Nest

yes so :Pa…

Type your comment> @Boomer697 said:

So After many hours of rummaging around I discovered a certain hash and soon after a certain path to a certain user and his files. My question is how much vbscript do I need to know in order to achieve what I think needs to be achieved?

this box was my first time looking at a vb code and i got the user in 2 hours

Nice machine after all.

@HTB Admins: Please dont do more drugs - whoever rated this easy is a) stoned or b) a troll

Rooted
PM for nuggets

@Warlord711 said:
Nice machine after all.

HTB Admins: Please dont do more drugs - whoever rated this easy is a) stoned or b) a troll

haha I rated it as easy when I submitted the machine, because I’d been battling with boxes marked as easy and medium that I felt were way harder than this. But yeah enough people have said its too hard for an easy machine, so next time I’ll classify my submissions a bit higher on the scale :slight_smile:

I gotta say though I don’t really see how it could be much easier than this without just being stupidly easy and everyone getting through it instantly. In which case what’s the point in it even existing?

could someone please help me with the VB reversing? it’s driving me insane

@VbScrub said:

I gotta say though I don’t really see how it could be much easier than this without just being stupidly easy and everyone getting through it instantly. In which case what’s the point in it even existing?

Have you seen Blue, Granpa, Grandma ? :smile:

@GlenRunciter said:

could someone please help me with the VB reversing? it’s driving me insane

If you have a windows box with visual studio, its super easy. If you dont you need to be a bit more creative but there are online tools which can run it for you - then you just need to put in the right values and it spits out the answer.

No I’ve not seen those. I only joined about 6 months ago, only tend to do windows machines, and don’t have VIP

@TazWake said:

@GlenRunciter said:

could someone please help me with the VB reversing? it’s driving me insane

If you have a windows box with visual studio, its super easy. If you dont you need to be a bit more creative but there are online tools which can run it for you - then you just need to put in the right values and it spits out the answer.

I do have a win box + VisualStudio and I’m trying to figure it out, it’s been about 8 years since I last opened Visual studio lol I’ll try and google around for an online way. thanks!

@VbScrub thank you very much. Amazing box that requires various skills.
Would never call it easy, mostly because it covers many aspects of pentesting (enumeration, reversing, code reading, encryption)
Had real fun solving it

any reason why I cannot see the C*** directory?

nevermind… that just a little annoying…

Can somebody please gimme a hint for foothold, or a link to a good site on smb/windows enum? This is my first windows machine and all I got is locked down so far.

I found low and high port, low seems locked down, could only do some minor share enum. I know I can go several places with high port but cannot read anything afaik.

Only idea I got left is sniffing creds, but I don’t think that works in this scenario.

EDIT: Well… I’m just a bit daft it seems. Right after writing this I though: “Have I really tried to actually do anything with what I got from low port?” Turns out I got spooked by the password prompt. ^^

Takeaway: Even if you think its locked down, try it anyway.

Rooted this machine the intended way. Feel free to hit me up with questions.

Type your comment> @element4ry said:

Rooted. Quite a fun box, but also a bit frustrating at times.

Started it thinking it was a super easy machine, but the ratings seem heavily flawed due to the unintended method that got fixed.

For user, I started off on the wrong foot(hold). There is a lot of enum to do.
Small hint:Make sure you check all files for anything that seems interesting. You may get to places you didn’t think you could reach.

For root, I found things to be relatively straightforward. You can find everything you want simply on the machine. ‘If you can’t figure it out get some help to get all info and try some more’. From there it’s pretty much enumerating and repeating actions.

Thanks to the maker :)!

I think this is the best hint for who are still confused with the ‘ghost file’.

Type your comment> @keyos1 said:

@VbScrub thank you very much. Amazing box that requires various skills.
Would never call it easy, mostly because it covers many aspects of pentesting (enumeration, reversing, code reading, encryption)
Had real fun solving it

Yeah that’s fair. I just thought if it only had one of those things, it may as well just be a standalone Challenge file on here rather than an entire Machine. Also I guess I figured that most of the community here would be familiar with all of those areas you mentioned, so it should be relatively easy (aside from the “empty” file, I thought that might trip a few people up).

Learned a lot with this machine, rooted intended and unintended.
Thanks for the machine @VbScrub i really liked it a lot.

Spoiler Removed

Type your comment> @asteer1 said:

Type your comment> @Boomer697 said:

(Quote)
this box was my first time looking at a vb code and i got the user in 2 hours

Managed to figure it out in the end with some help, call me a noob but that did not come easily lol

OK, done the “right” way, now. That was not easy. Not for me. But it was fun! Props to the creator! @VbScrub