Devel is a very fun box that gets into reverse shells and default web pages. Start with an nmap scan.
Note the anonymous login and the IIS versionLook up an msfvenom payload that will match your OS version and architecture Upload the reverse shell script to the web pageStart a reverse shell listener with netcatOR use metasploit as the listenerThis is the webpage of the boxNavigate to the uploaded shell to execute itNow back on our listener we should have a shell, see what info you can getHmmmmm not rootOkay we need to escalate our privilegeIf you are in meterpreter background the session and run the local exploit suggester post moduleTry using some and see what you get, here we may have just got root with the kitrap0dNICE!Finish it off by submitting the flags