Today we root the Search 🔎 (Windows | Hard) machine from HackTheBox! - Like and Subscribe :)
⏱️Timestamps/Steps:
➡️ 00:00 - Port scan
➡️ 01:20 - Web enum
➡️ 01:45 - Web app enum
➡️ 02:20 - Explanation of extracting user names for kerberos user name enum
➡️ 03:30 - Extracting usernames for use in kerberos brute forcing
➡️ 06:40 - Extracting username/password from image in web page
➡️ 09:00 - Dumping kerberos ticket via GetUserSPNs.py
➡️ 10:30 - Cracking hash with hashcat
➡️ 13:30 - Password spraying cracked hash with usernames
➡️ 16:00 - Forensics analysis of excel file, getting passwords
➡️ 21:00 - Password spraying leaked password
➡️ 23:00 - Dumping a certificate file from SMB and cracking it
➡️ 27:20 - Using certificate to authenticate to web app /staff
➡️ 28:00 - Getting remote windows web shell
➡️ 33:35 - Using sharphound
➡️ 42:00 - Using bloodhound
➡️ 46:00 - Pwning BIR-ADFS-GMSA$ user via ReadGMSAPassword access
➡️ 50:00 - Invoking commands as BIR-ADFS-GMSA$
➡️ 53:00 - Leveraging BIR-ADFS-GMSA$ creds, and writeOwner perms over tristan.davies to change their password
➡️ 56:00 - Getting root.txt :)
➡️ 56:20 - Outro
Wadcoms: https://wadcoms.github.io
For more Cyber security/hacking/pentesting beginner based content, check out the rest of my channel covering:
⭐️Web application security:
🔗Web Fundamentals for Cyber Security Series https://youtube.com/playlist?list=PLw...
🔗HackTheBox | Web/OSWE • HackTheBox | Web/OSWE
🔗OSWE "Build and Break it" Guide (Offensive Security Web Expert) • OSWE "Build and Break it" Guide (Offensive...
SQL injection, Server Side template Injection, XSS, remote code execution/Injection(RCE) XXE(XML Enternal Entity Injection) etc.
⭐️Linux Hacking + Priv esc - • HackTheBox | Linux
⭐️Windows Hacking + Priv esc- • HackTheBox | Windows
⭐️Active Directory Hacking - • HackTheBox | ActiveDirectory
⭐️GitHub: https://github.com/SecAuraYT/HackTheB...
⭐️Link to box:
🔗 https://app.hackthebox.com/machines/410