Official Escape Discussion

Sure, pm me

Any PE Scripts/tools can recommend? :laughing:

Can anybody give me a hint?

Sure, PM me

Can someone give some hints to how get PE to admin?

Only hint you need it to investigate the machine

1 Like

Got user flag: any hint for PE please.

If you needed to pass though a door that leads to the VIP room, but there was a three headed dog in front of you that asks for a ticket, how would you forge your own?

I sent you a message related to this topic, I hope this riddle is useful for anyone coming :heart:


can u give me some hint

Sure, pm me

Hey, I’m having a technical issue. Every time I try auth I get back KRB_AP_ERR_SKEW(Clock skew too great). I tried everything I could find on google but nothing seems to be of help. I checked multiple times and my time is the exact same as the box. If anybody had the same issue and managed to fix it please let me know how. Cheers.

I found some creds for a sql server. However the typical port for this type of SQL Database is filtered (ran nmap 3 times and cant communicate with that port). All the other ports are not showing signs of SQL either. Is this box broken maybe?

Try changing your OS system clock. You can get the time difference from nmap scan I think

I currently have the credentials for the sql account
There is SeImpersonatePrivilege, but I cannot elevate privileges
I don’t know what to do next

If there is no access restriction, the privilege escalation to admin will be much easier…

Reseting the box fixed the problem. A friend of mine had the same problem. So if you dont see a port which should be open, reset the box!

can someone give me a hint, i got a pdf use smbclient. Dont know if thats something valuable. Anyway im stuck please help!

how confusing!
it says " Logon failed for user …"
cuz of this it took me time to get the user flag

i rooted btw, escape from what?
though the name of box is related to its contents, im not sure this time

I’m pretty stuck at gaining admin on this machine. I’ve managed to gain access to Ryan from sql_svc, and I’ve found the PFX file, but I can’t seem to sign anything with it using SignTool. Any nudges?