Markup
Last updated
Last updated
What version of Apache is running on the target's port 80?
Answer: 2.4.41
What username:password combination logs in successfully?
Just tried basic default logins
Answer: admin:password
What is the word at the top of the page that accepts user input?
Answer: Order
What XML version is used on the target?
Answer: 1.0
What does the XXE / XEE attack acronym stand for?
Answer: XML external entity
What username can we find on the webpage's HTML code?
Answer: Daniel
What is the file located in the Log-Management folder on the target?
Put the rsa into a file on our machine
Login as daniel
Answer: job.bat
What executable is mentioned in the file mentioned before?
Answer: wevtutil.exe
Submit user flag
Answer: 032d2fc8952a8c24e39c8f0ee9918ef7
Submit root flag
Run winpeas
Under the section "Searching executable files in non-default folders with write (equivalent) permissions (can be slow)" We see
Which from the previous question we have looked at. Run Let's run netcat to connect back to us as admin.
Get nc.exe onto the target
Run it to get admin on the system
I had troubles getting the shell to pop, which apparently is common, the root flag is under: C:\Users\Administrator\Desktop\root.txt
Answer: f574a3e7650cebd8c39784299cb570f8