Analysis - HTB
by paven - Saturday January 20, 2024 at 01:22 PM
#11
(Jan 20, 2024, 09:33 PM)ajasjas Wrote: It's a DC, it has a DNS server.... you brute force subdomains via DNS using the host as the resolver. If it exists it will resolve it, if not it will return NX or such. gobuster does this, every other tool for DNS bruteforcing does it too.

I have one question. What if the target is not a DNS server, what custom DNS resolver we give in that case with Gobuster. Gateway IP ?
Reply
#12
(Jan 20, 2024, 09:51 PM)Shalabi Wrote:
(Jan 20, 2024, 09:47 PM)youssefm55 Wrote:
(Jan 20, 2024, 09:33 PM)ajasjas Wrote: It's a DC, it has a DNS server.... you brute force subdomains via DNS using the host as the resolver. If it exists it will resolve it, if not it will return NX or such. gobuster does this, every other tool for DNS bruteforcing does it too.

I am doing this but no results are coming out

You have to use dns param not vhost
this was the command I used is there sth wrong about it??
gobuster dns -d analysis.htb -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-20000.txt
Reply
#13
(Jan 20, 2024, 10:00 PM)youssefm55 Wrote:
(Jan 20, 2024, 09:51 PM)Shalabi Wrote:
(Jan 20, 2024, 09:47 PM)youssefm55 Wrote:
(Jan 20, 2024, 09:33 PM)ajasjas Wrote: It's a DC, it has a DNS server.... you brute force subdomains via DNS using the host as the resolver. If it exists it will resolve it, if not it will return NX or such. gobuster does this, every other tool for DNS bruteforcing does it too.

I am doing this but no results are coming out

You have to use dns param not vhost
this was the command I used is there sth wrong about it??
gobuster dns -d analysis.htb -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-20000.txt

include -r DNSIP: PORT
Reply
#14
(Jan 20, 2024, 10:02 PM)raiderado Wrote:
(Jan 20, 2024, 10:00 PM)youssefm55 Wrote:
(Jan 20, 2024, 09:51 PM)Shalabi Wrote:
(Jan 20, 2024, 09:47 PM)youssefm55 Wrote:
(Jan 20, 2024, 09:33 PM)ajasjas Wrote: It's a DC, it has a DNS server.... you brute force subdomains via DNS using the host as the resolver. If it exists it will resolve it, if not it will return NX or such. gobuster does this, every other tool for DNS bruteforcing does it too.

I am doing this but no results are coming out

You have to use dns param not vhost
this was the command I used is there sth wrong about it??
gobuster dns -d analysis.htb -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-20000.txt

include -r DNSIP: PORT

ok great thanks bro
Reply
#15
Found: www.analysis.htb
Found: internal.analysis.htb
Found: domaindnszones.analysis.htb
Found: forestdnszones.analysis.htb
Reply
#16
(Jan 20, 2024, 10:20 PM)Art10n Wrote: Found: www.analysis.htb
Found: internal.analysis.htb
Found: domaindnszones.analysis.htb
Found: forestdnszones.analysis.htb
also there is gc._msdcs.analysis.htb
Reply
#17
list.php?name= is an injectable ldap query.
So far all I can do is get a few usernames, and enumerate a bunch of uninstersting ldap attributes.

Guessing login form is also an ldap injection.
Reply
#18
I found this

http://internal.analysis.htb/employees/login.php
Reply
#19
[+] VALID USERNAME: jdoe@analysis.htb
[+] VALID USERNAME: ajohnson@analysis.htb
[+] VALID USERNAME: cwilliams@analysis.htb
[+] VALID USERNAME: wsmith@analysis.htb
[+] VALID USERNAME: jangel@analysis.htb
[+] VALID USERNAME: technician@analysis.htb
Reply
#20
Also anonymos login is eanbled in port 135 rpc.... use rpcclient

(Jan 20, 2024, 10:54 PM)Art10n Wrote: [+] VALID USERNAME: jdoe@analysis.htb
[+] VALID USERNAME: ajohnson@analysis.htb
[+] VALID USERNAME: cwilliams@analysis.htb
[+] VALID USERNAME: wsmith@analysis.htb
[+] VALID USERNAME: jangel@analysis.htb
[+] VALID USERNAME: technician@analysis.htb

how did u found this?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 370 92,402 5 hours ago
Last Post: lifolifo007
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,200 8 hours ago
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,515 Yesterday, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 410 Yesterday, 10:36 PM
Last Post: op334
  CBBH Write Ups hiddenhacker 22 6,237 Yesterday, 06:39 AM
Last Post: Usercomplex

Forum Jump:


 Users browsing this forum: 1 Guest(s)