Search 🔎🖥️

TryHackMe|Anthem WriteUp\Walkthrough (English)


Anthem 

Room Link: https://tryhackme.com/r/room/anthem

==============================================================

  • sudo nmap -vv IP you have two ports 80 and 3398 which is default for RDP. Now start looking at every page that you can follow with a link on the website, then gobuster dir -w /usr/share/dirb/wordlists/common.txt -u http://IP -r you got a lot of folders. In robots.txt you found the password **********. There is another interesting folder that we couldn’t reach when following the links on the website which is /Umbacro. If you go to this folder, you will find a login page.
  • The domain for the website is obviously anthem.com.

  • To get the credentials you need to follow along and solve the questions. You need first to know the name of the administrator. On the home page, you can see an article that has a poem written about the administrator.

Click on read this article take the poem and search for it, you will get the name Solomon Grundy which in this case is the administrator’s name.

  • To get the email for Solomon see another email on the website and follow the pattern as the hint says. In we are hiring article there is an email

From this we get that the administrator’s email is SG@anthem.com. 

  • Now the search for the flags begins. The flags don’t have anything that tells you which number are they, so you try to fill each box. The flags all exist on the website, one on the page and the 3 others are on the source code.

    • At the home page you will find the 2nd flag in the source code, in the input element at the placeholder field. Because the search box is small you can’t see it ✨.

    • At the we are hiring page you will find the 1st flag in the meta element ✨.

    • From we are hiring page reach for Jane Doe profile, and you will find the 3rd flag.

    •  In the page “A cheers to our IT department” you find the 4th flag .

  • Now we have a password and a username we can use them to login to the system via RDP. Here it gave you a note that the box is not on a domain. So the username will be SG only, and the password is the password we found on the robots.txt. xfreerdp /u:SG /p:UmbracoIsTheBest! /v:IP

  • Once you are on the machine you will find the user.txt at the desktop ✨.

  • You need now to search for the admin password. It gave you a hint that it is hidden. So, choose from view to show the hidden files. Then, start your search from the C drive. You will find a folder called backup. Inside it there is a file called restore that you don’t have permission to read, so you will change this. Right-click on the file and select properties then go to security click on Edit.

Then you will get a window for “Permissions for restore” click on Add

Write SG then click check names and it will fill it automatically for you. Click Ok.

 

You will get back to the “permissions for restore” windos, check the full control box, click Apply close all the windows. You will be able to open the file and get the administrator’s password.

  • Now that you have the administrator’s password, search for cmd right click on it and choose run as administrator then cd C: >> cd Users\Administrator\Desktop and you will find the root.txt ✨.









Comments

Popular posts from this blog

TryHackMe|Blog WriteUp\Walkthrough (Arabic)

eJPTv2 Exam Review (Arabic)

TryHackMe|Blueprint WriteUp\Walkthrough (Arabic)