Alchemy - HTB Lab
by kewlcat002 - Monday September 23, 2024 at 12:21 PM
#61
Constant broken ssh pipe errors man, hard to get this Chisel up and secure ffs.
Reply
#62
Can anyone provide nudges for the following flags? I have access to the 200.a and 300.a AutomationX web apps using the creds found in the PDF, but not sure what is supposed to be done from here?

1. There is always another way
2. The secret is out!
3. The secret recipe.. Part 2
4. Who turned the heat up?!
5. The secret recipe.. Part 1
6. This didn't age well..
7. What a waste of good beer!
Reply
#63
hi anyone help web01 me to rope rusty i don't found creds
Reply
#64
Still encountering friggen broken pipe errors messing up any kind of persistence. Cannot tell still if this is design or something actually going on.

I am sure using Chisel etc is the way to tunnel further to find IPs on bacnet - any suggestions for this part?

(Have logged on to the SSH account using creds obtained)
Reply
#65
(Dec 04, 2024, 01:49 AM)UVB76 Wrote: Still encountering friggen broken pipe errors messing up any kind of persistence. Cannot tell still if this is design or something actually going on.

I am sure using Chisel etc is the way to tunnel further to find IPs on bacnet - any suggestions for this part?

(Have logged on to the SSH account using creds obtained)

have you tried ligolo-ng? works better for me... run it as a background job with nohup
Reply
#66
Anyone can give me a hint on How to escalate my privileges on DC. I have logins for two users. But I can't get Admin privileges from any of them.
Reply
#67
(Dec 08, 2024, 06:58 AM)bl4ckf0xk Wrote: Anyone can give me a hint on How to escalate my privileges on DC. I have logins for two users. But I can't get Admin privileges from any of them.

look bloodhound and enumeration directory
Reply
#68
For the PLC part how to find the PLC port. started in .14 but nmap scan shows 502 is closed and how to start the process of compromising it
Reply
#69
(Dec 04, 2024, 07:33 AM)a44857437 Wrote:
(Dec 04, 2024, 01:49 AM)UVB76 Wrote: Still encountering friggen broken pipe errors messing up any kind of persistence. Cannot tell still if this is design or something actually going on.

I am sure using Chisel etc is the way to tunnel further to find IPs on bacnet - any suggestions for this part?

(Have logged on to the SSH account using creds obtained)

have you tried ligolo-ng? works better for me... run it as a background job with nohup

Will give this a try - thank you!
Reply
#70
Guys, i need help please. I have no idea how to do eternal blue to EW through proxy. Can someone give me a hint how to do it?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 98 4,762 11 hours ago
Last Post: cacha123
  [Season10] ROOT Pterodactyl pulsebreaker 58 2,119 Yesterday, 05:37 PM
Last Post: Evocator
  Powerful-Android-RAT-2026 opsecmaster67 0 75 Yesterday, 05:02 PM
Last Post: opsecmaster67
  Hackers Cave 4 Static Android Blogs opsecmaster67 0 65 Yesterday, 04:44 PM
Last Post: opsecmaster67
  Android-Hacker-DEV Mtigating Security In Android opsecmaster67 0 64 Yesterday, 04:42 PM
Last Post: opsecmaster67

Forum Jump:


 Users browsing this forum: 1 Guest(s)