Posts

Showing posts with the label pw reg

Hack the Box - Chatterbox - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Chatterbox machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Chatterbox machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.81.94 Scanning and Enumeration We'll start by scanning for open ports with Nmap : sudo nmap -T4 -p- 10.129.81.94 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: sudo nmap -sV -T4 -p9255,9256 10.129.81.94 There's only one service listed here, so let's see if there's any public exploit for it: searchsploit achat Let's take a look at this Python exploit: searchsploit -x 36025.py We've got a Python buffer overflow exploit, which requires us to supply a payload and the IP address of the target. To execute this, we'll need to: 1) Cop...

TryHackMe - Windows PrivEsc - Walkthrough

Image
Introduction Today we're going to be doing a walkthrough for the Windows PrivEsc room hosted at https://tryhackme.com/room/w indows10privesc . For this walkthrough, we'll be using two virtual machines (VMs), a Kali Linux VM as our attacking machine, and the deployed Windows 10 client as the the victim machine. Task 1 - Deploy the Vulnerable Windows VM Press the green button here: The Windows machine should come online after a minute or two. The IP address of the machine can be found here: Of course, the actual IP address will probably be a different one from the one in the screenshot.  For the examples, however, we will use the IP address of 10.10.227.113 RDP should be available on port 3389 (it may take a few minutes for the service to start). You can login to the "user" account using the password "password321": xfreerdp /u:user /p:password321 /cert:ignore /v:10.10.227.113 Questions: Deploy the Windows VM and login using the "user" ...