OSCP Prep - ServMon Windows - Part 1 Recon - Initial Foothold

Опубликовано: 05 Август 2026
на канале: ScriptKiddie
210
7

What's going on Matt! Sorry this recording took so long. I blame the freaking virus.

This time I covered a windows machine but I was only able to get the system access. On the next recording I will cover windows privilege escalation in general using this machine.


Timestamp
00:00 Intro
03:10 Ping to identify OS
04:25 nmap scanning
06:40 Obsidian note setup
10:30 Let's tap port 80. Just because.
12:30 Searchsploit nvms - Directory Traversal
13:55 exploit attempt fail
16:30 Notetaking Obsidian
23:50 Nmap finished // notetaking
29:30 Process of elimination
29:50 FTP
34:19 Introducing gitbook. Create one Matt!
35:55 SMB, smbmap/smbclient
38:00 gobuster on port 80, Failed, Tried ffuf
40:48 Process of elimination using netcat.
45:10 Port 8443 HTTPS
47:45 Potential Privilege escalation
54:40 Directory Traversal doesn't work from the url or curl. So use burpsuite!
55:08 Install foxyproxy.
1:00:23 Using Burp
1:01:01 Directory Traversal exploit worked!
1:02:10 Retrieved passwords
1:05:50 curl cht.sh/hydra to check syntax
1:08:35 bruteforce ssh using hydra
1:13:30 I don't know what I am doing.
1:24:44 My wife called me (Delete it)
1:25:11 Wrap it up. Done for the day.


Useful commands:
nmap sC -sV -p -oN recon/nmap_full -Pn 10.10.10.184
curl cht.sh/hydra
hydra -l nadine -p passwords.txt 10.10.10.184 ssh





References:
https://kwaky808.gitbook.io/pen-testi...
https://book.hacktricks.xyz/