Today we root "Driver " 🖨️ , an "Easy" Windows machine from HackTheBox! - Like and Subscribe :)
⏱️Timestamps/Steps:
➡️ 00:00 - Intro
➡️ 00:10 - Port scan
➡️ 02:15 - Web Enumeration
➡️ 03:06 - Web app login
➡️ 03:52 - Web app analysis
➡️ 06:30 - Client side attack - explorer SCF smb exploitation
➡️ 09:37 - Cracking NetNTLMv2 Hash with hashcat
➡️ 11:00 - Loggin in with evil winrm
➡️ 11:40 - Migrating to Meterpreter shell to use module
➡️ 16:15 - post/recon/local_exploit_suggester (64bit)
➡️ 17:20 - Migrating to x86/32 bit process
➡️ 18:10 - post/recon/local_exploit_suggester (32bit)
➡️ 18:40 - Googling spoolsv.exe and finding PrintNightmare exploit/CVE
➡️ 19:45 - Exploiting printNightmare
➡️ 23:00 - NT auth / root :)
➡️ 24:15 - Outro
⭐️Link to box:
🔗 https://app.hackthebox.com/machines/387
For more Cyber security/hacking/pentesting beginner based content, check out the rest of my channel covering:
⭐️Web application security:
🔗Web Fundamentals for Cyber Security Series https://youtube.com/playlist?list=PLw...
🔗HackTheBox | Web/OSWE • HackTheBox | Web/OSWE
🔗OSWE "Build and Break it" Guide (Offensive Security Web Expert) • OSWE "Build and Break it" Guide (Offensive...
SQL injection, Server Side template Injection, XSS, remote code execution/Injection(RCE) XXE(XML Enternal Entity Injection) etc.
⭐️Linux Hacking + Priv esc - • HackTheBox | Linux
⭐️Windows Hacking + Priv esc- • HackTheBox | Windows
⭐️Active Directory Hacking - • HackTheBox | ActiveDirectory
⭐️GitHub: https://github.com/SecAuraYT/HackTheB...