HackTheBox - Freelancer

IppSec October 5, 2024
Video Thumbnail
IppSec Logo

IppSec

@ippsec

About

Video Search: https://ippsec.rocks

Video Description

00:00 - Introduction 01:10 - Start of nmap 04:45 - Discovering the website is Django, Wappalyzer tells us but also talking about how we could manually identify with the help 08:00 - Creating an account, discovering we need to activate it, using Forgot Password to activate it 09:50 - There is a QR Code that lets users login by scanning it, looking at the URL it appears there could be an IDOR 11:28 - Discovering ID 2 is an admin, crafting a QR Code with the admin ID in it and gaining access to the Django Admin 14:30 - Enumerating the MSSQL Database, discovering we can impersonate SA and then enable XP_CMDSHELL 24:30 - Trying to get a Reverse Shell, AV is blocking it, do some light obfuscation to bypass it 31:40 - Shell returned as the webapp user, can't get WinPEAS Running due to AV 40:40 - Discovering a password left behind by the SQL Express Install, password spray to get access to mikasaAckerman 45:10 - Showing the NxcDb, which logs all the successful logins with nxc 50:00 - Discovering a Memory Dump, downloading it to our box then using MemProcFs 55:20 - Installing PyPyKatz which will have it automatically use pypykatz (mimikatz) to dump lsa 1:02:40 - More password sprays to get access to Lorra199, then using WinRM and discovering we can enumerate the Active Directory Recycle Bin 1:05:30 - Restoring Liza Kazanof from the recycle bin, then resetting the password due to it being expired. 1:11:15 - Liza has the SeBackup privilege, using DiskShadow and Robocopy to download ntds.dit to dump the domain 1:23:20 - The issue we had with DiskShadow is because of how the script file was encoded, major pita 1:29:30 - Running SecretsDump to get the administrator hash and login to the box 1:30:45 - BEYOND ROOT: Abusing GenericWrite to the Domain as Lorra199 to get a shell 1:32:40 - Going back to the memprocfs and showing we could have just ran secretsdump on the registry hives to get Lorra199's password. Administrator hash is invalid due to the password being changed since the dump was created 1:35:10 - First time setting up the Bloodhound Community Edition (new version that is supported) 1:41:00 - Fighting with Bloodhound.py since the main branch is installed 1:47:00 - Throwing in the towel fighting with my python environment, building a docker container to run bloodhound.py for us to ensure we are running the latest version 1:51:48 - Importing the latest bloodhound data and getting the attack path that shows genericwrite 1:54:20 - Adding a computer, giving it delegation, then dumping the AD Database with secretsdump

You May Also Like

Essential Gear Upgrade

AI-recommended products based on this video

Loading...
COOWPS Switch Case for Nintendo Switch and Switch OLED Model, Portable Full Protection Carrying Travel Bag with 18 Game Cards Storage for Switch Console Pro Controller Accessories Black

COOWPS Switch Case for Nintendo Switch and Switch OLED Model, Portable Full Protection Carrying Travel Bag with 18 Game Cards Storage for Switch Console Pro Controller Accessories Black

(2,497)
$24.99$22.99
FREE delivery Mon, Jun 16 on $35 of items shipped by Amazon
800+ bought in past month
Loading...
UGREEN Revodok Pro 210 Docking Station 10 in 1 USB C Dock Dual HDMI 4K@60Hz Single 8K@30Hz 100W PD 5Gbps USB C and USB A Data Ports Gigabit Ethernet, SD/TF Card Reader USB Hub Compatible for HP, Dell

UGREEN Revodok Pro 210 Docking Station 10 in 1 USB C Dock Dual HDMI 4K@60Hz Single 8K@30Hz 100W PD 5Gbps USB C and USB A Data Ports Gigabit Ethernet, SD/TF Card Reader USB Hub Compatible for HP, Dell

(1,701)
39.99
PrimeFREE delivery Saturday, June 14
100+ bought in past month
Loading...
ANKER 737 Power Bank, 24,000mAh 3-Port Laptop Portable Charger with 140W Fast Charging, Smart Display, for Outdoor Work, Compatible with iPhone 16/15/14 Series, Vision Pro, Samsung, MacBook, and More

ANKER 737 Power Bank, 24,000mAh 3-Port Laptop Portable Charger with 140W Fast Charging, Smart Display, for Outdoor Work, Compatible with iPhone 16/15/14 Series, Vision Pro, Samsung, MacBook, and More

(13,939)
109.99
FREE delivery Saturday, June 14
9K+ bought in past month
Loading...
Anker iPhone 16 Charger, 2-Pack 20W Fast USB C Charger Block, for iPhone 16/16 Pro Max/15 Series/iPad Pro and More (White, 2 Pack & 2 Cable)

Anker iPhone 16 Charger, 2-Pack 20W Fast USB C Charger Block, for iPhone 16/16 Pro Max/15 Series/iPad Pro and More (White, 2 Pack & 2 Cable)

(16,565)
13.99
PrimeFREE delivery Saturday, June 14 on orders shipped by Amazon over $35
10K+ bought in past month
Loading...
Anker Power Bank(PowerCore 10K),Compact Travel-Ready 10,000mAh Battery Pack with PowerIQ Charging Technology,5V/3A High-Speed Charging for iPhone,iPad,and More (USB-C Input and Output(Black),1pack) ClimatePartner certified

Anker Power Bank(PowerCore 10K),Compact Travel-Ready 10,000mAh Battery Pack with PowerIQ Charging Technology,5V/3A High-Speed Charging for iPhone,iPad,and More (USB-C Input and Output(Black),1pack) ClimatePartner certified

(109,961)
$17.99$17.81
FREE delivery Fri, Aug 8 on $35 of items shipped by Amazon
10K+ bought in past month