Sauna is an easy AD machine, getting initial is by gathering usernames from the web and doing AS-REP Roasting, we can get a user’s hash. And winPEAS reveals svc_loanmgr’s password in plain …
We are going to pwn Forest by egre55 & mrb3n from Hack The Box.
Link : https://www.hackthebox.eu/home/machines/profile/212
Let’s Begin with our Initial Nmap Scan.
Nmap Scan Results: PORT STATE SERVICE VERSION 53/tcp open domain? | fingerprint-strings: | DNSVersionBindReqTCP: | version |_ bind 63/tcp closed via-ftp 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: …
We are going to pwn Bastion from Hack The Box.
Link: https://www.hackthebox.eu/home/machines/profile/186
Let’s Begin with our Initial Nmap Scan.
Nmap Scan Results: PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH for_Windows_7.9 (protocol 2.0) | ssh-hostkey: | 2048 3a:56:ae:75:3c:78:0e:c8:56:4d:cb:1c:22:bf:45:8a (RSA) | 256 cc:2e:56:ab:19:97:d5:bb:03:fb:82:cd:63:da:68:01 (ECDSA) |_ 256 …