Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
smb
cybersecurity
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
smb
cybersecurity
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
In this lab, you will explore a corporate Windows server, identify exposed credentials, discover a key user's password through brute force, and take advantage of a misconfiguration to escalate privileges and become an administrator.
In this lab, you will learn:
Hydra
and rockyou.txt
for brute force attacksFollow these steps to begin:
You're facing a Windows server with multiple users. Your goal is to gain administrator privileges by accessing the system as the only user with a dangerous configuration.
Find the IP address of the ELEVATION 2 machine.
Use tools like nmap
, netdiscover
, or arp-scan
.
Perform a brute force attack using Hydra.
Check if you can escalate to Administrator.
Find the final flag.
Remember: sometimes you don't need a technical vulnerability—just a bad security practice.
Happy hacking!
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
smb
cybersecurity
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
smb
cybersecurity
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
smb
cybersecurity
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
smb
cybersecurity
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
smb
cybersecurity
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
smb
cybersecurity
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm