Posts

Showing posts with the label Bloodhound

HackTheBox - Endgame: POO - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Endgame P.O.O network hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the P.O.O network as the victim systems. After connecting to the Hack the Box network via VPN, we see that our first target is located at 10.13.38.11. Scanning and Enumeration We'll start by scanning for open ports with Nmap : nmap -T4 -p- 10.13.38.11   Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: nmap -sV -T4 -p80,1433 10.13.38.11 The IIS server version is 10, which probably means we're up against a Windows 10 or Server 2016 target. We'll run a Nikto scan against the web-service: nikto -h 10.13.38.11 Nikto identifies a hidden .DS_Store file on the web-server. After a bit of research, we learn that Ds_Store files on Windows machines can be used to enumerate w...