Easy Machine

6 November 2024 · VulnHub, Easy Machine

Aragog - VulnHub

Una máquina bastante sencilla, que puede ser útil para practicar el reconocimiento y explotación de vulnerabilidades de WordPress, pues para ganar acceso a la máquina, tenemos que explotar una …

LinuxWordPressSSHMySQLWeb EnumerationFuzzingVirtual HostingWordPress EnumerationUnauthenticated Arbitrary File Upload (RCE)CVE-2020-25213 (RCE)System Recognition (Linux)BurpSuiteMySQL EnumerationCracking HashAbusing CRON JobsPrivesc - Abusing CRON JobsBrute ForceOSCP StyleMetasploit Framework
Aragog - VulnHub
16 October 2024 · HackTheBox, Easy Machine

Sauna - Hack The Box

Esta fue una máquina sencilla. Empezamos analizando el servicio HTTP, ahí encontramos algunos nombres que después probamos con Kerbrute para poder ver qué usuarios existen en la máquina víctima, …

WindowsActive DirectoryDNSLDAPRPCWeb EnumerationLDAP EnumerationKerberos EnumerationInformation LeakageAS-REP Roasting AttackCracking HashRPC EnumerationSystem Recognition (Windows)BloodHound and SharpHound EnumerationDCSync AttackPrivesc - DCSync AttackOSCP Style
Sauna - Hack The Box
14 October 2024 · HackTheBox, Easy Machine

GoodGames - Hack The Box

Esta fue una máquina bastante útil para practicar inyecciones SQL basadas en errores. Empezamos únicamente encontrando un puerto abierto, siendo una página web activa que analizamos y probamos su …

LinuxWerkzeugFlask VoltWeb EnumerationFuzzingBurpSuiteSQL Injection (Error Based)SQLi Automatization (SQLMAP)Cracking HashServer Side Template Injection (SSTI)Docker EnumerationUser PivotingPassword ReuseAbusing User Mount in Docker ContainerPrivesc - Docker BreakoutOSCP Style
GoodGames - Hack The Box
10 October 2024 · HackTheBox, Easy Machine

Forest - Hack The Box

Esta máquina sí fue algo sencilla. Todo se basó en la enumeración, empezamos enumerando el DNS para ver qué información obteníamos e intentamos aplicar el ataque de transferencia de zona sin éxito. Al …

WindowsActive DirectoryDNSSMBRPCLDAPDNS EnumerationRPC EnumerationLDAP EnumerationAS-REP Roasting AttackSharpHound and BloodHound EnumerationAbusing Account Operators GroupDCSync AttackPrivesc - DCSync AttackOSCP Style
Forest - Hack The Box
8 October 2024 · HackTheBox, Easy Machine

OpenSource - Hack The Box

Esta fue una máquina que para nada es fácil; hubo que hacer bastante investigación. Empezamos enumerando la página web, aquí encontramos que podemos subir archivos y luego visitarlos, y también …

LinuxWerkzeugFlaskGiteaGitWeb EnumerationInformation LeakageGit EnumerationBurpSuiteAbusing File Upload (AFU)Local File Inclusion (LFI)Shell Via Flask Debug (Werkzeug Debbuger - Unintended Way)Remote Port ForwardingPivotingAbusing CRON JobsGit HooksPrivesc - Abusing CRON JobsPrivesc - Malicious Git HookOSCP Style
OpenSource - Hack The Box
28 September 2024 · HackTheBox, Easy Machine

Support - Hack The Box

Esta es una máquina que para nada es fácil, ya que hay muchos pasos y conceptos de Directorio Activo (AD) que deberías de tener claros para completar la máquina. Como en todo AD, nos basamos mucho en …

WindowsActive DirectorySMBLDAPKerberosSMB EnumerationInformation LeakageKerberos EnumerationBinary AnalysisAnalysis with DNSpyDebbuging with DNSpyLDAP EnumerationPassword SprayingSharpHound and BloodHound EnumerationResource-based Constrained Delegation Attack (RBCD Attack)S4U AttackPrivesc - RBCD AttackPrivesc - S4U AttackOSCP Style
Support - Hack The Box
22 May 2023 · HackTheBox, Easy Machine

Driver - Hack The Box

Es una máquina relativamente sencilla, comenzamos entrando al servicio HTTP, el cual nos pedirá credenciales para poder entrar, adivinamos las credenciales y enumerando el sitio web, encontramos que …

WindowsSMBMFP Firmware UploadSCF Malicious FileCracking HashSystem Recognition (Windows)Local Privilege Escalation (LPE)Abusing Vuln Process SpoolsvPrivesc - PrintNightmare Exploit (CVE-2021-1675)OSCP Style
Driver - Hack The Box
19 May 2023 · HackTheBox, Easy Machine

Toolbox - Hack The Box

Esta fue una máquina, un poquito complicada, vamos a analizar varios servicios que tiene activo, siendo que el servicio HTTPS será la clave para resolver la máquina, pues podremos aplicar PostgreSQL …

WindowsLinuxFTP EnumerationDocker ToolboxPostgreSQL InjectionRemote Code Execution (RCE)PostgreSQLI (RCE)BurpSuitePivotingDefault CredentialsPrivesc - Abusing boot2dockerOSCP Style
Toolbox - Hack The Box
17 May 2023 · HackTheBox, Easy Machine

Antique - Hack The Box

Esta fue una máquina bastante interesante, haciendo los escaneos correspondientes, únicamente, encontramos un puerto abierto que corre el servicio Telnet, al no encontrar nada más, buscamos por UDP y …

LinuxTelnetUDP ScanSNMP EnumerationAbusing Telnet PrivilegesCUPSCUPS Administration ExploitPrivesc - CVE-2012-5519 (CUPS Administration Exploit)Dirty Pipe ExploitationPrivesc - CVE-2022-0847 (Dirty Pipe)OSCP StyleMetasploit Framework
Antique - Hack The Box
12 May 2023 · HackTheBox, Easy Machine

Tabby - Hack The Box

Esta fue una máquina algo complicada, descubrimos que usa el servicio Tomcat para su página web y aplicamos Local File Inclusion (LFI) para poder enumerar distintos archivos como el /etc/passwd y …

LinuxTomcatLocal File Inclusion (LFI)Abusing Virtual Host ManagerAbusing Tomcat Text-Based ManagerDeploying Authenticated Code Execution Malicious WARReverse ShellCracking ZIPPrivesc - LXD/LXC ExploitationOSCP StyleMetasploit Framework
Tabby - Hack The Box