Sizzle

This box was amazing, I learned a ton of stuff about Windows, Active Directory, PowerShell and a lot of other things. Thanks a lot for the amazing ride @mrb3n and @lkys37en :smiley:

Thix box is fucking fucking excellent!!! thanks!!! all you need is here thx to @IteXss

Glad you all enjoyed the box, the comments and feedback are humbling… just wait til the sequel ā€œFizzleā€ comes out :slight_smile: @lkys37en and I have plenty more in store for y’all !

Rooted!!

Gr8 box man…
Frustrated in few steps and able to solve them with google enum…

Got user.txt , onto root now - amazing box so far & learned a lot. 10/10

Remind me of this comment in a few days when im sleep deprived and out of coffee.

Edit: rooted - amazing box.

@backspace said:
Found user + creds and other authentication things… looking for a good place to use them :slight_smile:

In the same spot right now .

If anyone can help me with the initial step will be great

one of the best machine ever and a big thanks to @AGIRMP for helping me out

get root…pm for hints…

Can’t seem to get the initial foothold. I’ve found the share where I need to upload a file, know the type of file I need to upload but can’t seem to obtain write access. I’ve enumerated all open ports in search of the right credentials but can’t find anything but the username. If anyone could give me a nudge in the right direction I would appreciate it a ton.

Okay so even if S**M*p says a share is read only you might be able to upload files. Thanks @marine for the help!

Can anyone point me to the right direction? I have creds, user and password, and also a cert and other strange files. What’s next? I don’t know what to do with all these things. I need help.

Go back to your Nmap. results, have a look at what services are running . You have probably used the s*b services to get this far, but there are others that can be used for administration

Rooted, oh my god what a ride.
Congrats to the makers @mrb3n and @lkys37en .
Technically hard and realistic.
I knew i didn’t had the experience but i thought i should try and i made it with a little bit of help at the end.
I loved every step of the way.

10/10 rate for the box.

If only the machine list was full of boxes like this, people would actually learn.
Keep it coming guys i heard there is gonna be a sequel(?), ā– ā– ā– ā–  yeah.

Rooted. Very, very fun box!
Cheers to @mrb3n and @lkys37en for such an amazing box. I really enjoy these kind of windows boxes, that make you learn something new. A must do box

now i’ve a user a****a and a password and a cert , is their anyway to work out an initial foothold using linux?

anyone passed this ??
validate_required_fields’: path to client key is required (RuntimeError) ?

@mitoOo said:

anyone passed this ??
validate_required_fields’: path to client key is required (RuntimeError) ?

It means you haven’t provided a private key for the user.

I’ve managed to get a shell using linux only but I’ve gotten stuck. Not sure if Windows is required to go forward. I suppose not

I got stuck after finding the cred for a*****. Would appreciate if someone could give me a nudge.

Edit: Hmm. nvm, i got it. The lack of enumeration hit me in the back.

i’ve found a file as a****a which contains hashes , even after resetting thebox
cracked those hashes and got a password for each , but can’t login with either … any help?