Posts

Showing posts with the label MS-AD

TryHackMe - Attacktive Directory - Walkthrough

Image
Introduction Today we're going to be doing a walkthrough for the Attacktive Directory room hosted at https://tryhackme.com/room/ attacktivedirectory . For this walkthrough, we'll be using two virtual machines (VMs), a Kali Linux VM as our attacking machine, and the deployed Windows client as the the victim machine. After the Windows client IP is assigned, we alias the machine as attacktive.thm . Task 1 - Intro - Deploy The Machine Questions: To access the Virtual Machine, you will need to first connect to our network using OpenVPN. Here is a mini walkthrough of getting connected. No answer needed Return to your access page. You can verify you are connected by looking on your access page. Refresh the page. You should see a green tick next to Connected. It will also show you your internal IP address. No answer needed Alternatively, you can deploy the In-Browser Kali or Attack Box and automatically be connected to the TryHackMe Network. No answer needed Once connected to the ...

TryHackMe - Active Directory Basics - Walkthrough

Image
Introduction Today we're going to be doing a walkthrough for the Active Directory Basics room hosted at https://tryhackme.com/room/ activedirectorybasics . We'll be using one virtual machine (VM), the the deployed Windows 10 client. Task 1 - Introduction Questions I understand what Active Directory is and why it is used. No answer needed Task 2 - Physical Active Directory Questions What database does the AD DS contain? Answer contained within Task description Where is the NTDS.dit stored? Answer contained within Task description What type of machine can be a domain controller? Answer contained within Task description Task 3 - The Forest Questions What is the term for a hierarchy of domains in a network? Answer contained within Task description What is the term for the rules for object creation? Answer contained within Task description What is the term for containers for groups, computers, users, printers, and other OUs? Answer contained within Task description Task 4 - Users + ...

HackTheBox - Endgame: POO - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Endgame P.O.O network hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the P.O.O network as the victim systems. After connecting to the Hack the Box network via VPN, we see that our first target is located at 10.13.38.11. Scanning and Enumeration We'll start by scanning for open ports with Nmap : nmap -T4 -p- 10.13.38.11   Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: nmap -sV -T4 -p80,1433 10.13.38.11 The IIS server version is 10, which probably means we're up against a Windows 10 or Server 2016 target. We'll run a Nikto scan against the web-service: nikto -h 10.13.38.11 Nikto identifies a hidden .DS_Store file on the web-server. After a bit of research, we learn that Ds_Store files on Windows machines can be used to enumerate w...