

Info about Anthem

Exploit a Windows machine in this beginner level challenge.

This task involves you, paying attention to details and finding the 'keys to the castle'.
This room is designed for beginners, however, everyone is welcomed to try it out!

Enjoy the Anthem.

Active reconnaissance

Port scan

Perform a quick general scan on all ports.

sudo nmap TARGET_IP -n -p- -sS -Pn -vvv --open --min-rate 5000 -oN nmap_scan
80/tcp   open  http          syn-ack ttl 125
3389/tcp open  ms-wbt-server syn-ack ttl 125


Perform a deep scan with common scripts only on ports we are interested in.

sudo nmap TARGET_IP -sCV -p 22,80 -oN nmap_enum


Windows; CPE: cpe:/o:microsoft:windows

Port 80 - Umbraco

tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)

|http-title: - Welcome to our blog
| http-robots.txt: 4 disallowed entries
|/bin/ /config/ /umbraco/ /umbraco_client/

Pasted image 20250107114105.png


Its empty


The same main page


The same main page


We have a login page
Pasted image 20250107114248.png|500

What's the name of the Administrator

It's the author of the poem
Pasted image 20250107150044.png

Port 3389 - RDP

tcp open ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info:
| Target_Name: WIN-LU09299160F
| NetBIOS_Domain_Name: WIN-LU09299160F
| NetBIOS_Computer_Name: WIN-LU09299160F
| DNS_Domain_Name: WIN-LU09299160F
| DNS_Computer_Name: WIN-LU09299160F
| Product_Version: 10.0.17763
|_ System_Time: 2025-01-07T14:18:27+00:00
| ssl-cert: Subject: commonName=WIN-LU09299160F
| Not valid before: 2025-01-06T14:15:34
|Not valid after: 2025-07-08T14:15:34
ssl-date: 2025-01-07T14:19:27+00:00; +1s from scanner timeH


Port 80 - Umbraco


After login with credentials
We have:
Pasted image 20250107150414.png

What is flag 1?

Pasted image 20250107153528.png

What is flag 2?

Pasted image 20250107153005.png

What is flag 3?

Pasted image 20250107153143.png

What is flag 4?

Pasted image 20250107153357.png

Port 3389 - RDP

Gain initial access to the machine, what is the contents of user.txt?

Pasted image 20250107160402.png

Can we spot the admin password?

In the hidden folder
Pasted image 20250107165559.png
Click on setting of restore file and add our user to the permissions file.
Pasted image 20250107165939.png
And open the file:
Pasted image 20250107170052.png

Privilege escalation

Login to the administrator account

xfreerdp /u:Administrator /p:ChangeMeBaby1MoreTime /v:
Escalate your privileges to root, what is the contents of root.txt?

Pasted image 20250107170456.png