Posts

Showing posts with the label SeImpersonate

Hack the Box - Remote - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Remote machine hosted at https://hackthebox.eu. For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Remote machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.1.153 Scanning and Enumeration We'll start by scanning for open ports with Nmap : nmap -T4 -p- 10.129.1.153   Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: nmap -sV -p21,80,111,135,139,445,2049,5985,47001 -T4 10.129.1.153 Port 2049 is open, which is a NFS service. Let's see if there's an publicly exposed shares: showmount -e 10.129.1.153 This is a great find. We can mount this directory to our filesystem by creating a new directory, then using the mount command sudo mkdir /mnt/remote sudo mount -t nfs 10.129.1.153:/site_backups /mnt/...

Hack the Box - Devel - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Devel machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Devel machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.98.96. Scanning and Enumeration We'll start by scanning for open ports with Nmap : nmap -T4 -p- 10.129.98.96 Now we'll do another  Nmap  scan, this time specifying the ports and picking up service names and version numbers: nmap -T4 -p21,80 10.129.98.96 Since we see that  FTP  is available, we now run some enumeration scripts with  Nmap : nmap --scripts=ftp* -p21 10.129.98.96 The scan tells us that we can login to  FTP  anonymously, so let's do a manual enumeration of the service: ftp 10.129.98.96 anonymous ls Judging from the iisstart.htm file, it looks like the  FTP  service points ...