To read the flag from the sysadmin's desktop using evil-winrm, run this command after you're inside the WinRM session:
type C:\Users\sysadmin\Desktop\user.txt
Submit the contents of user.txt ⇒ 01c920617c6470cdf46ba5861ce701c2
user.txt
Read the final flag from administrator’s desktop indicating full system compromise.
Submit the contents of root.txt ⇒ 79bf6f60850f10211c290be19ccf8b95
root.txt
Last updated 8 months ago
type C:\Users\Administrator\Desktop\root.txt