02-11-2025, 06:56 AM
This is helping alot but would love a full writeup
Ban reason: Leeching | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you feel this is incorrect. (Permanent)
|
DarkCorp Hack the Box Season 7 (Windows Insane)
by RedBlock - Saturday February 8, 2025 at 03:32 PM
|
|
02-11-2025, 06:56 AM
This is helping alot but would love a full writeup
Ban reason: Leeching | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you feel this is incorrect. (Permanent)
02-11-2025, 06:32 PM
can somebody explain me how to use sshuttle and nmap for scanning internal networking in combination please
02-11-2025, 06:34 PM
I have shared the writeup
Have a look on that once! https://raidforums.as/Thread-DarkCorp-Ha...ox-writeup
02-11-2025, 08:16 PM
(02-11-2025, 06:34 PM)LostGem Wrote: I have shared the writeup Good write up. Sad part it is the unintented way with the bruteforce. Really wish someone can share how to move avec ntlmrelay ldap/smb shell
Ban reason: Leeching | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you feel this is incorrect. (Permanent)
02-12-2025, 05:16 AM
why are you all so worrying about "intended road by some random nigger".
Your final objective, almost always -- is to reach Domain Admin. After that you can do whatever you wanted. And if you can shorten your path -- it a plus for you. After getting to 'taylor.b.adm' you simply abuse SharpGPOAbuse to create scheduled task -> gain SYSTEM -> dump hashes -> forge Silver/Golden tickets -> with Silver ticker become Admin on WEB-01 (or any system) -> and this Corp is finished off. But no... instead you want a long-term mind masturbation...
02-12-2025, 04:05 PM
(02-12-2025, 05:16 AM)mazafaka555 Wrote: why are you all so worrying about "intended road by some random nigger". Because some of us prefer learning something. That's the point of using this platform. You don't learn if you skip half of the process by pasting the hash in evilwinrm to obtain the flag, but to each their own.
02-12-2025, 04:53 PM
(02-12-2025, 04:05 PM)spamdegratis5 Wrote:(02-12-2025, 05:16 AM)mazafaka555 Wrote: why are you all so worrying about "intended road by some random nigger". exactly, i don't give a shit about points on htb just want to learn new things
02-12-2025, 06:19 PM
thank you all!!
02-12-2025, 07:19 PM
(This post was last modified: 02-12-2025, 08:00 PM by spamdegratis5.)
(02-10-2025, 11:32 PM)spamdegratis5 Wrote:Someone just confirmed the first part. Instead of spawning ldap shell, remove the interactive part and add the flag to use dns entry, then use krbrelayx to obtain a certificate using adcs. This blog contains the part about enrollment https://www.synacktiv.com/en/publication...-krbrelayx and the format dns entry should have.(02-10-2025, 10:55 PM)samuelballsiu1 Wrote:(02-10-2025, 10:39 PM)hint80h Wrote:(02-10-2025, 09:45 PM)4yhg5y72jffg820j3f Wrote: Here is my PrivEsc from taylor.b.adm to Domain Admin. I didn't know any of these horrific PowerShell GPO commands, ChatGPT helped a lot here. However, using those means there is no SharpGPOAbuse dependency and thus no need to circumvent Defender on the DC. Edit: Check with netexec -M adcs module the location of the ADCS
02-12-2025, 08:54 PM
(02-12-2025, 07:19 PM)spamdegratis5 Wrote:(02-10-2025, 11:32 PM)spamdegratis5 Wrote:Someone just confirmed the first part. Instead of spawning ldap shell, remove the interactive part and add the flag to use dns entry, then use krbrelayx to obtain a certificate using adcs. This blog contains the part about enrollment https://www.synacktiv.com/en/publication...-krbrelayx and the format dns entry should have.(02-10-2025, 10:55 PM)samuelballsiu1 Wrote:(02-10-2025, 10:39 PM)hint80h Wrote:(02-10-2025, 09:45 PM)4yhg5y72jffg820j3f Wrote: Here is my PrivEsc from taylor.b.adm to Domain Admin. I didn't know any of these horrific PowerShell GPO commands, ChatGPT helped a lot here. However, using those means there is no SharpGPOAbuse dependency and thus no need to circumvent Defender on the DC. Yep. And after that you simply auth with acquired cert, getting WEB-01 machine acc hash, forge Silver ticket (once again, but longer...) and dump hashes or auth as local Admin on WEB-01. But it's sooo long for the final objective of "Hunting Domain Admins" on the Corp Network. Actually, i'm surprised ... why `taylor.adm` account didn't locked-up after 3-5 password tries (as it should be!). Probably fuckup of the box creators. Anyways, you can still brute this same user via ssh. So, patches should fix this 2 parts i think. |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 22 | 8,706 |
06-25-2026, 02:15 PM Last Post: |
||
| HTB Eloquia User and Root Flags - Insane Box | 13 | 6,907 |
03-27-2026, 06:14 PM Last Post: |
||
| HTB - VOLEUR.HTB - MEDIUM WINDOWS | 1 | 6,427 |
02-09-2026, 07:07 PM Last Post: |
||
| HTB - CERTIFICATE.HTB - HARD WINDOWS | 0 | 2,637 |
02-09-2026, 04:49 PM Last Post: |
||
| Hack the Box FullHouse all 7 flags | 13 | 4,577 |
01-27-2026, 08:30 PM Last Post: |
||