will guide you). Python version drops errors if installed via pip, so go get the source and switch to the particular version.
  • Examine dogā€™s output and search for the shortest path to what you want so much. Get yourself familiar with rights and pay attention to the hints that tool provides. Donā€™t hesitate to create an empowered user to avoid messing with other guys doing this box. Hint that tool provide needs to be modified a bit, so go get yourself familiar with other options available for the command and make sure youā€™re executing it from the right user.
  • Donā€™t waste time and with cat (you need to be able to log in) or without it grab a little thingie that will finally give you what you want.

Type your comment> @Slxyre said:

Dog isnā€™t taking the .zip
Isnā€™t outputting anything at all

having this same problem, did you ever find a solution?

@bugeyemonster the same issue here. Maybe you can try to dzip and import file by file. I canā€™t go further because of that. I heard that there a python way to get through too. Had anyone a hint about this specific case?

anyone got:
ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)
on the ps version of Mimi?
grrrr :expressionless:

@bugeyemonster @damocles74 use version 2.0.3.1

Can someone gives me a nudge about root. I follow the hound, create someone but cannot assign group. An error occurs. Am I on a right path? Feel free to PM plz. If this is a spoil please remove it. Thxā€¦

Sweet Baby Root!!! Thanks @egre55 & @mrb3n for a fun AD challenge. Took a little reading and reviewing of some code of the tools that could help find those tracks but let you down as they havenā€™t kept up with the Dog!!.

Thank God, I got root after 2 days of brainstorming, researching and fiddling around with the tools. Not an AD Guru but definitely this helps getting that experience to become one.

Hereā€™s my hint:
For User: Use impacket, now prepare yourself a turkey and ROAST it, give your friend Johnny Bravo a piece of that turkey.

For Root:
Let your dog sniff for information.
Use that info and give your little brother permission to go out and play with his friends. Listen to your neighbors secret, to get the recipe on how to make a hashbrown. Once done, pass some hashbrown to your neighbor to see if itā€™s good or bad.

PM for nuggets

Finally rooted. This is my first box. Thanks for everyone on this forum :wink:

Hey guys I need help in PM for root user,
I run the ā€œdogā€ and find the path.
After I try Ec*** _dirkjan without any successā€¦
I create a new user whith DCS*** right but Iā€™m not able to grab the passwords.
I donā€™t know what I have done wrongā€¦
So if any one can give me some tips in private