UnderTheWire - Groot

https://underthewire.tech/grootarrow-up-right

Groot1

Desciption

The password for groot2 is the last five alphanumeric characters of the MD5 hash of this system’s hosts file.

NOTE: – The password will be lowercase no matter how it appears on the screen.

Solution

➜ ssh groot.underthewire.tech -l groot1 # Password: groot1

PS C:\users\Groot1\desktop> $hostsFile="$ENV:SystemRoot\System32\Drivers\etc\hosts" ; $hostsFile
C:\Windows\System32\Drivers\etc\hosts

PS C:\users\Groot1\desktop> $hostsFileHash = (Get-FileHash -Algorithm MD5 -Path $hostsFile).Hash ; $hostsFileHash
6EEC08310BD5328FFC8FB72CD8E464C3

PS C:\users\Groot1\desktop> $hostsFileHash.Substring($hostsFileHash.Length - 5).ToLower()
464c3
circle-check


Groot2

Desciption

The password for groot3 is the word that is made up from the letters in the range of 1,481,110 to 1,481,117 within the file on the desktop.

NOTE: – The password will be lowercase no matter how it appears on the screen.

Solution

circle-check


Groot3

Desciption

The password for groot4 is the number of times the word “beetle” is listed in the file on the desktop.

Solution

circle-check


Groot4

Desciption

The password for groot5 is the name of the Drax subkey within the HKEY_CURRENT_USER (HKCU) registry hive.

NOTE: – The password will be lowercase no matter how it appears on the screen.

Solution

circle-check


Groot5

Desciption

The password for groot6 is the name of the workstation that the user with a username of “baby.groot” can log into as depicted in Active Directory PLUS the name of the file on the desktop

NOTE: – If the workstation is “system1” and the file on the desktop is named “_log”, the password would be “system1_log”. – The password will be lowercase no matter how it appears on the screen.

Solution

circle-check


Groot6

Desciption

The password for groot7 is the name of the program that is set to start when this user logs in PLUS the name of the file on the desktop.

NOTE: – Omit the executable extension. – If the program is “mspaint” and the file on the desktop is named “_log”, the password would be “mspaint_log”. – The password will be lowercase no matter how it appears on the screen.

Solution

circle-check


Groot7

Desciption

The password for groot8 is the name of the dll, as depicted in the registry, associated with the “applockerfltr” service PLUS the name of the file on the desktop.

NOTE: – The password will be lowercase no matter how it appears on the screen. – If the name of the dll is “abc.dll” and the file on the desktop is named “_1234”, the password would be “abc_1234”.

Solution

circle-check


Groot8

Desciption

The password for groot9 is the description of the firewall rule blocking MySQL PLUS the name of the file on the desktop.

NOTE: – If the description of the rule is “blue” and the file on the desktop is named “_bob”, the password would be “blue_bob”. – The password will be lowercase no matter how it appears on the screen.

Solution

circle-check


Groot9

Desciption

The password for groot10 is the name of the OU that doesn’t have accidental deletion protection enabled PLUS the name of the file on the desktop.

NOTE: – If the name of the OU is called “blue” and the file on the desktop is named “_bob”, the password would be “blue_bob”. – The password will be lowercase no matter how it appears on the screen.

Solution

circle-check


Groot10

Desciption

The password for groot11 is the one word that makes the two files on the desktop different.

NOTE: – The password will be lowercase no matter how it appears on the screen.

Solution

circle-check


Groot11

Desciption

The password for groot12 is within an alternate data stream (ADS) somewhere on the desktop.

NOTE: – The password will be lowercase no matter how it appears on the screen.

Solution

circle-check


Groot12

Desciption

The password for groot13 is the owner of the Nine Realms folder on the desktop.

NOTE: – Exclude the Administrator, the Administrators group, and System. – The password will be lowercase with no punctuation no matter how it appears on the screen. For example, if the owner is “john.doe”, it would be “johndoe”.

Solution

circle-check


Groot13

Desciption

The password for groot14 is the name of the Registered Owner of this system as depicted in the Registry PLUS the name of the file on the desktop.

NOTE: – If the Registered Owner is “Elroy” and the file on the desktop is named “_bob”, the password would be “elroy_bob”. – The password will be lowercase no matter how it appears on the screen.

Solution

circle-check


Groot14

Desciption

The password for groot15 is the description of the share whose name contains “task” in it PLUS the name of the file on the desktop.

NOTE: – If the description is “frozen_pizza” and the file on the desktop is named “_sucks”, the password would be “frozen_pizza_sucks”. – The password will be lowercase no matter how it appears on the screen.

Solution

circle-check

All Passwords

Username
Password

groot1

groot1

groot2

464c3

groot3

hiding

groot4

5

groot5

destroyer

groot6

wk11_enterprise

groot7

star-lord_rules

groot8

srpapi_home

groot9

call_me_starlord

groot10

t-25_tester

groot11

taserface

groot12

spaceships

groot13

airwolf

groot14

utw_team_ned

groot15

shoretroopers

Last updated