This challenge involves compromising a Windows host exposed via RDP, starting from a passwordless kiosk account. After enumerating the service with Nmap and bypassing NLA, access to a restricted desktop is obtained. By escaping kiosk mode, extracting encrypted credentials from a third-party application (Remote Desktop Pro), the administrator password is recovered, leading to privilege escalation and full administrative access.
# tag: RDP
Escape