Anthem
https://tryhackme.com/room/anthem
Open Ports:
- 80: http
- 135: msrpc
- 139: netbios-ssn
- 445: microsoft-ds
- 3389: ms-wbt-server
Gaining Access:
-
Found Admin name from the
poem
via google a. hence username: sg b. Password: inside/robots.txt
-
Connecting to machine:
User Flag:
Priviledge Escalation:
-
Do view hidden files a. Under
C:\
in backupb. Add permission to restore file
c. Inside restore file we find the passowrd to the Administrator
-
Moving to Admin a. Desktop >
Root Flag:
Miscellaneous Flags:
- 1st flag:
- 2nd flag:
- 3rd flag:
- 4th flag: