Analysis - HTB
by paven - Saturday January 20, 2024 at 01:22 PM
#71
(Jan 21, 2024, 02:00 PM)bsbsmaster Wrote: frist think thz allot  i wanna sko how did u get the pass jdoe i only hace pass tec where did u findit

Pay attention to the output of winpeas, the password is mentioned in clear plain text
Reply
#72
any tips regarding root?
Reply
#73
(Jan 21, 2024, 02:09 PM)DwightSchrute Wrote: any tips regarding root?

this is a rabbit hole
(ANALYSIS\Administrateur) run_bctextencoder: C:\Users\jdoe\AppData\Local\Automation\run.bat

Pay attention to the snort
Snort(Snort)[C:\Snort\bin\snort.exe /SERVICE] - Autoload - No quotes and Space detected
Possible DLL Hijacking in binary folder: C:\Snort\bin (Users [AppendData/CreateDirectories WriteData/CreateFiles])
Reply
#74
(Jan 21, 2024, 02:08 PM)taletUrLeyakUpAR Wrote:
(Jan 21, 2024, 02:00 PM)bsbsmaster Wrote: frist think thz allot  i wanna sko how did u get the pass jdoe i only hace pass tec where did u findit

Pay attention to the output of winpeas, the password is mentioned in clear plain text

How do i login using the technician credentials ? I see people refering to webshell upload, but where do i login with that credentials to get reverse shell ? winlogon didnt work . I'm very bad with webapp,working on it atm.
Reply
#75
(Jan 21, 2024, 02:20 PM)raiderado Wrote:
(Jan 21, 2024, 02:08 PM)taletUrLeyakUpAR Wrote:
(Jan 21, 2024, 02:00 PM)bsbsmaster Wrote: frist think thz allot  i wanna sko how did u get the pass jdoe i only hace pass tec where did u findit

Pay attention to the output of winpeas, the password is mentioned in clear plain text

How do i login using the technician credentials ? I see people refering to webshell upload, but where do i login with that credentials to get reverse shell ? winlogon didnt work . I'm very bad with webapp,working on it atm.

Login Page: http://internal.analysis.htb/employees/login.php

after that go to http://internal.analysis.htb/dashboard/form.php (SOC Report), upload the rev shell then to execute it go to http://internal.analysis.htb/dashboard/u...f_file.php
Reply
#76
which revshells are working for you guys, the ones i'm using, including p0wny shell and meterpreter don't seem to be able to run the winpeas and meterpreter keeps shutting
Reply
#77
(Jan 21, 2024, 03:07 PM)qxuarpcy Wrote:
(Jan 21, 2024, 02:14 PM)taletUrLeyakUpAR Wrote:
(Jan 21, 2024, 02:09 PM)DwightSchrute Wrote: any tips regarding root?

this is a rabbit hole
(ANALYSIS\Administrateur) run_bctextencoder: C:\Users\jdoe\AppData\Local\Automation\run.bat

Pay attention to the snort
Snort(Snort)[C:\Snort\bin\snort.exe /SERVICE] - Autoload - No quotes and Space detected
Possible DLL Hijacking in binary folder: C:\Snort\bin (Users [AppendData/CreateDirectories WriteData/CreateFiles])

there is a old CVE about Snort dll hijack but that doesn't seem to work, there is others dll but hijacking still doesn't seem to work for me

thats where i am stuck as well...
Reply
#78
It looks there are some misssing dlls, but didnt succesfully menage to exploit them
Reply
#79
Are we sure that it's not encoded.txt? If I enter any password I get: The password you entered is invalid. But if I enter jdoe I get "Errorin decoding text".

I'm only able to replicate some of this behavior if I change the cipher text, so that it's invalid, then the application will say "Error in decoding" before entering a password and not after.

Edit:

I checked the AD attack chain, it looks like we need access to wsmith, then we can escalate to soc_analyst.
Reply
#80
(Jan 21, 2024, 07:56 AM)balckroot Wrote: Can anyone help for what is correct password length?

97NTtl*4QP96Bv

Thats the password I arrived at as well. Havent been able to get it to work on anything though
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,485 Yesterday, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 394 Yesterday, 10:36 PM
Last Post: op334
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 369 91,957 Yesterday, 04:10 PM
Last Post: sabbyahmed
  CBBH Write Ups hiddenhacker 22 6,223 Yesterday, 06:39 AM
Last Post: Usercomplex
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 86 7,807 Apr 28, 2026, 11:39 PM
Last Post: my4ri0d0

Forum Jump:


 Users browsing this forum: 1 Guest(s)