@alg42 said:
I could use a nudge to see if I’m on the right path. I’ve got xp_ enabled and user.txt is mine. I’m trying to get a shell by uploading a file, I can see via tcpdump that my upload command is working but I get an error no matter where I try to write the file to that permission is denied. Am I on the correct path, can anyone message me a hint on where to upload?
I believe ,You can execute file without writing anywhere … I am a NOOB …beware
Well After Spending Much longer than I would like to admit on this box, I finally got root. I got hung up on many small things but learned a ton along the way. PM if anyone needs some hints
A good windows machine after a series of Linux ones under my belt. A good way to earn user though we have done it before. The reverse shell was nice in user. For root, I would suggest to give “Power” to yourself and then you will have what you want. Shoutout to @superfume for your brilliance in answering all the doubts I have.
P.S. execute what you have to get the Admin shell.
Finally rooted (shell). Big thanks to @Malone5923, @TheGrandPew, and @Baikuya for their much needed hints. Also a big thanks @mrh4sh and @egre55 for a good learning box. So much about windows I did not know.
As always, here are my pointers.
Pretraining: Yes, I have included something you should do before even looking into this box. I am a big fan of ippsec. Watch Gi***, Opt****, and Bas****.
Initial: Start with the known ports. For things that you find, one must look within to learn something worthwhile. Take some time to learn the different ways to authenticate a DB, specifically the two different ways related to OS. Impacket is your friend.
User: Gi*** is your guide. Impacket is your companion.
Root: Enumeration is key, especially if you have a ‘super mushroom’ lying around. For those wondering about the “uncles” reference that keeps cropping up, don’t think about it. When it is revealed to you, all will make sense. Impacket again can lead you over the finish line.
Again, if I have said too much, please let me know and I’ll edit this.
As always, PM me for more concrete hints. Don’t forget to tell me your progress so I don’t spoil it too much.
Finally! That was painful for me, I must have reread everyone’s post a dozen times. So many random things I kept messing up…hopefully I’ll remember. If anyone needs a hint, feel free to pm me.
getting these error when connecting to mssql using Im***** mssql*****.py
Sounds like an OpenSSL problem you have on your client machine, but hard to tell without seeing the command you are using exactly (don’t post here). The client could possibly be trying to use TLS 1.3
I’ve been trying to get a user shell (already have the user flag) but I can’t, everything I try either can’t be executed or is blocked by some sort of AV. Are we supposed to get a user shell to move forward or can you get root through x*******ll?
I’ve been trying to get a user shell (already have the user flag) but I can’t, everything I try either can’t be executed or is blocked by some sort of AV. Are we supposed to get a user shell to move forward or can you get root through x*******ll?
I’ve been trying to get a user shell (already have the user flag) but I can’t, everything I try either can’t be executed or is blocked by some sort of AV. Are we supposed to get a user shell to move forward or can you get root through x*******ll?
You don’t necessarily need shell as you have what you need already, but if that’s the approach you want to take then I’d leave the more common shell tools behind.