Temporary Advertisements:
Ad
Ad
Ad
DarkCorp Hack the Box Season 7 (Windows Insane)
by RedBlock - Saturday February 8, 2025 at 03:32 PM
started right now
i was able to trigger xss on cube but gave me server error

triying to reset password for that other subdomain
Reply
Somehow I'm able to use ldap search but can't run bloodhound sshuttle seems to have helped.
Reply
(Feb 09, 2025, 03:20 PM)jonklem Wrote: Somehow I'm able to use ldap search but can't run bloodhound sshuttle seems to have helped.

ldapdomaindump also works but can't use that data in bloodhound...

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching.
Reply
Yeah, its really annoying. I can't get the bloodhound-python to work either. windapsearch.py ain't working too
Reply
http://172.16.20.2:5000/check this works with victor's creds. I thought maybe i could snag a hash with responder, but I already had to jump through hoops to get access to the network, i can't just make it fetch my ip.
Reply
(Feb 09, 2025, 03:23 PM)0xbeef Wrote:
(Feb 09, 2025, 03:20 PM)jonklem Wrote: Somehow I'm able to use ldap search but can't run bloodhound sshuttle seems to have helped.

ldapdomaindump also works but can't use that data in bloodhound...

I think you can try rusthound-ce (not that rusthound-ce only works with bloodhound-ce
Reply
where the heck is Victor's passwd?
Reply
(Feb 09, 2025, 03:44 PM)jonklem Wrote: http://172.16.20.2:5000/check this works with victor's creds.  I thought maybe i could snag a hash with responder, but I already had to jump through hoops to get access to the network, i can't just make it fetch my ip.
try ligolo listener, http-ntlm-auth
Reply
Anyone was able to get the NTLM hash with responder?
Reply
The POST request to 172.16.20.2/status contains a json. I don't know if we can inject commands there, the request is done via python requests. Just start a listener with ligolo pointing to your http server and modify the port of the json
{"protocol":"http","host":"drip.darkcorp.htb","port":"xxxx"}


GET / HTTP/1.1
Host: drip.darkcorp.htb:8080
User-Agent: python-requests/2.32.3
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive

Edit: You can use ntlmrelay to obtain a shell from another account
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [UPDATED] APT-Labs Prolabs Writeup z1ne99 41 5,930 2 hours ago
Last Post: morris
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 61 6,068 4 hours ago
Last Post: NIhaogt
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 441 112,620 Yesterday, 05:51 PM
Last Post: evermore
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 621 105,930 Yesterday, 03:59 PM
Last Post: user65745747
  How to Hack WiFi password Using PMKID Apvu 9 4,393 Sep 19, 2026, 09:08 PM
Last Post: anonhawk437

Forum Jump:


 Users browsing this forum: 1 Guest(s)