Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
In this lab, you will analyze a corporate Windows server that hosts multiple user accounts. It is suspected that one of them has misconfigurations that could allow privilege escalation and lead to full system control.
Your objective is to identify exposed credentials, gain remote access to the machine, and analyze the environment's configuration to determine whether you can become an administrator.
Follow these steps to begin:
1 https://storage.googleapis.com/cybersecurity-machines/elevation-windows-machine.ova
During your analysis, you may consider using:
Remember: sometimes you don't need a technical vulnerability—just a bad security practice.
Happy hacking!
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
owasp-a05-security-misconfiguration
ssh
red team
owasp-a07-identification-authentication-failures
hydra
winrm