TryHackMe - VulnNet Roasted - Walkthrough
Introduction Today we're going to be doing a walkthrough for the VulnNet: Roasted room hosted at https://tryhackme.com/room/ vulnnetroasted . For this walkthrough, we'll be using two virtual machines (VMs), a Kali Linux VM as our attacking machine, and the deployed Windows client as the the victim machine. After we're given the IP address of the server, we assign the IP address to the alias vulnnet-roasted.thm . The first thing we'll do is fire off an Nmap scan. nmap -Pn -p-10000 -T4 vulnnet-roasted.thm nmap -Pn -T4 -sV -sC -p53,88,135,139,389,445,464,593,636,3268,3269,9389 vulnnet-roasted.thm This server appears to be domain joined, and being the only (we assume) domain joined server on the network, we can assume that it is also the Domain Controller. Let's test whether or not we can brute-force the usernames from the server using Crackmapexec: crackmapexec smb vulnnet-roasted.thm -u guest -p ‘’ --rid-brute Because the guest account was not ...