Steel Mountain
Steel Mountain
Who is the employee of the month?
Bill Harper
Scan the machine with nmap. What is the other port running a web server on?
Take a look at the other web server. What file server is running?
Rejetto HTTP File Server
What is the CVE number to exploit this file server?
Use Metasploit to get an initial shell. What is the user flag?
Take close attention to the CanRestart option that is set to true. What is the name of the service which shows up as an unquoted service path vulnerability?
What is the root flag?
What powershell -c command could we run to manually find out the service name?
*Format is "powershell -c "command here"*
powershell -c "Get-Service"