Metasploit Framework

16 February 2023 · HackTheBox, Easy Machine

Optimum - Hack The Box

La máquina Optimum, bastante sencilla con varias formas para poder vulnerarla, en mi caso use el CVE-2014-6287 para poder acceder a la máquina como usuario, y para escalar privilegios utilice el …

WindowsHttp File Server (HFS)Remote Command Execution (RCE)CVE-2014-6287 (RCE)System Recognition (Windows)Local Privilege Escalation (LPE)Privesc - MS16-098 (LPE)Privesc - MS16-032 (LPE)OSCP StyleMetasploit Framework
Optimum - Hack The Box
14 February 2023 · HackTheBox, Easy Machine

Devel - Hack The Box

Una máquina bastante sencilla, en la cual usaremos el servicio FTP para cargar un Payload que contendrá una Shell que se activará en el puerto HTTP que corre el servicio IIS y después escalaremos …

WindowsMicrosoft IISFTPFTP EnumerationAbusing FTP ServiceLocal File Inclusion (LFI)Reverse ShellAbusing IIS ServiceASPX WebShellSystem Recognition (Windows)Local Privilege Escalation (LPE)Privesc - MS11-046 (LPE)Privesc - MS13-053 (LPE)OSCP StyleMetasploit Framework
Devel - Hack The Box
13 February 2023 · HackTheBox, Easy Machine

Legacy - Hack The Box

Una máquina no tan complicada, ya que vamos a utilizar un Exploit que ya hemos usado antes con la máquina Blue, la diferencia radica en los named pipes activos en el servicio Samba que está activo, …

WindowsSMBRemote Command Execution (RCE)Eternal Blue MS17-010 (RCE)Malicious PayloadReverse ShellPrivesc - Eternal Blue MS17-010 (RCE)Microsoft Windows Server Code Execution MS08-067 (MWSCE MS08-067)Privesc - MWSCE MS08-067OSCP StyleMetasploit Framework
Legacy - Hack The Box
25 January 2023 · HackTheBox, Easy Machine

Remote - Hack The Box

Esta máquina es algo difícil, pues hay que investigar todos los servicios que usa y ver de cual nos podemos aprovechar para poder vulnerar los sistemas de la máquina, además de analizar los Exploits, …

WindowsFTP EnumerationUmbracoRemote Code Execution - Authenticated (RCE - Authenticated)NFS PentestingCracking HashReverse ShellTeamViewer Enumeration & ExploitationCVE-2019-18988Privesc - TeamViewer Enumeration & Exploitation (CVE-2019-18988)Privesc - Abusing UsoSvcPrivesc - Juicy PotatoOSCP StyleMetasploit Framework
Remote - Hack The Box
18 January 2023 · HackTheBox, Easy Machine

Blue - Hack The Box

Una máquina relativamente fácil, ya que usamos un Exploit muy conocido que hace juego con el nombre de la máquina y que hay una historia detrás de su obtención, siendo que este Exploit supuestamente …

WindowsSMBRemote Code Execution (RCE)Eternal Blue MS17-010 (RCE)Reverse ShellPrivesc - Eternal Blue MS17-010 (RCE)MimikatzOSCP StyleMetasploit Framework
Blue - Hack The Box
11 January 2023 · HackTheBox, Easy Machine

Lame - Hack The Box

La máquina lame es una de las primeras maquinas que hice, justo después del **Starting Point**, obviamente necesité mucha ayuda porque había cosas que aún no comprendía del todo. Es una maquina super …

LinuxSambaFTP EnumerationSamba EnumerationUsername Map Script Command Execution (UMSCE)CVE-2007-2447Command InjectionPrivesc - UMSCE (CVE-2007-2447)OSCP StyleMetasploit Framework
Lame - Hack The Box