Sauna is an easy AD machine, getting initial is by gathering usernames from the web and doing AS-REP Roasting, we can get a user’s hash. And winPEAS reveals svc_loanmgr’s password in plain …
We are going to pwn Forest by egre55 & mrb3n from Hack The Box.
Link : https://www.hackthebox.eu/home/machines/profile/212
Let’s Begin with our Initial Nmap Scan.
Nmap Scan Results: PORT STATE SERVICE VERSION 53/tcp open domain? | fingerprint-strings: | DNSVersionBindReqTCP: | version |_ bind 63/tcp closed via-ftp 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: …