HackTheBox - Intelligence

แชร์
ฝัง
  • เผยแพร่เมื่อ 29 มิ.ย. 2024
  • 00:00 - Intro
    01:02 - Start of nmap, discover Active Directory and a web server
    02:45 - Doing some common checks against a Domain Controller
    04:50 - Discovering PDF's with filenames based upon the date
    05:25 - Building a customized wordlist based upon the date with the date command
    08:30 - Downloading the PDF's with wget and then examining metadata
    11:25 - Using Kerbrute to validate the usernames in the metadata are correct
    12:50 - Using pdftotext to convert all the PDF's into text files, so we can grep through text
    14:20 - Finding the password NewIntelligenceCorpUser987, then using KerBrute to perfrom a passwordspray
    15:40 - Running CrackMapExec Spider_Plus while we do some other CME things
    17:20 - Running Python Bloodhound with the credentials we got from the password spray
    19:10 - Using JQ to parse the data from CME's spider_plus module to discover a powershell script
    22:50 - Importing the bloodhound results and then searching for attack paths
    26:00 - Discovering we probably need to get access to the SVC_INT GMSA (Group Managed Service Account)
    27:50 - Going back over the powershell script we downloaded, and then creating a DNS Record with krbrelayx's dnstool
    28:57 - Using dnstool to create an A Record on an Active Directory Server
    32:30 - Using the MSF Capture http_ntlm module to capture an NTLMv2 Hash of people that access our webserver (Responder also would work but was broke on my box)
    36:35 - Using John to crack the ntlmv2 hash and gaining access to the Ted Graves account
    42:19 - Using gMSA Dumper to extract the svc_int hash
    43:43 - Using impacket's getST to generate a SilverTicket which we can use for impersonating an administrator
    46:00 - Using NTPDate to syncronize the time to our domain controller
    48:30 - Using our ticket with psexec to gain access to the server

ความคิดเห็น • 37

  • @JuanBotes
    @JuanBotes 2 ปีที่แล้ว +24

    I got my OSCP from your content months ago, but I still come back to keep learning, Thanks for making this awesome content \o/

  • @vbscrub
    @vbscrub 2 ปีที่แล้ว +21

    Its not actually a silver ticket you're using at the end, but S4U delegation. Tried to leave a longer comment explaining in more detail but I guess youtube didn't like it lol

    • @vbscrub
      @vbscrub 2 ปีที่แล้ว +7

      Explained it a bit in my video walkthrough of this machine, but I do plan on making a whole video dedicated to kerberos delegation stuff

  • @robk2043
    @robk2043 2 ปีที่แล้ว +1

    This is loaded information. Thank you so much as always.

  • @marwandos
    @marwandos 2 ปีที่แล้ว

    Impressive as always.

  • @inopsek
    @inopsek 2 ปีที่แล้ว +2

    Love the content. Thanks

  • @Ms.Robot.
    @Ms.Robot. 2 ปีที่แล้ว +4

    This is one of my favorite boxes. ❤️

  • @ismailarame3756
    @ismailarame3756 2 ปีที่แล้ว +3

    first one wow love u from morroco

  • @Chukxztv
    @Chukxztv 2 ปีที่แล้ว

    awesome content !

  • @testtest-jl3rn
    @testtest-jl3rn 2 ปีที่แล้ว

    Next Level!

  • @arslanamir3739
    @arslanamir3739 2 ปีที่แล้ว

    Awesome man.

  • @user-ds7io2dm3b
    @user-ds7io2dm3b 3 หลายเดือนก่อน

    Man thats gold ❤️

  • @Jaidevpgramya
    @Jaidevpgramya 2 ปีที่แล้ว +2

    A lot to learn 😬😬😬

  • @sudozain6371
    @sudozain6371 2 ปีที่แล้ว

    Great job , keep going !

  • @daysling
    @daysling 2 ปีที่แล้ว +1

    big fan

  • @guyunknown226
    @guyunknown226 2 ปีที่แล้ว +3

    1st viewer ❤️🔥

  • @fogofwar342
    @fogofwar342 7 หลายเดือนก่อน

    THANK YOU!!!

  • @kret63
    @kret63 2 ปีที่แล้ว +3

    Oof, my brain can't even process what i saw.

  • @sergebash2305
    @sergebash2305 2 ปีที่แล้ว +1

    wow!

  • @gokul6120
    @gokul6120 2 ปีที่แล้ว +1

    I really love that... ❤️❤️👍👍

  • @garybuttherissilent5896
    @garybuttherissilent5896 2 ปีที่แล้ว +2

    Sheesh this one is difficult I feel like a moron haha

  • @ursr78122
    @ursr78122 2 ปีที่แล้ว

    Why u didn't do notes in obsidian?

  • @obfusec8329
    @obfusec8329 2 ปีที่แล้ว +2

    As always, love the content. I wish the intros were at the end. It feels like a spoiler to listen to it so I always skip.

    • @ippsec
      @ippsec  2 ปีที่แล้ว +3

      That’s why there’s always a jump in my he description.

  • @ayushprajapati2630
    @ayushprajapati2630 ปีที่แล้ว

    can anyone compare this ad box to oscp

  • @getoutmore
    @getoutmore 2 ปีที่แล้ว +4

    For a Beginner: How hard/high is this Box ranked on htb?

    • @vbscrub
      @vbscrub 2 ปีที่แล้ว +1

      its marked as medium and I'd agree with that rating compared to the other machines. There are definitely easier machines and if you're a beginner they do have their "starting point" series that walks you through a few machines

  • @rozbrajaczpoziomow
    @rozbrajaczpoziomow 2 ปีที่แล้ว +2

  • @shivasijwali6779
    @shivasijwali6779 2 ปีที่แล้ว +4

    Hey which OS do u use pls tell?

    • @jiriperutek2055
      @jiriperutek2055 2 ปีที่แล้ว +2

      parrot security os

    • @shivasijwali6779
      @shivasijwali6779 2 ปีที่แล้ว

      @@jiriperutek2055 I'm also doing the parrot os I just swifted from kali to parrot but its disconnecting my wifi after a few minutes pls help If u know to resolve it?

  • @lenon406
    @lenon406 2 ปีที่แล้ว

    .

  • @henryhowland3686
    @henryhowland3686 ปีที่แล้ว

    A little lower quality than his other ones

  • @sand3epyadav
    @sand3epyadav 2 ปีที่แล้ว +1

    5 th view