Windows

19 May 2023 · HackTheBox, Easy Machine

Toolbox - Hack The Box

Esta fue una máquina, un poquito complicada, vamos a analizar varios servicios que tiene activo, siendo que el servicio HTTPS será la clave para resolver la máquina, pues podremos aplicar PostgreSQL …

WindowsLinuxFTP EnumerationDocker ToolboxPostgreSQL InjectionRemote Code Execution (RCE)PostgreSQLI (RCE)BurpSuitePivotingDefault CredentialsPrivesc - Abusing boot2dockerOSCP Style
Toolbox - Hack The Box
2 May 2023 · HackTheBox, Easy Machine

Active - Hack The Box

Esta máquina fue algo complicada para mí, porque se trató de un ejercicio de Active Directory. Tuve que investigar mucho sobre Active Directory, gracias a la herramienta smbclient y smbmap, se pudo …

WindowsSMBActive DirectorySMB EnumerationSYSVOL MiningExploiting GPP SYSVOLCracking HashPrivesc - Kerberoasting AttackOSCP Style
Active - Hack The Box
24 April 2023 · HackTheBox, Easy Machine

Bounty - Hack The Box

Esta es una máquina algo sencilla, vamos a usar Fuzzing a la página web que está activa en el puerto HTTP, como no descubrimos nada, buscaremos por archivos ASP, pues usa el servicio IIS y …

WindowsMicrosoft IISFuzzingBurpSuiteSniper AttackMalicious web.config FileASP/ASPX PayloadPrivesc - Juicy PotatoOSCP Style
Bounty - Hack The Box
18 February 2023 · HackTheBox, Easy Machine

Grandpa - Hack The Box

Esta fue una máquina fácil en la cual vamos a vulnerar el servicio HTTP del puerto 80 que está usando Microsoft IIS 6.0 WebDAV, usando un Exploit que nos conectara de forma remota a la máquina …

WindowsIIS 6.0 WebDAVRemote Buffer Overflow (RBO)CVE-2017-7269 (RBO)System Recognition (Windows)Local Privilege Escalation (LPE)Privesc - Churrasco Token Kidnapping (LPE)Reverse ShellOSCP Style
Grandpa - Hack The Box
17 February 2023 · HackTheBox, Easy Machine

Arctic - Hack The Box

Una máquina algo sencilla, vamos a vulnerar el servicio Adobe ColdFusion 8 usando el Exploit CVE-2009-2264 que nos conectara directamente a la máquina usando una Reverse Shell, entraremos como usuario …

WindowsFTMPAdobe ColdFusionRemote Command Execution (RCE)CVE-2009-2265 (RCE)Reverse ShellSystem Recognition (Windows)Local Privilege Escalation (LPE)Privesc - MS10-059 (LPE)OSCP Style
Arctic - Hack The Box
16 February 2023 · HackTheBox, Easy Machine

Optimum - Hack The Box

La máquina Optimum, bastante sencilla con varias formas para poder vulnerarla, en mi caso use el CVE-2014-6287 para poder acceder a la máquina como usuario, y para escalar privilegios utilice el …

WindowsHttp File Server (HFS)Remote Command Execution (RCE)CVE-2014-6287 (RCE)System Recognition (Windows)Local Privilege Escalation (LPE)Privesc - MS16-098 (LPE)Privesc - MS16-032 (LPE)OSCP StyleMetasploit Framework
Optimum - Hack The Box
14 February 2023 · HackTheBox, Easy Machine

Devel - Hack The Box

Una máquina bastante sencilla, en la cual usaremos el servicio FTP para cargar un Payload que contendrá una Shell que se activará en el puerto HTTP que corre el servicio IIS y después escalaremos …

WindowsMicrosoft IISFTPFTP EnumerationAbusing FTP ServiceLocal File Inclusion (LFI)Reverse ShellAbusing IIS ServiceASPX WebShellSystem Recognition (Windows)Local Privilege Escalation (LPE)Privesc - MS11-046 (LPE)Privesc - MS13-053 (LPE)OSCP StyleMetasploit Framework
Devel - Hack The Box
13 February 2023 · HackTheBox, Easy Machine

Legacy - Hack The Box

Una máquina no tan complicada, ya que vamos a utilizar un Exploit que ya hemos usado antes con la máquina Blue, la diferencia radica en los named pipes activos en el servicio Samba que está activo, …

WindowsSMBRemote Command Execution (RCE)Eternal Blue MS17-010 (RCE)Malicious PayloadReverse ShellPrivesc - Eternal Blue MS17-010 (RCE)Microsoft Windows Server Code Execution MS08-067 (MWSCE MS08-067)Privesc - MWSCE MS08-067OSCP StyleMetasploit Framework
Legacy - Hack The Box
25 January 2023 · HackTheBox, Easy Machine

Remote - Hack The Box

Esta máquina es algo difícil, pues hay que investigar todos los servicios que usa y ver de cual nos podemos aprovechar para poder vulnerar los sistemas de la máquina, además de analizar los Exploits, …

WindowsFTP EnumerationUmbracoRemote Code Execution - Authenticated (RCE - Authenticated)NFS PentestingCracking HashReverse ShellTeamViewer Enumeration & ExploitationCVE-2019-18988Privesc - TeamViewer Enumeration & Exploitation (CVE-2019-18988)Privesc - Abusing UsoSvcPrivesc - Juicy PotatoOSCP StyleMetasploit Framework
Remote - Hack The Box
18 January 2023 · HackTheBox, Easy Machine

Blue - Hack The Box

Una máquina relativamente fácil, ya que usamos un Exploit muy conocido que hace juego con el nombre de la máquina y que hay una historia detrás de su obtención, siendo que este Exploit supuestamente …

WindowsSMBRemote Code Execution (RCE)Eternal Blue MS17-010 (RCE)Reverse ShellPrivesc - Eternal Blue MS17-010 (RCE)MimikatzOSCP StyleMetasploit Framework
Blue - Hack The Box