Hack The Box - Heist - Walkthrough
Introduction Today we're going to be doing a pentest walkthrough of the Heist machine hosted at https://hackthebox.eu. For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Heist machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.118.120. Scanning and Enumeration We'll start by scanning for open ports with Nmap: nmap -T4 -p- 10.129.118.120 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: nmap -sV -T4 -p80,135,445,5985,49669 10.129.118.120 This seems mostly typical for Windows systems, but we notice that port 5985 is open, which is associated with WinRM , so we'll keep in mind as we continue with our enumeration. For now, we'll take a look at the webpage: http://10.129.118.120 If we don't have credentials for the page, we might as well try enumerating as a guest user: http://10...