DarkCorp Hack the Box Season 7 (Windows Insane)
by RedBlock - Saturday February 8, 2025 at 03:32 PM
started right now
i was able to trigger xss on cube but gave me server error

triying to reset password for that other subdomain
Reply
Somehow I'm able to use ldap search but can't run bloodhound sshuttle seems to have helped.
Reply
(02-09-2025, 03:20 PM)jonklem Wrote: Somehow I'm able to use ldap search but can't run bloodhound sshuttle seems to have helped.

ldapdomaindump also works but can't use that data in bloodhound...
Ban reason: Leeching. (Permanent)
Reply
Yeah, its really annoying. I can't get the bloodhound-python to work either. windapsearch.py ain't working too
Reply
http://172.16.20.2:5000/check this works with victor's creds. I thought maybe i could snag a hash with responder, but I already had to jump through hoops to get access to the network, i can't just make it fetch my ip.
Reply
(02-09-2025, 03:23 PM)0xbeef Wrote:
(02-09-2025, 03:20 PM)jonklem Wrote: Somehow I'm able to use ldap search but can't run bloodhound sshuttle seems to have helped.

ldapdomaindump also works but can't use that data in bloodhound...

I think you can try rusthound-ce (not that rusthound-ce only works with bloodhound-ce
Reply
where the heck is Victor's passwd?
Reply
(02-09-2025, 03:44 PM)jonklem Wrote: http://172.16.20.2:5000/check this works with victor's creds.  I thought maybe i could snag a hash with responder, but I already had to jump through hoops to get access to the network, i can't just make it fetch my ip.
try ligolo listener, http-ntlm-auth
Reply
Anyone was able to get the NTLM hash with responder?
Reply
The POST request to 172.16.20.2/status contains a json. I don't know if we can inject commands there, the request is done via python requests. Just start a listener with ligolo pointing to your http server and modify the port of the json
{"protocol":"http","host":"drip.darkcorp.htb","port":"xxxx"} GET / HTTP/1.1 Host: drip.darkcorp.htb:8080 User-Agent: python-requests/2.32.3 Accept-Encoding: gzip, deflate Accept: */* Connection: keep-alive

Edit: You can use ntlmrelay to obtain a shell from another account
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 22 8,706 06-25-2026, 02:15 PM
Last Post: hashxyz
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 6,907 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - VOLEUR.HTB - MEDIUM WINDOWS chain 1 6,427 02-09-2026, 07:07 PM
Last Post: 403Forbidden
  HTB - CERTIFICATE.HTB - HARD WINDOWS chain 0 2,637 02-09-2026, 04:49 PM
Last Post: chain
  Hack the Box FullHouse all 7 flags RedBlock 13 4,577 01-27-2026, 08:30 PM
Last Post: 00xx00



 Users browsing this thread: 1 Guest(s)