HackTheBox | Driver | Evil-WinRM + Local Exploit Suggester Technique 🖨️

Опубликовано: 22 Март 2026
на канале: SecAura
764
32

Today we root "Driver " 🖨️ , an "Easy" Windows machine from HackTheBox! - Like and Subscribe :)

⏱️Timestamps/Steps:
➡️ 00:00 - Intro
➡️ 00:10 - Port scan
➡️ 02:15 - Web Enumeration
➡️ 03:06 - Web app login
➡️ 03:52 - Web app analysis
➡️ 06:30 - Client side attack - explorer SCF smb exploitation
➡️ 09:37 - Cracking NetNTLMv2 Hash with hashcat
➡️ 11:00 - Loggin in with evil winrm
➡️ 11:40 - Migrating to Meterpreter shell to use module
➡️ 16:15 - post/recon/local_exploit_suggester (64bit)
➡️ 17:20 - Migrating to x86/32 bit process
➡️ 18:10 - post/recon/local_exploit_suggester (32bit)
➡️ 18:40 - Googling spoolsv.exe and finding PrintNightmare exploit/CVE
➡️ 19:45 - Exploiting printNightmare
➡️ 23:00 - NT auth / root :)
➡️ 24:15 - Outro
⭐️Link to box:
🔗 https://app.hackthebox.com/machines/387

For more Cyber security/hacking/pentesting beginner based content, check out the rest of my channel covering:
⭐️Web application security:
🔗Web Fundamentals for Cyber Security Series https://youtube.com/playlist?list=PLw...
🔗HackTheBox | Web/OSWE    • HackTheBox | Web/OSWE  
🔗OSWE "Build and Break it" Guide (Offensive Security Web Expert)    • OSWE "Build and Break it" Guide (Offensive...  
SQL injection, Server Side template Injection, XSS, remote code execution/Injection(RCE) XXE(XML Enternal Entity Injection) etc.

⭐️Linux Hacking + Priv esc -    • HackTheBox | Linux  
⭐️Windows Hacking + Priv esc-    • HackTheBox | Windows  
⭐️Active Directory Hacking -    • HackTheBox | ActiveDirectory  
⭐️GitHub: https://github.com/SecAuraYT/HackTheB...