Recon
- n00bs Table
The easy-points boxes: a flag sitting in an SNMP sysLocation field, and two backdoor ports that handed out flags over netcat.
- SqLSleuth
A SQL injection login bypass opened a recon trail of hidden directories, DB creds, and a riddle pointing at combining encoded values into a PDF. Co-worked with ZyWAC.
- SMB
Enumeration of an SMB host: protocol, encryption, domain, and SIDs. Recon only, no flag in my notes.
- Finger
An exposed finger service leaked a user, and that user’s plan field held the flag.